Количество 314 458
Количество 314 458
GHSA-3hx8-jcjc-x9xm
A vulnerability, which was classified as problematic, was found in OFCMS 1.1.3. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
GHSA-3hx8-92xp-7g4r
Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.10 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters involving the (1) getUserStateFromRequest function, and the (2) SEF and (3) com_messages modules.
GHSA-3hx8-6m94-fm2x
Buffer overflow in AbsoluteTelnet before 2.12 RC10 allows remote attackers to execute arbitrary code via a long window title.
GHSA-3hx8-4hp2-whqv
A Command Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor to execute arbitrary commands within the context of the system.
GHSA-3hx8-25m4-f73q
Out-of-Bounds read in ciCCIOTOPT in ASR180X will cause incorrect computations.
GHSA-3hx6-fqpj-xfjr
RichFaces vulnerable to Expression Language Injection
GHSA-3hx6-cm77-2752
libsixel 1.8.4 has an integer overflow in sixel_frame_resize in frame.c.
GHSA-3hx6-3qqx-qhvf
Improper encoding or escaping of output vulnerability in the system plugin daemon in Synology BeeStation Manager (BSM) before 1.1-65374, Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.1.1-42962-7, 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to execute arbitrary code via unspecified vectors.
GHSA-3hx4-h4gp-2jhp
The Qualcomm Wi-Fi driver in Android before 2016-06-01 on Nexus 7 (2013) devices allows attackers to gain privileges via a crafted application, aka internal bug 27777501.
GHSA-3hx4-77f4-g7cp
BIND was improperly sequencing cleanup operations on upstream recursion fetch contexts, leading in some cases to a use-after-free error that can trigger an assertion failure and crash in named. Affects BIND 9.0.0 to 9.8.x, 9.9.0 to 9.9.11, 9.10.0 to 9.10.6, 9.11.0 to 9.11.2, 9.9.3-S1 to 9.9.11-S1, 9.10.5-S1 to 9.10.6-S1, 9.12.0a1 to 9.12.0rc1.
GHSA-3hx4-75gf-pcm8
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MultimediaViewer.This issue affects MultimediaViewer: from * before 1.39.13, 1.42.7, 1.43.2, 1.44.0.
GHSA-3hx4-285w-v6mm
Jenkins Project Inheritance Plugin vulnerable to cross site scripting
GHSA-3hx3-v4g2-hgqp
Under certain conditions, SAP Business One Hana Chef Cookbook, versions - 8.82, 9.0, 9.1, 9.2, 9.3, 10.0, used to install SAP Business One for SAP HANA, allows an attacker to exploit an insecure temporary backup path and to access information which would otherwise be restricted, resulting in Information Disclosure vulnerability highly impacting the confidentiality, integrity and availability of the application.
GHSA-3hx3-6qpf-m689
CVE was unused by HPE.
GHSA-3hwx-vc7v-fw2m
Crash in the RFC 7468 dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file
GHSA-3hwx-j4f5-4679
The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the storeImages function in all versions up to, and including, 2.4.40. This makes it possible for authenticated attackers, with contributor access or above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
GHSA-3hwx-c6cp-q972
Publify vulnerable to cross site scripting
GHSA-3hww-w3cw-c9cm
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Daniel Floeter Hyperlink Group Block allows DOM-Based XSS. This issue affects Hyperlink Group Block: from n/a through 2.0.1.
GHSA-3hww-45xr-whm4
In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed.
GHSA-3hwv-x5p9-3h2h
In Bluetooth, there is a possible way to pair a display only device without PIN confirmation due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-222289114
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3hx8-jcjc-x9xm A vulnerability, which was classified as problematic, was found in OFCMS 1.1.3. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 4.3 | 0% Низкий | 12 месяцев назад | |
GHSA-3hx8-92xp-7g4r Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.0.10 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters involving the (1) getUserStateFromRequest function, and the (2) SEF and (3) com_messages modules. | 0% Низкий | почти 4 года назад | ||
GHSA-3hx8-6m94-fm2x Buffer overflow in AbsoluteTelnet before 2.12 RC10 allows remote attackers to execute arbitrary code via a long window title. | 32% Средний | почти 4 года назад | ||
GHSA-3hx8-4hp2-whqv A Command Injection vulnerability has been identified in the MiVoice Office 400 SMB Controller through 1.2.5.23 which could allow a malicious actor to execute arbitrary commands within the context of the system. | CVSS3: 9.8 | 1% Низкий | больше 2 лет назад | |
GHSA-3hx8-25m4-f73q Out-of-Bounds read in ciCCIOTOPT in ASR180X will cause incorrect computations. | CVSS3: 7.2 | 0% Низкий | почти 2 года назад | |
GHSA-3hx6-fqpj-xfjr RichFaces vulnerable to Expression Language Injection | CVSS3: 9.8 | 3% Низкий | больше 3 лет назад | |
GHSA-3hx6-cm77-2752 libsixel 1.8.4 has an integer overflow in sixel_frame_resize in frame.c. | 0% Низкий | больше 3 лет назад | ||
GHSA-3hx6-3qqx-qhvf Improper encoding or escaping of output vulnerability in the system plugin daemon in Synology BeeStation Manager (BSM) before 1.1-65374, Synology DiskStation Manager (DSM) before 6.2.4-25556-8, 7.1.1-42962-7, 7.2-64570-4, 7.2.1-69057-6 and 7.2.2-72806-1 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to execute arbitrary code via unspecified vectors. | CVSS3: 9.8 | 1% Низкий | 11 месяцев назад | |
GHSA-3hx4-h4gp-2jhp The Qualcomm Wi-Fi driver in Android before 2016-06-01 on Nexus 7 (2013) devices allows attackers to gain privileges via a crafted application, aka internal bug 27777501. | CVSS3: 9.8 | 0% Низкий | больше 3 лет назад | |
GHSA-3hx4-77f4-g7cp BIND was improperly sequencing cleanup operations on upstream recursion fetch contexts, leading in some cases to a use-after-free error that can trigger an assertion failure and crash in named. Affects BIND 9.0.0 to 9.8.x, 9.9.0 to 9.9.11, 9.10.0 to 9.10.6, 9.11.0 to 9.11.2, 9.9.3-S1 to 9.9.11-S1, 9.10.5-S1 to 9.10.6-S1, 9.12.0a1 to 9.12.0rc1. | CVSS3: 7.5 | 8% Низкий | больше 3 лет назад | |
GHSA-3hx4-75gf-pcm8 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MultimediaViewer.This issue affects MultimediaViewer: from * before 1.39.13, 1.42.7, 1.43.2, 1.44.0. | CVSS3: 4.7 | 0% Низкий | 6 дней назад | |
GHSA-3hx4-285w-v6mm Jenkins Project Inheritance Plugin vulnerable to cross site scripting | CVSS3: 8 | 14% Средний | больше 3 лет назад | |
GHSA-3hx3-v4g2-hgqp Under certain conditions, SAP Business One Hana Chef Cookbook, versions - 8.82, 9.0, 9.1, 9.2, 9.3, 10.0, used to install SAP Business One for SAP HANA, allows an attacker to exploit an insecure temporary backup path and to access information which would otherwise be restricted, resulting in Information Disclosure vulnerability highly impacting the confidentiality, integrity and availability of the application. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-3hx3-6qpf-m689 CVE was unused by HPE. | около 3 лет назад | |||
GHSA-3hwx-vc7v-fw2m Crash in the RFC 7468 dissector in Wireshark 3.6.0 and 3.4.0 to 3.4.10 allows denial of service via packet injection or crafted capture file | CVSS3: 7.5 | 0% Низкий | около 4 лет назад | |
GHSA-3hwx-j4f5-4679 The Brizy – Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the storeImages function in all versions up to, and including, 2.4.40. This makes it possible for authenticated attackers, with contributor access or above, to upload arbitrary files on the affected site's server which may make remote code execution possible. | CVSS3: 8.8 | 10% Низкий | почти 2 года назад | |
GHSA-3hwx-c6cp-q972 Publify vulnerable to cross site scripting | CVSS3: 9.1 | 0% Низкий | больше 3 лет назад | |
GHSA-3hww-w3cw-c9cm Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Daniel Floeter Hyperlink Group Block allows DOM-Based XSS. This issue affects Hyperlink Group Block: from n/a through 2.0.1. | CVSS3: 6.5 | 0% Низкий | 10 месяцев назад | |
GHSA-3hww-45xr-whm4 In telephony service, there is a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. | CVSS3: 5.5 | 0% Низкий | больше 2 лет назад | |
GHSA-3hwv-x5p9-3h2h In Bluetooth, there is a possible way to pair a display only device without PIN confirmation due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-222289114 | CVSS3: 3.3 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу