Количество 312 573
Количество 312 573
GHSA-39vh-5vp8-mrhx
coders/xwd.c in GraphicsMagick 1.3.31 allows attackers to cause a denial of service (floating-point exception and application crash) by crafting an XWD image file, a different vulnerability than CVE-2019-11008 and CVE-2019-11009.
GHSA-39vf-phfq-v8qr
The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<form action='data:text" attack.
GHSA-39vf-5xqf-2xfv
In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: fsl_upm: Fix an off-by one test in fun_exec_op() 'op-cs' is copied in 'fun->mchip_number' which is used to access the 'mchip_offsets' and the 'rnb_gpio' arrays. These arrays have NAND_MAX_CHIPS elements, so the index must be below this limit. Fix the sanity check in order to avoid the NAND_MAX_CHIPS value. This would lead to out-of-bound accesses.
GHSA-39vc-r5gw-mf5w
Incorrect security UI in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)
GHSA-39v7-xpq4-8884
PDFKit Improper Input Validation vulnerability
GHSA-39v7-36rj-8jh4
Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.9.0.
GHSA-39v6-whcc-chg3
LakeWeb Mail List CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the recipient email address.
GHSA-39v6-68rf-3jhj
In param_find_digests_internal and related functions of the Titan-M source, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-222472803References: N/A
GHSA-39v5-jf84-wf9c
SAP FI Manager Self-Service has a hard-coded user name, which makes it easier for remote attackers to obtain access via unspecified vectors.
GHSA-39v5-c8j7-2628
Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.27 allows remote attackers to cause a denial of service via unknown vectors, related to "an error in fixpacks 6.1.0.23 and 6.1.0.25."
GHSA-39v5-536x-qjhm
Multiple unspecified vulnerabilities in Webmatic before 2.7 have unknown impact and attack vectors, related to the "administration area."
GHSA-39v5-33fm-98f2
TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the cameo.cameo.nslookup_target parameter in the tools_nslookup function.
GHSA-39v4-qq8h-r3p9
A vulnerability has been found in UTT HiPER 840G up to 3.1.1-190328. Affected by this issue is the function strcpy of the file /goform/formTaskEdit. The manipulation of the argument txtMin2 leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
GHSA-39v4-4m6h-c4rm
Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'pass' parameter at School/teacher_login.php.
GHSA-39v3-f278-vj3g
@backstage/plugin-techdocs-backend storage bucket Directory Traversal vulnerability
GHSA-39v2-wqcx-xc5w
pscal in xcal 4.1 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/pscal##### temporary file.
GHSA-39v2-v4hx-4r39
The Acrobat web control in Adobe Acrobat and Acrobat Reader 7.0 and earlier, when used with Internet Explorer, allows remote attackers to determine the existence of arbitrary files via the LoadFile ActiveX method.
GHSA-39v2-r9rw-3qpx
In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper configuration of dev nodes may lead to potential security issue.
GHSA-39rx-hmmc-q5pv
A symlink following vulnerability in the pouch cp function of AliyunContainerService pouch v1.3.1 allows attackers to escalate privileges and write arbitrary files.
GHSA-39rw-v9vh-37g8
SQL injection vulnerability in store_pages/category_list.php in 5th Avenue Shopping Cart 1.2 trial edition allows remote attackers to execute arbitrary SQL commands via the category_ID parameter.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-39vh-5vp8-mrhx coders/xwd.c in GraphicsMagick 1.3.31 allows attackers to cause a denial of service (floating-point exception and application crash) by crafting an XWD image file, a different vulnerability than CVE-2019-11008 and CVE-2019-11009. | CVSS3: 6.5 | 3% Низкий | больше 3 лет назад | |
GHSA-39vf-phfq-v8qr The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<form action='data:text" attack. | CVSS3: 6.1 | 1% Низкий | больше 3 лет назад | |
GHSA-39vf-5xqf-2xfv In the Linux kernel, the following vulnerability has been resolved: mtd: rawnand: fsl_upm: Fix an off-by one test in fun_exec_op() 'op-cs' is copied in 'fun->mchip_number' which is used to access the 'mchip_offsets' and the 'rnb_gpio' arrays. These arrays have NAND_MAX_CHIPS elements, so the index must be below this limit. Fix the sanity check in order to avoid the NAND_MAX_CHIPS value. This would lead to out-of-bound accesses. | 0% Низкий | около 2 месяцев назад | ||
GHSA-39vc-r5gw-mf5w Incorrect security UI in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low) | CVSS3: 9.8 | 0% Низкий | 19 дней назад | |
GHSA-39v7-xpq4-8884 PDFKit Improper Input Validation vulnerability | CVSS3: 9.8 | 1% Низкий | почти 4 года назад | |
GHSA-39v7-36rj-8jh4 Heap-based Buffer Overflow in GitHub repository radareorg/radare2 prior to 5.9.0. | CVSS3: 5.1 | 0% Низкий | больше 2 лет назад | |
GHSA-39v6-whcc-chg3 LakeWeb Mail List CGI script allows remote attackers to execute arbitrary commands via shell metacharacters in the recipient email address. | 3% Низкий | почти 4 года назад | ||
GHSA-39v6-68rf-3jhj In param_find_digests_internal and related functions of the Titan-M source, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-222472803References: N/A | CVSS3: 6.7 | 0% Низкий | больше 3 лет назад | |
GHSA-39v5-jf84-wf9c SAP FI Manager Self-Service has a hard-coded user name, which makes it easier for remote attackers to obtain access via unspecified vectors. | 2% Низкий | больше 3 лет назад | ||
GHSA-39v5-c8j7-2628 Unspecified vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.27 allows remote attackers to cause a denial of service via unknown vectors, related to "an error in fixpacks 6.1.0.23 and 6.1.0.25." | 1% Низкий | почти 4 года назад | ||
GHSA-39v5-536x-qjhm Multiple unspecified vulnerabilities in Webmatic before 2.7 have unknown impact and attack vectors, related to the "administration area." | 0% Низкий | почти 4 года назад | ||
GHSA-39v5-33fm-98f2 TRENDnet TEW755AP 1.13B01 was discovered to contain a stack overflow via the cameo.cameo.nslookup_target parameter in the tools_nslookup function. | CVSS3: 9.8 | 0% Низкий | около 3 лет назад | |
GHSA-39v4-qq8h-r3p9 A vulnerability has been found in UTT HiPER 840G up to 3.1.1-190328. Affected by this issue is the function strcpy of the file /goform/formTaskEdit. The manipulation of the argument txtMin2 leads to buffer overflow. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 8.8 | 0% Низкий | 4 месяца назад | |
GHSA-39v4-4m6h-c4rm Code-projects Simple School Managment System 1.0 allows SQL Injection via the 'pass' parameter at School/teacher_login.php. | CVSS3: 8.8 | 0% Низкий | почти 2 года назад | |
GHSA-39v3-f278-vj3g @backstage/plugin-techdocs-backend storage bucket Directory Traversal vulnerability | CVSS3: 7.7 | 0% Низкий | больше 1 года назад | |
GHSA-39v2-wqcx-xc5w pscal in xcal 4.1 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/pscal##### temporary file. | 0% Низкий | больше 3 лет назад | ||
GHSA-39v2-v4hx-4r39 The Acrobat web control in Adobe Acrobat and Acrobat Reader 7.0 and earlier, when used with Internet Explorer, allows remote attackers to determine the existence of arbitrary files via the LoadFile ActiveX method. | 4% Низкий | почти 4 года назад | ||
GHSA-39v2-r9rw-3qpx In all android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper configuration of dev nodes may lead to potential security issue. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-39rx-hmmc-q5pv A symlink following vulnerability in the pouch cp function of AliyunContainerService pouch v1.3.1 allows attackers to escalate privileges and write arbitrary files. | CVSS3: 7.6 | 0% Низкий | больше 1 года назад | |
GHSA-39rw-v9vh-37g8 SQL injection vulnerability in store_pages/category_list.php in 5th Avenue Shopping Cart 1.2 trial edition allows remote attackers to execute arbitrary SQL commands via the category_ID parameter. | 1% Низкий | почти 4 года назад |
Уязвимостей на страницу