Количество 314 458
Количество 314 458
GHSA-3f5j-mfg2-hxvj
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.8.1.
GHSA-3f5j-jpr4-g85r
Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the time parameter in the saveParentControlInfo function.
GHSA-3f5j-4h2q-jfx9
sudo 1.6.0 through 1.7.10p6 and sudo 1.8.0 through 1.8.6p6 allows local users or physically proximate attackers to bypass intended time restrictions and retain privileges without re-authenticating by setting the system clock and sudo user timestamp to the epoch.
GHSA-3f5j-23xp-rpp7
In the GetOpenCLCachedFilesDirectory function in magick/opencl.c in ImageMagick 7.0.7, a NULL pointer dereference vulnerability occurs because a memory allocation result is not checked, related to GetOpenCLCacheDirectory.
GHSA-3f5h-5c3g-c68c
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'deleteUserCcDraftPost' function in all versions up to, and including, 8.7.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change the status of arbitrary posts to trash.
GHSA-3f5g-f3vm-8xqf
Authconfig version 6.2.8 is vulnerable to an Information exposure while using SSSD to authenticate against remote server resulting in the leak of information about existing usernames.
GHSA-3f5g-9wm3-vq63
The mintToken function of a smart contract implementation for bzxcoin (BZX), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
GHSA-3f5f-xgrj-97pf
Parse Server is vulnerable to Server-Side Request Forgery (SSRF) via Instagram OAuth Adapter
GHSA-3f5f-x3vv-f92r
The password protection feature of Microsoft Money can store the password in plaintext, which allows attackers with physical access to the system to obtain the password, aka the "Money Password" vulnerability.
GHSA-3f5f-g8gg-c73f
Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Sun Products Suite 2.1.1 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Administration.
GHSA-3f5c-xpwv-8wgm
In the Linux kernel, the following vulnerability has been resolved: media: i2c: dw9714: Disable the regulator when the driver fails to probe When the driver fails to probe, we will get the following splat: [ 59.305988] ------------[ cut here ]------------ [ 59.306417] WARNING: CPU: 2 PID: 395 at drivers/regulator/core.c:2257 _regulator_put+0x3ec/0x4e0 [ 59.310345] RIP: 0010:_regulator_put+0x3ec/0x4e0 [ 59.318362] Call Trace: [ 59.318582] <TASK> [ 59.318765] regulator_put+0x1f/0x30 [ 59.319058] devres_release_group+0x319/0x3d0 [ 59.319420] i2c_device_probe+0x766/0x940 Fix this by disabling the regulator in error handling.
GHSA-3f5c-4qxj-vmpf
Next.js Directory Traversal Vulnerability
GHSA-3f5c-485h-v36h
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CleverSoft Anon anon2x allows Reflected XSS.This issue affects Anon: from n/a through <= 2.2.10.
GHSA-3f59-325x-78rx
Insecure inherited permissions for the Intel(R) NUC M15 Laptop Kit Driver Pack software before updated version 1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
GHSA-3f58-74qw-ph75
TYPO3 allows remote attackers to embed Flash videos from external domain
GHSA-3f58-59wc-xqp9
Heap-based buffer overflow in the DrawImage function in magick/draw.c in ImageMagick before 6.9.5-5 allows remote attackers to cause a denial of service (application crash) via a crafted image file.
GHSA-3f58-3q4v-mmv6
Rejected reason: Not used
GHSA-3f57-w2rp-72fc
Undertow Uncaught Exception vulnerability
GHSA-3f57-p85f-5486
In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.
GHSA-3f56-hcw5-g566
GPAC v1.1.0 was discovered to contain an invalid memory address dereference via the function gf_sg_vrml_mf_reset(). This vulnerability allows attackers to cause a Denial of Service (DoS).
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3f5j-mfg2-hxvj Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in JS Help Desk JS Help Desk – Best Help Desk & Support Plugin.This issue affects JS Help Desk – Best Help Desk & Support Plugin: from n/a through 2.8.1. | CVSS3: 9.3 | 0% Низкий | около 2 лет назад | |
GHSA-3f5j-jpr4-g85r Tenda AC6 v15.03.05.09_multi was discovered to contain a stack overflow via the time parameter in the saveParentControlInfo function. | CVSS3: 9.8 | 0% Низкий | почти 4 года назад | |
GHSA-3f5j-4h2q-jfx9 sudo 1.6.0 through 1.7.10p6 and sudo 1.8.0 through 1.8.6p6 allows local users or physically proximate attackers to bypass intended time restrictions and retain privileges without re-authenticating by setting the system clock and sudo user timestamp to the epoch. | 8% Низкий | больше 3 лет назад | ||
GHSA-3f5j-23xp-rpp7 In the GetOpenCLCachedFilesDirectory function in magick/opencl.c in ImageMagick 7.0.7, a NULL pointer dereference vulnerability occurs because a memory allocation result is not checked, related to GetOpenCLCacheDirectory. | CVSS3: 8.8 | 1% Низкий | больше 3 лет назад | |
GHSA-3f5h-5c3g-c68c The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'deleteUserCcDraftPost' function in all versions up to, and including, 8.7.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to change the status of arbitrary posts to trash. | CVSS3: 5.4 | 0% Низкий | 3 месяца назад | |
GHSA-3f5g-f3vm-8xqf Authconfig version 6.2.8 is vulnerable to an Information exposure while using SSSD to authenticate against remote server resulting in the leak of information about existing usernames. | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад | |
GHSA-3f5g-9wm3-vq63 The mintToken function of a smart contract implementation for bzxcoin (BZX), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
GHSA-3f5f-xgrj-97pf Parse Server is vulnerable to Server-Side Request Forgery (SSRF) via Instagram OAuth Adapter | 0% Низкий | около 2 месяцев назад | ||
GHSA-3f5f-x3vv-f92r The password protection feature of Microsoft Money can store the password in plaintext, which allows attackers with physical access to the system to obtain the password, aka the "Money Password" vulnerability. | 0% Низкий | почти 4 года назад | ||
GHSA-3f5f-g8gg-c73f Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Sun Products Suite 2.1.1 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Administration. | 40% Средний | больше 3 лет назад | ||
GHSA-3f5c-xpwv-8wgm In the Linux kernel, the following vulnerability has been resolved: media: i2c: dw9714: Disable the regulator when the driver fails to probe When the driver fails to probe, we will get the following splat: [ 59.305988] ------------[ cut here ]------------ [ 59.306417] WARNING: CPU: 2 PID: 395 at drivers/regulator/core.c:2257 _regulator_put+0x3ec/0x4e0 [ 59.310345] RIP: 0010:_regulator_put+0x3ec/0x4e0 [ 59.318362] Call Trace: [ 59.318582] <TASK> [ 59.318765] regulator_put+0x1f/0x30 [ 59.319058] devres_release_group+0x319/0x3d0 [ 59.319420] i2c_device_probe+0x766/0x940 Fix this by disabling the regulator in error handling. | CVSS3: 5.5 | 0% Низкий | 4 месяца назад | |
GHSA-3f5c-4qxj-vmpf Next.js Directory Traversal Vulnerability | CVSS3: 7.5 | 83% Высокий | около 8 лет назад | |
GHSA-3f5c-485h-v36h Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CleverSoft Anon anon2x allows Reflected XSS.This issue affects Anon: from n/a through <= 2.2.10. | CVSS3: 7.1 | 0% Низкий | 17 дней назад | |
GHSA-3f59-325x-78rx Insecure inherited permissions for the Intel(R) NUC M15 Laptop Kit Driver Pack software before updated version 1.1 may allow an authenticated user to potentially enable escalation of privilege via local access. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-3f58-74qw-ph75 TYPO3 allows remote attackers to embed Flash videos from external domain | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-3f58-59wc-xqp9 Heap-based buffer overflow in the DrawImage function in magick/draw.c in ImageMagick before 6.9.5-5 allows remote attackers to cause a denial of service (application crash) via a crafted image file. | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
GHSA-3f58-3q4v-mmv6 Rejected reason: Not used | около 2 месяцев назад | |||
GHSA-3f57-w2rp-72fc Undertow Uncaught Exception vulnerability | CVSS3: 5.9 | 4% Низкий | больше 3 лет назад | |
GHSA-3f57-p85f-5486 In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services. | CVSS3: 5.5 | 0% Низкий | около 3 лет назад | |
GHSA-3f56-hcw5-g566 GPAC v1.1.0 was discovered to contain an invalid memory address dereference via the function gf_sg_vrml_mf_reset(). This vulnerability allows attackers to cause a Denial of Service (DoS). | CVSS3: 5.5 | 0% Низкий | около 4 лет назад |
Уязвимостей на страницу