Количество 314 458
Количество 314 458
GHSA-3c7p-vv5r-cmr5
Incorrect Authorization in Apache Solr
GHSA-3c7p-pp83-vmm8
A remote URL redirection vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability.
GHSA-3c7p-7jhh-gw98
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.0.14878. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-4737.
GHSA-3c7h-926p-7f94
In the Linux kernel, the following vulnerability has been resolved: can: gs_usb: gs_usb_xmit_callback(): fix handling of failed transmitted URBs The driver lacks the cleanup of failed transfers of URBs. This reduces the number of available URBs per error by 1. This leads to reduced performance and ultimately to a complete stop of the transmission. If the sending of a bulk URB fails do proper cleanup: - increase netdev stats - mark the echo_sbk as free - free the driver's context and do accounting - wake the send queue
GHSA-3c7g-p9jx-8cgm
GeniXCMS Cross-site Scripting (XSS) via the Menu ID field
GHSA-3c7g-8x9w-wjqp
Dahua DVR appliances have a hardcoded password for (1) the root account and (2) an unspecified "backdoor" account, which makes it easier for remote attackers to obtain administrative access via authorization requests involving (a) ActiveX, (b) a standalone client, or (c) unknown other vectors.
GHSA-3c7g-7r78-c425
An arbitrary file upload vulnerability in the Ueditor component of productinfoquick v1.0 allows attackers to execute arbitrary code via uploading a crafted PNG file.
GHSA-3c7g-3984-748r
Integer overflow in Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code via a crafted SWF file with a negative Scene Count value, which passes a signed comparison, is used as an offset of a NULL pointer, and triggers a buffer overflow.
GHSA-3c7c-p4m9-gwhc
Korenix JetWave 4200 Series 1.3.0 and JetWave 3200 Series 1.6.0 are vulnerable to Denial of Service via /goform/formDefault.
GHSA-3c7c-8hj4-v9qh
In versions of the PEADM Forge Module prior to 3.24.0 a security misconfiguration was discovered.
GHSA-3c7c-8h8f-3p6v
Use After Free in GitHub repository vim/vim prior to 8.2.
GHSA-3c79-rgf5-v4gg
Stack-based buffer overflow in the request handling implementation in Sun Java Active Server Pages (ASP) Server before 4.0.3 allows remote attackers to execute arbitrary code via an unspecified string field.
GHSA-3c78-wrg5-fqxr
The issue was addressed with improved memory handling. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, watchOS 10, tvOS 17. An app may be able to execute arbitrary code with kernel privileges.
GHSA-3c78-m682-8wp9
ChakraCore RCE Vulnerability
GHSA-3c77-w2fc-xqrh
Multiple cross-site scripting (XSS) vulnerabilities in the Gateway component in Sun Java System Portal Server 6.3.1, 7.1, and 7.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
GHSA-3c77-6pw4-hr87
Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection while adding file shares.
GHSA-3c76-p447-jmg2
HCL Sametime is impacted by misconfigured security related HTTP headers. It was identified that some HTTP headers were missing on web service responses. This will lead to less secure browser default treatment for the policies controlled by these headers.
GHSA-3c75-fpmc-wjhf
Privilege escalation vulnerability in the PMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
GHSA-3c75-76g3-hcrx
Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled function module. This could provide the attacker with full control of the system hence leading to high impact on confidentiality, integrity and availability of the system.
GHSA-3c74-p5qr-hhhx
The Contest Gallery – Upload, Vote & Sell with PayPal and Stripe plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 27.0.3 via gallery submissions. This makes it possible for unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3c7p-vv5r-cmr5 Incorrect Authorization in Apache Solr | CVSS3: 9.8 | 85% Высокий | почти 4 года назад | |
GHSA-3c7p-pp83-vmm8 A remote URL redirection vulnerability was discovered in Aruba AirWave Management Platform version(s) prior to 8.2.12.1. Aruba has released patches for AirWave Management Platform that address this security vulnerability. | 0% Низкий | больше 3 лет назад | ||
GHSA-3c7p-7jhh-gw98 This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.0.14878. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-4737. | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад | |
GHSA-3c7h-926p-7f94 In the Linux kernel, the following vulnerability has been resolved: can: gs_usb: gs_usb_xmit_callback(): fix handling of failed transmitted URBs The driver lacks the cleanup of failed transfers of URBs. This reduces the number of available URBs per error by 1. This leads to reduced performance and ultimately to a complete stop of the transmission. If the sending of a bulk URB fails do proper cleanup: - increase netdev stats - mark the echo_sbk as free - free the driver's context and do accounting - wake the send queue | 0% Низкий | около 2 месяцев назад | ||
GHSA-3c7g-p9jx-8cgm GeniXCMS Cross-site Scripting (XSS) via the Menu ID field | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-3c7g-8x9w-wjqp Dahua DVR appliances have a hardcoded password for (1) the root account and (2) an unspecified "backdoor" account, which makes it easier for remote attackers to obtain administrative access via authorization requests involving (a) ActiveX, (b) a standalone client, or (c) unknown other vectors. | 9% Низкий | больше 3 лет назад | ||
GHSA-3c7g-7r78-c425 An arbitrary file upload vulnerability in the Ueditor component of productinfoquick v1.0 allows attackers to execute arbitrary code via uploading a crafted PNG file. | CVSS3: 9.8 | 0% Низкий | больше 1 года назад | |
GHSA-3c7g-3984-748r Integer overflow in Adobe Flash Player 9.0.115.0 and earlier, and 8.0.39.0 and earlier, allows remote attackers to execute arbitrary code via a crafted SWF file with a negative Scene Count value, which passes a signed comparison, is used as an offset of a NULL pointer, and triggers a buffer overflow. | 87% Высокий | почти 4 года назад | ||
GHSA-3c7c-p4m9-gwhc Korenix JetWave 4200 Series 1.3.0 and JetWave 3200 Series 1.6.0 are vulnerable to Denial of Service via /goform/formDefault. | CVSS3: 6.5 | 0% Низкий | почти 3 года назад | |
GHSA-3c7c-8hj4-v9qh In versions of the PEADM Forge Module prior to 3.24.0 a security misconfiguration was discovered. | 0% Низкий | больше 1 года назад | ||
GHSA-3c7c-8h8f-3p6v Use After Free in GitHub repository vim/vim prior to 8.2. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-3c79-rgf5-v4gg Stack-based buffer overflow in the request handling implementation in Sun Java Active Server Pages (ASP) Server before 4.0.3 allows remote attackers to execute arbitrary code via an unspecified string field. | 13% Средний | почти 4 года назад | ||
GHSA-3c78-wrg5-fqxr The issue was addressed with improved memory handling. This issue is fixed in iOS 17 and iPadOS 17, macOS Sonoma 14, watchOS 10, tvOS 17. An app may be able to execute arbitrary code with kernel privileges. | CVSS3: 6.6 | 0% Низкий | больше 1 года назад | |
GHSA-3c78-m682-8wp9 ChakraCore RCE Vulnerability | CVSS3: 7.5 | 24% Средний | больше 3 лет назад | |
GHSA-3c77-w2fc-xqrh Multiple cross-site scripting (XSS) vulnerabilities in the Gateway component in Sun Java System Portal Server 6.3.1, 7.1, and 7.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 0% Низкий | почти 4 года назад | ||
GHSA-3c77-6pw4-hr87 Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection while adding file shares. | CVSS3: 8.3 | 1% Низкий | больше 1 года назад | |
GHSA-3c76-p447-jmg2 HCL Sametime is impacted by misconfigured security related HTTP headers. It was identified that some HTTP headers were missing on web service responses. This will lead to less secure browser default treatment for the policies controlled by these headers. | CVSS3: 5.8 | 0% Низкий | больше 1 года назад | |
GHSA-3c75-fpmc-wjhf Privilege escalation vulnerability in the PMS module Impact: Successful exploitation of this vulnerability may affect service confidentiality. | CVSS3: 7.1 | 0% Низкий | больше 1 года назад | |
GHSA-3c75-76g3-hcrx Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled function module. This could provide the attacker with full control of the system hence leading to high impact on confidentiality, integrity and availability of the system. | CVSS3: 9.9 | 0% Низкий | 2 месяца назад | |
GHSA-3c74-p5qr-hhhx The Contest Gallery – Upload, Vote & Sell with PayPal and Stripe plugin for WordPress is vulnerable to CSV Injection in all versions up to, and including, 27.0.3 via gallery submissions. This makes it possible for unauthenticated attackers to embed untrusted input into exported CSV files, which can result in code execution when these files are downloaded and opened on a local system with a vulnerable configuration. | CVSS3: 4.3 | 0% Низкий | 4 месяца назад |
Уязвимостей на страницу