Количество 314 458
Количество 314 458
GHSA-398m-f4ch-cf26
Cryptocat before 2.0.22 has Nickname User Impersonation
GHSA-398m-55cm-6j6x
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
GHSA-398j-x47f-2q99
When sharing geolocation during an active WebRTC share, Firefox could have reset the webRTC sharing state in the user interface, leading to loss of control over the currently granted permission. This vulnerability affects Firefox < 85.
GHSA-398j-w8vh-r865
The Tomcat package on Red Hat Enterprise Linux (RHEL) 5 through 7, JBoss Web Server 3.0, and JBoss EWS 2 uses weak permissions for (1) /etc/sysconfig/tomcat and (2) /etc/tomcat/tomcat.conf, which allows local users to gain privileges by leveraging membership in the tomcat group.
GHSA-398j-r5c5-vrph
In Cloud Foundry router routing-release all versions prior to v0.163.0 and cf-release all versions prior to v274, in some applications, it is possible to append a combination of characters to the URL that will allow for an open redirect. An attacker could exploit this as a phishing attack to gain access to user credentials or other sensitive data. NOTE: 274 resolves the vulnerability but has a serious bug that is fixed in 275.
GHSA-398j-f7m7-795j
PHPMailer vulnerable to email header injection
GHSA-398j-37xh-xw92
SQL injection vulnerability in messages.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the msg_view parameter, a different vulnerability than CVE-2005-3157 and CVE-2005-3158.
GHSA-398g-xgm8-h7c4
Kaspersky Anti-Virus (KAV) and Internet Security 7.0 build 125 do not properly validate certain parameters to System Service Descriptor Table (SSDT) and Shadow SSDT function handlers, which allows local users to cause a denial of service (crash) via the (1) NtUserSendInput, (2) LoadLibraryA, (3) NtOpenProcess, (4) NtOpenThread, (5) NtTerminateProcess, (6) NtUserFindWindowEx, and (7) NtUserBuildHwndList kernel SSDT hooks in kylif.sys; the (8) NtDuplicateObject (DuplicateHandle) kernel SSDT hook; and possibly other kernel SSDT hooks. NOTE: the NtCreateSection vector is covered by CVE-2007-5043.1. NOTE: the vendor disputes that the DuplicateHandle vector is a vulnerability in their code, stating that "it is not an error in our code, but an obscure method for manipulating standard Windows routines to circumvent our self-defense mechanisms."
GHSA-398g-pgqg-vjj2
A local attacker may be able to elevate their privileges. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. A memory corruption issue was addressed with improved validation.
GHSA-398f-726v-q88v
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4. An app may be able to read sensitive location information.
GHSA-398f-443h-w6mr
Cryptocat before 2.0.22: cryptocat.js handlePresence() has cross site scripting
GHSA-398c-f7w9-crc8
A flaw was found in FFmpeg's TTY Demuxer. This vulnerability allows possible data exfiltration via improper parsing of non-TTY-compliant input files in HLS playlists.
GHSA-398c-7m57-4f84
Multiple integer overflows in drivers/crypto/msm/qcedev.c in the Qualcomm cryptographic engine driver in Android before 2016-10-05 on Nexus 5X, Nexus 6, Nexus 6P, and Android One devices allow attackers to gain privileges via a crafted application, aka Android internal bug 29999665 and Qualcomm internal bug CR 1046507.
GHSA-3989-vpff-cvxj
Missing Authorization vulnerability in actpro Extra Product Options for WooCommerce.This issue affects Extra Product Options for WooCommerce: from n/a through 3.0.6.
GHSA-3989-crp4-69hw
A vulnerability has been found in code-projects Blood Bank Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /file/updateprofile.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
GHSA-3989-4c6x-725f
XWiki Platform vulnerable to privilege escalation from view right on XWiki.AttachmentSelector
GHSA-3988-q8q7-p787
ash_authentication has email link auto-click account confirmation vulnerability
GHSA-3988-jj2m-p6m7
A vulnerability has been identified in Altair Grid Engine (All versions < V2026.0.0). Affected products do not properly validate environment variables when loading shared libraries, allowing path hijacking through malicious library substitution. This could allow a local attacker to execute arbitrary code with superuser privileges by manipulating the environment variable and placing a malicious library in the controlled path.
GHSA-3988-h75v-hwf6
Arbitrary shell execution
GHSA-3988-7v79-mrm7
HGiga EIP product contains SQL Injection vulnerability. Attackers can inject SQL commands into specific URL parameter (document management page) to obtain database schema and data.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-398m-f4ch-cf26 Cryptocat before 2.0.22 has Nickname User Impersonation | 0% Низкий | больше 3 лет назад | ||
GHSA-398m-55cm-6j6x Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | CVSS3: 7.6 | 0% Низкий | около 2 лет назад | |
GHSA-398j-x47f-2q99 When sharing geolocation during an active WebRTC share, Firefox could have reset the webRTC sharing state in the user interface, leading to loss of control over the currently granted permission. This vulnerability affects Firefox < 85. | 0% Низкий | больше 3 лет назад | ||
GHSA-398j-w8vh-r865 The Tomcat package on Red Hat Enterprise Linux (RHEL) 5 through 7, JBoss Web Server 3.0, and JBoss EWS 2 uses weak permissions for (1) /etc/sysconfig/tomcat and (2) /etc/tomcat/tomcat.conf, which allows local users to gain privileges by leveraging membership in the tomcat group. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-398j-r5c5-vrph In Cloud Foundry router routing-release all versions prior to v0.163.0 and cf-release all versions prior to v274, in some applications, it is possible to append a combination of characters to the URL that will allow for an open redirect. An attacker could exploit this as a phishing attack to gain access to user credentials or other sensitive data. NOTE: 274 resolves the vulnerability but has a serious bug that is fixed in 275. | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-398j-f7m7-795j PHPMailer vulnerable to email header injection | 0% Низкий | больше 3 лет назад | ||
GHSA-398j-37xh-xw92 SQL injection vulnerability in messages.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the msg_view parameter, a different vulnerability than CVE-2005-3157 and CVE-2005-3158. | 1% Низкий | почти 4 года назад | ||
GHSA-398g-xgm8-h7c4 Kaspersky Anti-Virus (KAV) and Internet Security 7.0 build 125 do not properly validate certain parameters to System Service Descriptor Table (SSDT) and Shadow SSDT function handlers, which allows local users to cause a denial of service (crash) via the (1) NtUserSendInput, (2) LoadLibraryA, (3) NtOpenProcess, (4) NtOpenThread, (5) NtTerminateProcess, (6) NtUserFindWindowEx, and (7) NtUserBuildHwndList kernel SSDT hooks in kylif.sys; the (8) NtDuplicateObject (DuplicateHandle) kernel SSDT hook; and possibly other kernel SSDT hooks. NOTE: the NtCreateSection vector is covered by CVE-2007-5043.1. NOTE: the vendor disputes that the DuplicateHandle vector is a vulnerability in their code, stating that "it is not an error in our code, but an obscure method for manipulating standard Windows routines to circumvent our self-defense mechanisms." | 0% Низкий | почти 4 года назад | ||
GHSA-398g-pgqg-vjj2 A local attacker may be able to elevate their privileges. This issue is fixed in macOS Big Sur 11.4, Security Update 2021-003 Catalina, Security Update 2021-004 Mojave. A memory corruption issue was addressed with improved validation. | 0% Низкий | больше 3 лет назад | ||
GHSA-398f-726v-q88v A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Ventura 13.3, iOS 16.4 and iPadOS 16.4. An app may be able to read sensitive location information. | CVSS3: 3.3 | 0% Низкий | около 2 лет назад | |
GHSA-398f-443h-w6mr Cryptocat before 2.0.22: cryptocat.js handlePresence() has cross site scripting | 0% Низкий | почти 4 года назад | ||
GHSA-398c-f7w9-crc8 A flaw was found in FFmpeg's TTY Demuxer. This vulnerability allows possible data exfiltration via improper parsing of non-TTY-compliant input files in HLS playlists. | CVSS3: 5.3 | 0% Низкий | около 1 года назад | |
GHSA-398c-7m57-4f84 Multiple integer overflows in drivers/crypto/msm/qcedev.c in the Qualcomm cryptographic engine driver in Android before 2016-10-05 on Nexus 5X, Nexus 6, Nexus 6P, and Android One devices allow attackers to gain privileges via a crafted application, aka Android internal bug 29999665 and Qualcomm internal bug CR 1046507. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-3989-vpff-cvxj Missing Authorization vulnerability in actpro Extra Product Options for WooCommerce.This issue affects Extra Product Options for WooCommerce: from n/a through 3.0.6. | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
GHSA-3989-crp4-69hw A vulnerability has been found in code-projects Blood Bank Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /file/updateprofile.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
GHSA-3989-4c6x-725f XWiki Platform vulnerable to privilege escalation from view right on XWiki.AttachmentSelector | CVSS3: 9.9 | 18% Средний | почти 3 года назад | |
GHSA-3988-q8q7-p787 ash_authentication has email link auto-click account confirmation vulnerability | CVSS3: 5.3 | 0% Низкий | 10 месяцев назад | |
GHSA-3988-jj2m-p6m7 A vulnerability has been identified in Altair Grid Engine (All versions < V2026.0.0). Affected products do not properly validate environment variables when loading shared libraries, allowing path hijacking through malicious library substitution. This could allow a local attacker to execute arbitrary code with superuser privileges by manipulating the environment variable and placing a malicious library in the controlled path. | CVSS3: 7.8 | 0% Низкий | 3 месяца назад | |
GHSA-3988-h75v-hwf6 Arbitrary shell execution | почти 4 года назад | |||
GHSA-3988-7v79-mrm7 HGiga EIP product contains SQL Injection vulnerability. Attackers can inject SQL commands into specific URL parameter (document management page) to obtain database schema and data. | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу