Количество 314 691
Количество 314 691
GHSA-38h6-gmr2-j4wx
Silverstripe Form Capture vulnerable to stored cross-site-scripting
GHSA-38h5-q5q6-wmqj
Cloudera Hue 4.6.0 allows XSS via the type parameter.
GHSA-38h5-7v7x-v6pw
In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Fix invalid data access in ath12k_dp_rx_h_undecap_nwifi In certain cases, hardware might provide packets with a length greater than the maximum native Wi-Fi header length. This can lead to accessing and modifying fields in the header within the ath12k_dp_rx_h_undecap_nwifi function for DP_RX_DECAP_TYPE_NATIVE_WIFI decap type and potentially resulting in invalid data access and memory corruption. Add a sanity check before processing the SKB to prevent invalid data access in the undecap native Wi-Fi function for the DP_RX_DECAP_TYPE_NATIVE_WIFI decap type. Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.3.1-00173-QCAHKSWPL_SILICONZ-1
GHSA-38h4-p674-c649
Cross-Site Request Forgery (CSRF) vulnerability in LeadSquared, Inc LeadSquared Suite plugin <= 0.7.4 versions.
GHSA-38h4-hmr8-8c7q
Memory corruption when IOCTL call is invoked from user-space to read board data.
GHSA-38h4-fx85-qcx7
Exiv2 allows Use After Free
GHSA-38h4-92v3-hhh5
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability This CVE ID is unique from CVE-2020-17005, CVE-2020-17006, CVE-2020-17018.
GHSA-38h4-4x7h-qprw
Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, failed to prevent certain UI elements from being displayed by non-visible pages, which allowed a remote attacker to show certain UI elements on a page they don't control via a crafted HTML page.
GHSA-38h4-3233-xrh9
Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier allows remote authenticated users to affect availability via vectors related to DML.
GHSA-38h3-wj4x-mm5c
unix_random.c in lshd for lsh 2.0.1 leaks file descriptors related to the randomness generator, which allows local users to cause a denial of service by truncating the seed file, which prevents the server from starting, or obtain sensitive seed information that could be used to crack keys.
GHSA-38h3-jcwf-hx88
External Control of Critical State Data, Improper Control of Generation of Code ('Code Injection') vulnerability in YugaByte, Inc. Yugabyte DB on Windows, Linux, MacOS, iOS (DevopsBase.Java:execCommand, TableManager.Java:runCommand modules) allows API Manipulation, Privilege Abuse. This vulnerability is associated with program files backup.Py. This issue affects Yugabyte DB: Lesser then 2.2.
GHSA-38gx-pgpj-9cw5
Luocms v2.0 is affected by an incorrect access control vulnerability. Through /admin/templates/template_manage.php, an attacker can write an arbitrary shell file.
GHSA-38gw-wmv7-g95w
Cross-site scripting (XSS) vulnerability in the duwasai flashy theme 1.3 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
GHSA-38gw-6g45-69p7
GTK+ 3.10.9 and earlier, as used in cinnamon-screensaver, gnome-screensaver, and other applications, allows physically proximate attackers to bypass the lock screen by pressing the menu button.
GHSA-38gv-g72v-rp63
SELinux policycoreutils allows local users to execute arbitrary commands outside of the sandbox via a crafted TIOCSTI ioctl call.
GHSA-38gv-cwr5-whgg
An issue was discovered in Exiv2 v0.26. The function Exiv2::DataValue::copy in value.cpp has a NULL pointer dereference.
GHSA-38gr-cjjp-3f5w
When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note: The HTTP/3 QUIC module is not enabled by default and is considered experimental. For more information, refer to Support for QUIC and HTTP/3 https://nginx.org/en/docs/quic.html . Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
GHSA-38gq-f4qx-7pmw
Untrusted search path vulnerability in Installer for Shin Sekiyu Yunyu Chousa Houkoku Data Nyuryoku Program (program released on 2013 September 30) distributed on the website until 2017 May 17 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
GHSA-38gp-wr3c-cqw7
cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon the enabling of backups (SEC-342).
GHSA-38gp-wf27-935r
The bin-collect package in PyPI before v0.1 included a code execution backdoor inserted by a third party.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-38h6-gmr2-j4wx Silverstripe Form Capture vulnerable to stored cross-site-scripting | CVSS3: 6.1 | 1% Низкий | почти 3 года назад | |
GHSA-38h5-q5q6-wmqj Cloudera Hue 4.6.0 allows XSS via the type parameter. | 0% Низкий | больше 3 лет назад | ||
GHSA-38h5-7v7x-v6pw In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: Fix invalid data access in ath12k_dp_rx_h_undecap_nwifi In certain cases, hardware might provide packets with a length greater than the maximum native Wi-Fi header length. This can lead to accessing and modifying fields in the header within the ath12k_dp_rx_h_undecap_nwifi function for DP_RX_DECAP_TYPE_NATIVE_WIFI decap type and potentially resulting in invalid data access and memory corruption. Add a sanity check before processing the SKB to prevent invalid data access in the undecap native Wi-Fi function for the DP_RX_DECAP_TYPE_NATIVE_WIFI decap type. Tested-on: QCN9274 hw2.0 PCI WLAN.WBE.1.3.1-00173-QCAHKSWPL_SILICONZ-1 | CVSS3: 7.8 | 0% Низкий | 9 месяцев назад | |
GHSA-38h4-p674-c649 Cross-Site Request Forgery (CSRF) vulnerability in LeadSquared, Inc LeadSquared Suite plugin <= 0.7.4 versions. | CVSS3: 7.1 | 0% Низкий | больше 2 лет назад | |
GHSA-38h4-hmr8-8c7q Memory corruption when IOCTL call is invoked from user-space to read board data. | CVSS3: 7.8 | 0% Низкий | около 1 года назад | |
GHSA-38h4-fx85-qcx7 Exiv2 allows Use After Free | 1% Низкий | 12 месяцев назад | ||
GHSA-38h4-92v3-hhh5 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability This CVE ID is unique from CVE-2020-17005, CVE-2020-17006, CVE-2020-17018. | CVSS3: 5.4 | 1% Низкий | больше 3 лет назад | |
GHSA-38h4-4x7h-qprw Blink in Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, failed to prevent certain UI elements from being displayed by non-visible pages, which allowed a remote attacker to show certain UI elements on a page they don't control via a crafted HTML page. | CVSS3: 6.5 | 1% Низкий | больше 3 лет назад | |
GHSA-38h4-3233-xrh9 Unspecified vulnerability in Oracle MySQL 5.6.27 and earlier allows remote authenticated users to affect availability via vectors related to DML. | 1% Низкий | больше 3 лет назад | ||
GHSA-38h3-wj4x-mm5c unix_random.c in lshd for lsh 2.0.1 leaks file descriptors related to the randomness generator, which allows local users to cause a denial of service by truncating the seed file, which prevents the server from starting, or obtain sensitive seed information that could be used to crack keys. | 0% Низкий | почти 4 года назад | ||
GHSA-38h3-jcwf-hx88 External Control of Critical State Data, Improper Control of Generation of Code ('Code Injection') vulnerability in YugaByte, Inc. Yugabyte DB on Windows, Linux, MacOS, iOS (DevopsBase.Java:execCommand, TableManager.Java:runCommand modules) allows API Manipulation, Privilege Abuse. This vulnerability is associated with program files backup.Py. This issue affects Yugabyte DB: Lesser then 2.2. | CVSS3: 9.8 | 0% Низкий | около 3 лет назад | |
GHSA-38gx-pgpj-9cw5 Luocms v2.0 is affected by an incorrect access control vulnerability. Through /admin/templates/template_manage.php, an attacker can write an arbitrary shell file. | CVSS3: 9.8 | 0% Низкий | почти 4 года назад | |
GHSA-38gw-wmv7-g95w Cross-site scripting (XSS) vulnerability in the duwasai flashy theme 1.3 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 0% Низкий | больше 3 лет назад | ||
GHSA-38gw-6g45-69p7 GTK+ 3.10.9 and earlier, as used in cinnamon-screensaver, gnome-screensaver, and other applications, allows physically proximate attackers to bypass the lock screen by pressing the menu button. | 0% Низкий | больше 3 лет назад | ||
GHSA-38gv-g72v-rp63 SELinux policycoreutils allows local users to execute arbitrary commands outside of the sandbox via a crafted TIOCSTI ioctl call. | CVSS3: 8.8 | 0% Низкий | больше 3 лет назад | |
GHSA-38gv-cwr5-whgg An issue was discovered in Exiv2 v0.26. The function Exiv2::DataValue::copy in value.cpp has a NULL pointer dereference. | CVSS3: 6.5 | 1% Низкий | больше 3 лет назад | |
GHSA-38gr-cjjp-3f5w When NGINX Plus or NGINX OSS are configured to use the HTTP/3 QUIC module, undisclosed requests can cause NGINX worker processes to terminate. Note: The HTTP/3 QUIC module is not enabled by default and is considered experimental. For more information, refer to Support for QUIC and HTTP/3 https://nginx.org/en/docs/quic.html . Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | CVSS3: 7.5 | 0% Низкий | почти 2 года назад | |
GHSA-38gq-f4qx-7pmw Untrusted search path vulnerability in Installer for Shin Sekiyu Yunyu Chousa Houkoku Data Nyuryoku Program (program released on 2013 September 30) distributed on the website until 2017 May 17 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-38gp-wr3c-cqw7 cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon the enabling of backups (SEC-342). | CVSS3: 3.3 | 0% Низкий | больше 3 лет назад | |
GHSA-38gp-wf27-935r The bin-collect package in PyPI before v0.1 included a code execution backdoor inserted by a third party. | CVSS3: 9.8 | 1% Низкий | больше 3 лет назад |
Уязвимостей на страницу