Количество 301 840
Количество 301 840
GHSA-296j-r9gr-7w2c
Dell Dock Firmware and Dell Client Platform contain an Improper Link Resolution vulnerability during installation resulting in arbitrary folder deletion, which could lead to Privilege Escalation or Denial of Service.
GHSA-296j-2h87-8rxh
Visual Studio Code ESLint Extension Remote Code Execution Vulnerability
GHSA-296j-266h-6jc4
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
GHSA-296h-f7c6-qrvp
Stack-based buffer overflow in Jasc Paint Shop Pro 8.10 (aka Corel Paint Shop Pro) allows user-assisted remote attackers to execute arbitrary code via a crafted PNG file. NOTE: this might be the same issue as CVE-2007-2366.
GHSA-296g-m5cw-f8p9
A vulnerability in Cisco AMP for Endpoints Linux Connector Software and Cisco AMP for Endpoints Mac Connector Software could allow an authenticated, local attacker to cause a buffer overflow on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted packet to an affected device. A successful exploit could allow the attacker to cause the Cisco AMP for Endpoints service to crash and restart.
GHSA-296f-j97f-9r25
IOHIDFamily in Apple OS X before 10.10 allows attackers to cause denial of service (out-of-bounds read operation) via a crafted application.
GHSA-296f-cx2x-g274
SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the userService API model.
GHSA-296f-9hr7-4mwq
Stored Cross-Site Scripting in the Access Request History in Omada Identity before version 15 update 1 allows an authenticated attacker to execute arbitrary code in the browser of a victim via a specially crafted link or by viewing a manipulated Access Request History
GHSA-296f-4hq2-5r99
Web authoring command in Microsoft Content Management Server (MCMS) 2001 allows attackers to authenticate and upload executable content, by modifying the upload location, aka "Program Execution via MCMS Authoring Function."
GHSA-296c-8m99-q77p
Memory corruption when preparing a shared memory notification for a memparcel in Resource Manager.
GHSA-2969-8hh9-57jc
Allocation of Resources Without Limits or Throttling in ckb
GHSA-2969-2qqp-g57c
cPanel before 67.9999.103 allows code execution in the context of the mailman account because of incorrect environment-variable filtering (SEC-302).
GHSA-2968-xc5j-q436
The OC_Util::getUrlContent function in ownCloud Server before 5.0.18, 6.x before 6.0.6, and 7.x before 7.0.3 allows remote attackers to read arbitrary files via a file:// protocol.
GHSA-2968-wv79-2wqf
HCL BigFix Mobile 3.3 and earlier is affected by improper access control. Unauthorized users can access a small subset of endpoint actions, potentially allowing access to select internal functions.
GHSA-2968-fmvc-r6gw
Signal Handler Race Condition vulnerability in Mitsubishi Electric India GC-ENET-COM whose first 2 digits of 11-digit serial number of unit are "16" allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition in Ethernet communication by sending a large number of specially crafted packets to any UDP port when GC-ENET-COM is configured as a Modbus TCP Server. The communication resumes only when the power of the main unit is turned off and on or when the GC-ENET-COM is hot-swapped from the main unit.
GHSA-2968-6vjj-whq8
Phicomm K2G v22.6.3.20 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the automatic upgrade function.
GHSA-2967-w8m2-xw7h
PHP remote file inclusion vulnerability in class.cs_phpmailer.php in CS-Cart 1.3.3 allows remote attackers to execute arbitrary PHP code via a URL in the classes_dir parameter.
GHSA-2966-gh5h-j633
The session extension in PHP 4 before 4.4.5, and PHP 5 before 5.2.1, calculates the reference count for the session variables without considering the internal pointer from the session globals, which allows context-dependent attackers to execute arbitrary code via a crafted string in the session_register after unsetting HTTP_SESSION_VARS and _SESSION, which destroys the session data Hashtable.
GHSA-2965-8m5f-3hph
Insufficient policy enforcement in Extensions API in Google Chrome prior to 116.0.5845.96 allowed an attacker who convinced a user to install a malicious extension to bypass an enterprise policy via a crafted HTML page. (Chromium security severity: Medium)
GHSA-2963-qpfw-w3r2
InDesign Desktop versions ID18.5.2, ID19.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to an application denial-of-service (DoS). An attacker could exploit this vulnerability to crash the application, resulting in a denial of service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-296j-r9gr-7w2c Dell Dock Firmware and Dell Client Platform contain an Improper Link Resolution vulnerability during installation resulting in arbitrary folder deletion, which could lead to Privilege Escalation or Denial of Service. | CVSS3: 6.7 | 0% Низкий | около 1 года назад | |
GHSA-296j-2h87-8rxh Visual Studio Code ESLint Extension Remote Code Execution Vulnerability | CVSS3: 7.8 | 6% Низкий | больше 3 лет назад | |
GHSA-296j-266h-6jc4 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-296h-f7c6-qrvp Stack-based buffer overflow in Jasc Paint Shop Pro 8.10 (aka Corel Paint Shop Pro) allows user-assisted remote attackers to execute arbitrary code via a crafted PNG file. NOTE: this might be the same issue as CVE-2007-2366. | 8% Низкий | больше 3 лет назад | ||
GHSA-296g-m5cw-f8p9 A vulnerability in Cisco AMP for Endpoints Linux Connector Software and Cisco AMP for Endpoints Mac Connector Software could allow an authenticated, local attacker to cause a buffer overflow on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted packet to an affected device. A successful exploit could allow the attacker to cause the Cisco AMP for Endpoints service to crash and restart. | 0% Низкий | больше 3 лет назад | ||
GHSA-296f-j97f-9r25 IOHIDFamily in Apple OS X before 10.10 allows attackers to cause denial of service (out-of-bounds read operation) via a crafted application. | 0% Низкий | больше 3 лет назад | ||
GHSA-296f-cx2x-g274 SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the userService API model. | CVSS3: 9.1 | 0% Низкий | 9 месяцев назад | |
GHSA-296f-9hr7-4mwq Stored Cross-Site Scripting in the Access Request History in Omada Identity before version 15 update 1 allows an authenticated attacker to execute arbitrary code in the browser of a victim via a specially crafted link or by viewing a manipulated Access Request History | CVSS3: 8 | 0% Низкий | 12 месяцев назад | |
GHSA-296f-4hq2-5r99 Web authoring command in Microsoft Content Management Server (MCMS) 2001 allows attackers to authenticate and upload executable content, by modifying the upload location, aka "Program Execution via MCMS Authoring Function." | 9% Низкий | больше 3 лет назад | ||
GHSA-296c-8m99-q77p Memory corruption when preparing a shared memory notification for a memparcel in Resource Manager. | CVSS3: 8.4 | 0% Низкий | больше 1 года назад | |
GHSA-2969-8hh9-57jc Allocation of Resources Without Limits or Throttling in ckb | CVSS3: 7.5 | 1% Низкий | почти 4 года назад | |
GHSA-2969-2qqp-g57c cPanel before 67.9999.103 allows code execution in the context of the mailman account because of incorrect environment-variable filtering (SEC-302). | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-2968-xc5j-q436 The OC_Util::getUrlContent function in ownCloud Server before 5.0.18, 6.x before 6.0.6, and 7.x before 7.0.3 allows remote attackers to read arbitrary files via a file:// protocol. | 0% Низкий | больше 3 лет назад | ||
GHSA-2968-wv79-2wqf HCL BigFix Mobile 3.3 and earlier is affected by improper access control. Unauthorized users can access a small subset of endpoint actions, potentially allowing access to select internal functions. | CVSS3: 5.3 | 0% Низкий | около 1 месяца назад | |
GHSA-2968-fmvc-r6gw Signal Handler Race Condition vulnerability in Mitsubishi Electric India GC-ENET-COM whose first 2 digits of 11-digit serial number of unit are "16" allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition in Ethernet communication by sending a large number of specially crafted packets to any UDP port when GC-ENET-COM is configured as a Modbus TCP Server. The communication resumes only when the power of the main unit is turned off and on or when the GC-ENET-COM is hot-swapped from the main unit. | CVSS3: 5.9 | 0% Низкий | больше 2 лет назад | |
GHSA-2968-6vjj-whq8 Phicomm K2G v22.6.3.20 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the automatic upgrade function. | CVSS3: 7.8 | 0% Низкий | почти 3 года назад | |
GHSA-2967-w8m2-xw7h PHP remote file inclusion vulnerability in class.cs_phpmailer.php in CS-Cart 1.3.3 allows remote attackers to execute arbitrary PHP code via a URL in the classes_dir parameter. | 9% Низкий | больше 3 лет назад | ||
GHSA-2966-gh5h-j633 The session extension in PHP 4 before 4.4.5, and PHP 5 before 5.2.1, calculates the reference count for the session variables without considering the internal pointer from the session globals, which allows context-dependent attackers to execute arbitrary code via a crafted string in the session_register after unsetting HTTP_SESSION_VARS and _SESSION, which destroys the session data Hashtable. | 5% Низкий | больше 3 лет назад | ||
GHSA-2965-8m5f-3hph Insufficient policy enforcement in Extensions API in Google Chrome prior to 116.0.5845.96 allowed an attacker who convinced a user to install a malicious extension to bypass an enterprise policy via a crafted HTML page. (Chromium security severity: Medium) | CVSS3: 8.8 | 0% Низкий | больше 2 лет назад | |
GHSA-2963-qpfw-w3r2 InDesign Desktop versions ID18.5.2, ID19.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to an application denial-of-service (DoS). An attacker could exploit this vulnerability to crash the application, resulting in a denial of service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | CVSS3: 5.5 | 0% Низкий | больше 1 года назад |
Уязвимостей на страницу