Количество 301 694
Количество 301 694
GHSA-28f5-mg2c-r34c
Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass intended restrictions on JavaScript API execution via unspecified vectors, a different vulnerability than CVE-2015-3060, CVE-2015-3061, CVE-2015-3062, CVE-2015-3063, CVE-2015-3064, CVE-2015-3065, CVE-2015-3066, CVE-2015-3067, CVE-2015-3068, CVE-2015-3069, CVE-2015-3071, CVE-2015-3072, and CVE-2015-3074.
GHSA-28f5-7mw6-mfmc
In AccountManager, there is a possible bypass of a permissions check due to a confused deputy. This could lead to local information disclosure, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-123700107
GHSA-28f5-7fwx-xrf3
When SWFTools 0.9.2 processes a crafted file in png2swf, it can lead to a Segmentation Violation in the png_load() function in lib/png.c.
GHSA-28f5-3rf2-gpm8
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.
GHSA-28f4-mjfq-qrvf
Malicious Package in buffes-xor
GHSA-28f4-f5wq-36wr
The WooCommerce POS plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 1.4.11. This is due to the plugin not properly verifying the authentication and authorization of the current user This makes it possible for authenticated attackers, with customer-level access and above, to view potentially sensitive information about other users by leveraging their order id
GHSA-28f4-9qfp-6f7v
An issue was discovered in Xpdf 4.01.01. There is an FPE in the function ImageStream::ImageStream at Stream.cc for nBits.
GHSA-28f3-rf96-2vvg
Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'txtPass' parameter of the login.php resource does not validate the characters received and they are sent unfiltered to the database.
GHSA-28f3-c95g-f4g3
In Wireshark 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11, the IxVeriWave file parser could crash. This was addressed in wiretap/vwr.c by correcting the signature timestamp bounds checks.
GHSA-28f2-gw74-5cpj
The setpermissions function in the auto-updater in Arq before 5.9.7 for Mac allows local users to gain root privileges via a symlink attack on the updater binary itself.
GHSA-28cx-j4v5-m5fv
Pluck CMS 4.7.18 does not restrict failed login attempts, allowing attackers to execute a brute force attack.
GHSA-28cx-hxv4-g5q7
Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/admin/vehicles/manage_vehicle.php?id=.
GHSA-28cx-5f85-hrh4
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/page/edit/10.
GHSA-28cw-rx3r-6f3c
Palo Alto Networks Traps ESM Console before 3.4.4 allows attackers to cause a denial of service by leveraging improper validation of requests to revoke a Traps agent license.
GHSA-28cw-qr46-rx46
The php_zip_make_relative_path function in php_zip.c in PHP 5.2.x before 5.2.9 allows context-dependent attackers to cause a denial of service (crash) via a ZIP file that contains filenames with relative paths, which is not properly handled during extraction.
GHSA-28cw-qjjv-g5g8
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to a Log Injection attack by constructing URLs from user-controlled data. This could enable attackers to make arbitrary requests to the internal network or to the local file system. IBM X-Force ID: 240266.
GHSA-28cw-3j6f-3fv3
A vulnerability exists that could allow the execution of operating system commands on systems running MiPlatform 2019.05.16 and earlier. An attacker could execute arbitrary remote command by sending parameters to WinExec function in ExtCommandApi.dll module of MiPlatform.
GHSA-28cv-g234-w9cx
A vulnerability has been identified in Polarion ALM (All versions < V2304.0). The application contains a XML External Entity Injection (XXE) vulnerability. This could allow an attacker to view files on the application server filesystem.
GHSA-28cv-7xwr-65c6
VitaraCharts 5.3.5 is vulnerable to Server-Side Request Forgery in fileLoader.jsp.
GHSA-28cv-45w7-c3g7
Memory safety bugs present in Firefox 123, Firefox ESR 115.8, and Thunderbird 115.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-28f5-mg2c-r34c Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass intended restrictions on JavaScript API execution via unspecified vectors, a different vulnerability than CVE-2015-3060, CVE-2015-3061, CVE-2015-3062, CVE-2015-3063, CVE-2015-3064, CVE-2015-3065, CVE-2015-3066, CVE-2015-3067, CVE-2015-3068, CVE-2015-3069, CVE-2015-3071, CVE-2015-3072, and CVE-2015-3074. | 31% Средний | больше 3 лет назад | ||
GHSA-28f5-7mw6-mfmc In AccountManager, there is a possible bypass of a permissions check due to a confused deputy. This could lead to local information disclosure, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-123700107 | 0% Низкий | больше 3 лет назад | ||
GHSA-28f5-7fwx-xrf3 When SWFTools 0.9.2 processes a crafted file in png2swf, it can lead to a Segmentation Violation in the png_load() function in lib/png.c. | CVSS3: 8.8 | 0% Низкий | больше 3 лет назад | |
GHSA-28f5-3rf2-gpm8 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12. | 0% Низкий | больше 3 лет назад | ||
GHSA-28f4-mjfq-qrvf Malicious Package in buffes-xor | CVSS3: 9.8 | около 5 лет назад | ||
GHSA-28f4-f5wq-36wr The WooCommerce POS plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 1.4.11. This is due to the plugin not properly verifying the authentication and authorization of the current user This makes it possible for authenticated attackers, with customer-level access and above, to view potentially sensitive information about other users by leveraging their order id | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
GHSA-28f4-9qfp-6f7v An issue was discovered in Xpdf 4.01.01. There is an FPE in the function ImageStream::ImageStream at Stream.cc for nBits. | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
GHSA-28f3-rf96-2vvg Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'txtPass' parameter of the login.php resource does not validate the characters received and they are sent unfiltered to the database. | CVSS3: 9.8 | почти 2 года назад | ||
GHSA-28f3-c95g-f4g3 In Wireshark 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11, the IxVeriWave file parser could crash. This was addressed in wiretap/vwr.c by correcting the signature timestamp bounds checks. | CVSS3: 6.5 | 1% Низкий | больше 3 лет назад | |
GHSA-28f2-gw74-5cpj The setpermissions function in the auto-updater in Arq before 5.9.7 for Mac allows local users to gain root privileges via a symlink attack on the updater binary itself. | CVSS3: 7.4 | 1% Низкий | больше 3 лет назад | |
GHSA-28cx-j4v5-m5fv Pluck CMS 4.7.18 does not restrict failed login attempts, allowing attackers to execute a brute force attack. | CVSS3: 9.8 | 0% Низкий | около 1 года назад | |
GHSA-28cx-hxv4-g5q7 Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/admin/vehicles/manage_vehicle.php?id=. | CVSS3: 9.8 | 0% Низкий | больше 3 лет назад | |
GHSA-28cx-5f85-hrh4 FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/page/edit/10. | CVSS3: 5.4 | 0% Низкий | больше 1 года назад | |
GHSA-28cw-rx3r-6f3c Palo Alto Networks Traps ESM Console before 3.4.4 allows attackers to cause a denial of service by leveraging improper validation of requests to revoke a Traps agent license. | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | |
GHSA-28cw-qr46-rx46 The php_zip_make_relative_path function in php_zip.c in PHP 5.2.x before 5.2.9 allows context-dependent attackers to cause a denial of service (crash) via a ZIP file that contains filenames with relative paths, which is not properly handled during extraction. | 2% Низкий | больше 3 лет назад | ||
GHSA-28cw-qjjv-g5g8 IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to a Log Injection attack by constructing URLs from user-controlled data. This could enable attackers to make arbitrary requests to the internal network or to the local file system. IBM X-Force ID: 240266. | CVSS3: 7.5 | 0% Низкий | почти 3 года назад | |
GHSA-28cw-3j6f-3fv3 A vulnerability exists that could allow the execution of operating system commands on systems running MiPlatform 2019.05.16 and earlier. An attacker could execute arbitrary remote command by sending parameters to WinExec function in ExtCommandApi.dll module of MiPlatform. | 1% Низкий | больше 3 лет назад | ||
GHSA-28cv-g234-w9cx A vulnerability has been identified in Polarion ALM (All versions < V2304.0). The application contains a XML External Entity Injection (XXE) vulnerability. This could allow an attacker to view files on the application server filesystem. | CVSS3: 5.3 | 0% Низкий | больше 2 лет назад | |
GHSA-28cv-7xwr-65c6 VitaraCharts 5.3.5 is vulnerable to Server-Side Request Forgery in fileLoader.jsp. | CVSS3: 6.5 | 0% Низкий | около 1 месяца назад | |
GHSA-28cv-45w7-c3g7 Memory safety bugs present in Firefox 123, Firefox ESR 115.8, and Thunderbird 115.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9. | CVSS3: 8.8 | 1% Низкий | больше 1 года назад |
Уязвимостей на страницу