Количество 314 458
Количество 314 458
GHSA-344w-5936-x3fq
SQL injection vulnerability in the rate_picture function in include/functions_rate.inc.php in Piwigo before 2.5.5, 2.6.x before 2.6.4, and 2.7.x before 2.7.2 allows remote attackers to execute arbitrary SQL commands via the rate parameter to picture.php, related to an improper data type in a comparison of a non-numeric value that begins with a digit.
GHSA-344v-v752-rwcm
The mint function of a smart contract implementation for kkTestCoin1 (KTC1), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
GHSA-344v-jr69-x57c
In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, low level users, such as subscribers, could use the import_from_debug AJAX action to install any plugin from the WordPress repository.
GHSA-344r-g579-ppxg
Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2023-21543, CVE-2023-21546, CVE-2023-21556, CVE-2023-21679.
GHSA-344r-8fg9-xhm9
SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
GHSA-344q-xw48-jxqf
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Next4Biz CRM & BPM Software Business Process Manangement (BPM) allows Stored XSS.This issue affects Business Process Manangement (BPM): from 6.6.4.4 before 6.6.4.5.
GHSA-344p-v638-q9gc
A vulnerability, which was classified as critical, has been found in Linux Kernel. Affected by this issue is the function tst_timer of the file drivers/atm/idt77252.c of the component IPsec. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. VDB-211934 is the identifier assigned to this vulnerability.
GHSA-344m-qcjq-xgrf
Vulnerable OpenSSL included in sgx-dcap-quote-verify-python
GHSA-344m-9hp3-hgr7
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/add-news.php by adding a question mark (?) followed by the payload.
GHSA-344m-62pc-2wvw
Improper sanitization in the invocation of ODA File Converter from FreeCAD 0.19 allows an attacker to inject OS commands via a crafted filename.
GHSA-344h-xj76-vwrq
A Execution with Unnecessary Privileges vulnerability in lightdm-kde-greeter allows escalation from the service user to root.This issue affects lightdm-kde-greeter. before 6.0.4.
GHSA-344g-jvx4-773r
The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to PHP Code Injection leading to Remote Code Execution in all versions up to, and including, 2.8.6 via the 'storeTheme' function. This is due to a lack of sanitization on user-supplied values, which replace values in the style.php file, along with missing capability checks. This makes it possible for unauthenticated attackers to execute code on the server. This issue was partially patched in 2.8.6 when the code injection issue was resolved, and fully patched in 2.8.7 when the missing authorization and cross-site request forgery protection was added.
GHSA-344f-vx7h-jfh2
Buffer overflow in the Accessibility component in Apple iOS before 9.3.2 allows attackers to obtain sensitive kernel memory-layout information via a crafted app.
GHSA-344f-f5vg-2jfj
Potential remote code execution in Apache Tomcat
GHSA-344f-3xh7-82cg
Adobe Experience Manager versions 6.5.19 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into a webpage. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable script. This could result in arbitrary code execution in the context of the victim's browser.
GHSA-3449-q73h-pp22
Cesanta MJS v2.20.0 was discovered to contain a global buffer overflow via snquote at src/mjs_json.c.
GHSA-3448-wp7r-84q4
In Parcel::continueWrite of Parcel.cpp, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-140419401
GHSA-3448-vrgh-85xr
NULL Pointer Dereference in OpenCV.
GHSA-3448-vfvv-xp9g
Apache Tika Denial of Service due to Infinite Loop in Tika's SQLite3Parser
GHSA-3448-h4p5-g6mc
All versions of package freeopcua/freeopcua are vulnerable to Denial of Service (DoS) when bypassing the limitations for excessive memory consumption by sending multiple CloseSession requests with the deleteSubscription parameter equal to False.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-344w-5936-x3fq SQL injection vulnerability in the rate_picture function in include/functions_rate.inc.php in Piwigo before 2.5.5, 2.6.x before 2.6.4, and 2.7.x before 2.7.2 allows remote attackers to execute arbitrary SQL commands via the rate parameter to picture.php, related to an improper data type in a comparison of a non-numeric value that begins with a digit. | 1% Низкий | больше 3 лет назад | ||
GHSA-344v-v752-rwcm The mint function of a smart contract implementation for kkTestCoin1 (KTC1), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
GHSA-344v-jr69-x57c In the Redirection for Contact Form 7 WordPress plugin before 2.3.4, low level users, such as subscribers, could use the import_from_debug AJAX action to install any plugin from the WordPress repository. | 0% Низкий | больше 3 лет назад | ||
GHSA-344r-g579-ppxg Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2023-21543, CVE-2023-21546, CVE-2023-21556, CVE-2023-21679. | CVSS3: 8.1 | 1% Низкий | около 3 лет назад | |
GHSA-344r-8fg9-xhm9 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | CVSS3: 8.8 | 3% Низкий | больше 1 года назад | |
GHSA-344q-xw48-jxqf Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Next4Biz CRM & BPM Software Business Process Manangement (BPM) allows Stored XSS.This issue affects Business Process Manangement (BPM): from 6.6.4.4 before 6.6.4.5. | CVSS3: 5.4 | 0% Низкий | больше 1 года назад | |
GHSA-344p-v638-q9gc A vulnerability, which was classified as critical, has been found in Linux Kernel. Affected by this issue is the function tst_timer of the file drivers/atm/idt77252.c of the component IPsec. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. VDB-211934 is the identifier assigned to this vulnerability. | CVSS3: 7 | 0% Низкий | больше 3 лет назад | |
GHSA-344m-qcjq-xgrf Vulnerable OpenSSL included in sgx-dcap-quote-verify-python | почти 3 года назад | |||
GHSA-344m-9hp3-hgr7 The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/add-news.php by adding a question mark (?) followed by the payload. | CVSS3: 4.8 | 0% Низкий | больше 3 лет назад | |
GHSA-344m-62pc-2wvw Improper sanitization in the invocation of ODA File Converter from FreeCAD 0.19 allows an attacker to inject OS commands via a crafted filename. | CVSS3: 7.8 | 0% Низкий | около 4 лет назад | |
GHSA-344h-xj76-vwrq A Execution with Unnecessary Privileges vulnerability in lightdm-kde-greeter allows escalation from the service user to root.This issue affects lightdm-kde-greeter. before 6.0.4. | 0% Низкий | 3 месяца назад | ||
GHSA-344g-jvx4-773r The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to PHP Code Injection leading to Remote Code Execution in all versions up to, and including, 2.8.6 via the 'storeTheme' function. This is due to a lack of sanitization on user-supplied values, which replace values in the style.php file, along with missing capability checks. This makes it possible for unauthenticated attackers to execute code on the server. This issue was partially patched in 2.8.6 when the code injection issue was resolved, and fully patched in 2.8.7 when the missing authorization and cross-site request forgery protection was added. | CVSS3: 9.8 | 72% Высокий | больше 1 года назад | |
GHSA-344f-vx7h-jfh2 Buffer overflow in the Accessibility component in Apple iOS before 9.3.2 allows attackers to obtain sensitive kernel memory-layout information via a crafted app. | CVSS3: 3.3 | 0% Низкий | больше 3 лет назад | |
GHSA-344f-f5vg-2jfj Potential remote code execution in Apache Tomcat | CVSS3: 7 | 93% Критический | больше 5 лет назад | |
GHSA-344f-3xh7-82cg Adobe Experience Manager versions 6.5.19 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into a webpage. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable script. This could result in arbitrary code execution in the context of the victim's browser. | CVSS3: 5.4 | 4% Низкий | почти 2 года назад | |
GHSA-3449-q73h-pp22 Cesanta MJS v2.20.0 was discovered to contain a global buffer overflow via snquote at src/mjs_json.c. | 0% Низкий | около 4 лет назад | ||
GHSA-3448-wp7r-84q4 In Parcel::continueWrite of Parcel.cpp, there is possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-140419401 | 0% Низкий | больше 3 лет назад | ||
GHSA-3448-vrgh-85xr NULL Pointer Dereference in OpenCV. | CVSS3: 7.5 | 1% Низкий | больше 4 лет назад | |
GHSA-3448-vfvv-xp9g Apache Tika Denial of Service due to Infinite Loop in Tika's SQLite3Parser | CVSS3: 6.5 | 3% Низкий | около 7 лет назад | |
GHSA-3448-h4p5-g6mc All versions of package freeopcua/freeopcua are vulnerable to Denial of Service (DoS) when bypassing the limitations for excessive memory consumption by sending multiple CloseSession requests with the deleteSubscription parameter equal to False. | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу