Количество 314 458
Количество 314 458
GHSA-342c-vcff-2ff2
Login timing attack in ezsystems/ezplatform-kernel
GHSA-342c-f869-5m44
Apache Sling POST Servlets Denial of Service Vulnerability
GHSA-3429-h97r-hqqx
Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows exposure of Custom Settings data. This impacts OmniStudio: before version 254.
GHSA-3429-2hmm-5vvx
A flaw was found in Privoxy in versions before 3.0.31. A memory leak that occurs when decompression fails unexpectedly may lead to a denial of service. The highest threat from this vulnerability is to system availability.
GHSA-3428-vpwf-2w42
CSV Injection vulnerability in the Asus RT-N12+ router allows administrator users to inject arbitrary commands or formulas in the client name parameter which can be triggered and executed in a different user session upon exporting to CSV format.
GHSA-3427-99jp-r4g2
Windows Kernel Elevation of Privilege Vulnerability
GHSA-3426-w9wr-jxx4
Multiple cross-site scripting (XSS) vulnerabilities in Chipmunk Blogger allow remote authenticated users to inject arbitrary web script or HTML via script tags in (1) posts and (2) profile names; and (3) a javascript URI in a URL argument in the photo gallery.
GHSA-3426-h5fc-ghj2
LimeSurvey version prior to 3.14.4 contains a file upload vulnerability in upload functionality that can result in an attacker gaining code execution via webshell. This attack appear to be exploitable via an authenticated user uploading a zip archive which can contains malicious php files that can be called under certain circumstances. This vulnerability appears to have been fixed in after commit 91d143230eb357260a19c8424b3005deb49a47f7 / version 3.14.4.
GHSA-3425-gj4f-6wvw
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to multiple reflected cross site scripting vulnerabilities. Attacker controlled input is reflected back in the page without sanitization.
GHSA-3425-8q76-vpj9
Under certain conditions SAP Mobile Secure Android client (before version 6.60.19942.0 SP28 1711) allows an attacker to access information which would otherwise be restricted.
GHSA-3424-mxvj-pcgx
Arbitrary code execution is possible due to improper validation of the file upload functionality in Eaton BLSS.
GHSA-3424-fhhw-7h8h
The acn_add_dmp_data function in epan/dissectors/packet-acn.c in the ACN dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via an invalid count value in ACN_DMP_ADT_D_RE DMP data.
GHSA-3422-7r3j-w49g
A Reflected Cross Site Scripting (XSS) vulnerability was found in /ifscfinder/admin/profile.php in PHPGurukul IFSC Code Finder Project v1.0, which allows remote attackers to execute arbitrary code via " searchifsccode" parameter.
GHSA-3422-45qx-4m3x
Race condition in the IPv6-to-IPv4 functionality in Cisco IOS 15.3S in the Performance Routing Engine (PRE) module on UBR devices allows remote attackers to cause a denial of service (NULL pointer free and module crash) by triggering intermittent connectivity with many IPv6 CPE devices, aka Bug ID CSCug47366.
GHSA-33xx-xhf9-4h3m
FireWall-1 4.1 with a limited-IP license allows remote attackers to cause a denial of service by sending a large number of spoofed IP packets with various source addresses to the inside interface, which floods the console with warning messages and consumes CPU resources.
GHSA-33xx-v6xh-7w9j
In Kronos Web Time and Attendance (webTA) 4.1.x and later 4.x versions before 5.0, there is a Stored XSS vulnerability by setting the Application Banner input field of the /ApplicationBanner page as an authenticated administrator.
GHSA-33xw-x3pr-rvqj
Wikimedia Potential DOS due to slow WatchedItemStore::countVisitingWatchersMultiple
GHSA-33xw-9hr7-47v7
The provisional-load commit implementation in WebKit/Source/bindings/core/v8/WindowProxy.cpp in Google Chrome before 47.0.2526.73 allows remote attackers to bypass the Same Origin Policy by leveraging a delay in window proxy clearing.
GHSA-33xw-247w-6hmc
BentoML Allows Remote Code Execution (RCE) via Insecure Deserialization
GHSA-33xv-g39w-2g66
In the Linux kernel, the following vulnerability has been resolved: block: fix memory leak in disk_register_independent_access_ranges kobject_init_and_add() takes reference even when it fails. According to the doc of kobject_init_and_add() If this function returns an error, kobject_put() must be called to properly clean up the memory associated with the object. Fix this issue by adding kobject_put(). Callback function blk_ia_ranges_sysfs_release() in kobject_put() can handle the pointer "iars" properly.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-342c-vcff-2ff2 Login timing attack in ezsystems/ezplatform-kernel | больше 3 лет назад | |||
GHSA-342c-f869-5m44 Apache Sling POST Servlets Denial of Service Vulnerability | 38% Средний | больше 3 лет назад | ||
GHSA-3429-h97r-hqqx Improper Preservation of Permissions vulnerability in Salesforce OmniStudio (FlexCards) allows exposure of Custom Settings data. This impacts OmniStudio: before version 254. | CVSS3: 7.5 | 0% Низкий | 8 месяцев назад | |
GHSA-3429-2hmm-5vvx A flaw was found in Privoxy in versions before 3.0.31. A memory leak that occurs when decompression fails unexpectedly may lead to a denial of service. The highest threat from this vulnerability is to system availability. | CVSS3: 7.5 | 2% Низкий | больше 3 лет назад | |
GHSA-3428-vpwf-2w42 CSV Injection vulnerability in the Asus RT-N12+ router allows administrator users to inject arbitrary commands or formulas in the client name parameter which can be triggered and executed in a different user session upon exporting to CSV format. | CVSS3: 5.4 | 0% Низкий | почти 2 года назад | |
GHSA-3427-99jp-r4g2 Windows Kernel Elevation of Privilege Vulnerability | CVSS3: 7.8 | 0% Низкий | почти 2 года назад | |
GHSA-3426-w9wr-jxx4 Multiple cross-site scripting (XSS) vulnerabilities in Chipmunk Blogger allow remote authenticated users to inject arbitrary web script or HTML via script tags in (1) posts and (2) profile names; and (3) a javascript URI in a URL argument in the photo gallery. | 0% Низкий | почти 4 года назад | ||
GHSA-3426-h5fc-ghj2 LimeSurvey version prior to 3.14.4 contains a file upload vulnerability in upload functionality that can result in an attacker gaining code execution via webshell. This attack appear to be exploitable via an authenticated user uploading a zip archive which can contains malicious php files that can be called under certain circumstances. This vulnerability appears to have been fixed in after commit 91d143230eb357260a19c8424b3005deb49a47f7 / version 3.14.4. | CVSS3: 8.8 | 1% Низкий | больше 3 лет назад | |
GHSA-3425-gj4f-6wvw PrinterLogic Web Stack versions 19.1.1.13 SP9 and below are vulnerable to multiple reflected cross site scripting vulnerabilities. Attacker controlled input is reflected back in the page without sanitization. | 1% Низкий | почти 4 года назад | ||
GHSA-3425-8q76-vpj9 Under certain conditions SAP Mobile Secure Android client (before version 6.60.19942.0 SP28 1711) allows an attacker to access information which would otherwise be restricted. | CVSS3: 4.7 | 0% Низкий | больше 3 лет назад | |
GHSA-3424-mxvj-pcgx Arbitrary code execution is possible due to improper validation of the file upload functionality in Eaton BLSS. | CVSS3: 8.3 | 0% Низкий | 3 месяца назад | |
GHSA-3424-fhhw-7h8h The acn_add_dmp_data function in epan/dissectors/packet-acn.c in the ACN dissector in Wireshark 1.6.x before 1.6.14 and 1.8.x before 1.8.6 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via an invalid count value in ACN_DMP_ADT_D_RE DMP data. | 1% Низкий | больше 3 лет назад | ||
GHSA-3422-7r3j-w49g A Reflected Cross Site Scripting (XSS) vulnerability was found in /ifscfinder/admin/profile.php in PHPGurukul IFSC Code Finder Project v1.0, which allows remote attackers to execute arbitrary code via " searchifsccode" parameter. | CVSS3: 8.8 | 0% Низкий | больше 1 года назад | |
GHSA-3422-45qx-4m3x Race condition in the IPv6-to-IPv4 functionality in Cisco IOS 15.3S in the Performance Routing Engine (PRE) module on UBR devices allows remote attackers to cause a denial of service (NULL pointer free and module crash) by triggering intermittent connectivity with many IPv6 CPE devices, aka Bug ID CSCug47366. | 1% Низкий | больше 3 лет назад | ||
GHSA-33xx-xhf9-4h3m FireWall-1 4.1 with a limited-IP license allows remote attackers to cause a denial of service by sending a large number of spoofed IP packets with various source addresses to the inside interface, which floods the console with warning messages and consumes CPU resources. | 1% Низкий | почти 4 года назад | ||
GHSA-33xx-v6xh-7w9j In Kronos Web Time and Attendance (webTA) 4.1.x and later 4.x versions before 5.0, there is a Stored XSS vulnerability by setting the Application Banner input field of the /ApplicationBanner page as an authenticated administrator. | 0% Низкий | больше 3 лет назад | ||
GHSA-33xw-x3pr-rvqj Wikimedia Potential DOS due to slow WatchedItemStore::countVisitingWatchersMultiple | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
GHSA-33xw-9hr7-47v7 The provisional-load commit implementation in WebKit/Source/bindings/core/v8/WindowProxy.cpp in Google Chrome before 47.0.2526.73 allows remote attackers to bypass the Same Origin Policy by leveraging a delay in window proxy clearing. | 1% Низкий | больше 3 лет назад | ||
GHSA-33xw-247w-6hmc BentoML Allows Remote Code Execution (RCE) via Insecure Deserialization | CVSS3: 9.8 | 76% Высокий | 10 месяцев назад | |
GHSA-33xv-g39w-2g66 In the Linux kernel, the following vulnerability has been resolved: block: fix memory leak in disk_register_independent_access_ranges kobject_init_and_add() takes reference even when it fails. According to the doc of kobject_init_and_add() If this function returns an error, kobject_put() must be called to properly clean up the memory associated with the object. Fix this issue by adding kobject_put(). Callback function blk_ia_ranges_sysfs_release() in kobject_put() can handle the pointer "iars" properly. | CVSS3: 5.5 | 0% Низкий | больше 1 года назад |
Уязвимостей на страницу