Количество 314 458
Количество 314 458
GHSA-335p-4qjx-hp36
PCManager has a Weaknesses Introduced During Design vulnerability .Successful exploitation of this vulnerability may cause that the PIN of the subscriber is changed.
GHSA-335j-8h73-qjmc
The WebReporting module in F-Secure Policy Manager 7.x, 8.00 before hotfix 2, 8.1x before hotfix 3 on Windows and hotfix 2 on Linux, and 9.00 before hotfix 4 on Windows and hotfix 2 on Linux, allows remote attackers to obtain sensitive information via a request to an invalid report, which reveals the installation path in an error message, as demonstrated with requests to (1) report/infection-table.html or (2) report/productsummary-table.html.
GHSA-335h-x4pf-hpc2
A race condition was addressed with additional validation. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. An app may be able to execute arbitrary code with kernel privileges.
GHSA-335h-mvpr-rccp
A vulnerability was found in Tenda AC15 15.03.20_multi. It has been rated as critical. This issue affects the function fromDhcpListClient of the file /goform/DhcpListClient. The manipulation of the argument page leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-257669 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
GHSA-335h-h5hx-g42j
Possible XSS in iManager URL for access Component has been discovered in OpenText™ iManager 3.2.5.0000.
GHSA-335g-xcjh-ghc2
Apache OpenMeetings vulnerable to SQL injection
GHSA-335g-mg6r-4m22
The theplus_more_post AJAX action of The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.12 did not properly sanitise some of its fields, leading to a reflected Cross-Site Scripting (exploitable on both unauthenticated and authenticated users)
GHSA-335g-966f-cg64
Microsoft Exchange Server Remote Code Execution Vulnerability
GHSA-335g-5x6x-7qgj
Windows Event Tracing Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-38630.
GHSA-335g-4xxp-8f55
Local File Inclusion vulnerability in LA-Studio LA-Studio Element Kit for Elementor via "LaStudioKit Progress Bar" widget in New Post, specifically in the "progress_type" attribute.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.3.8.1.
GHSA-335f-xvw7-xg9m
3D Viewer Information Disclosure Vulnerability
GHSA-335f-9mr2-fg88
A vulnerability in the getSelectedMimeTypesByRole function of the WP Upload Restriction WordPress plugin allows low-level authenticated users to view custom extensions added by administrators. This issue affects versions 2.2.3 and prior.
GHSA-335c-7h8h-h64q
Cross-Site Request Forgery (CSRF) vulnerability in Sourov Amin Word Freshener allows Stored XSS.This issue affects Word Freshener: from n/a through 1.3.
GHSA-3359-9p9h-8p54
The orinoco_ioctl_set_auth function in drivers/net/wireless/orinoco/wext.c in the Linux kernel before 2.6.37 does not properly implement a TKIP protection mechanism, which makes it easier for remote attackers to obtain access to a Wi-Fi network by reading Wi-Fi frames.
GHSA-3359-8r4q-9r9p
A CWE-120: Buffer Copy without Checking Size of Input (Classic Buffer Overflow) vulnerability exists that could cause user privilege escalation if a local user sends specific string input to a local function call.
GHSA-3359-25fv-h37v
Mattermost Desktop App versions <=5.13.0 fail to manage modals in the Mattermost Desktop App that stops a user with a server that uses basic authentication from accessing their server which allows an attacker that provides a malicious server to the user to deny use of the Desktop App via having the user configure the malicious server and forcing a modal popup that cannot be closed.
GHSA-3358-4f7f-p4j4
Use after free in generic-array
GHSA-3357-829x-m9pr
Apache CXF Fediz application plugins are vulnerable to Denial of Service (DoS) attacks
GHSA-3356-grh4-xpc8
A vulnerability was found in mrtnmtth joomla_mod_einsatz_stats up to 0.2. It has been classified as critical. This affects the function getStatsByType of the file helper.php. The manipulation of the argument year leads to sql injection. Upgrading to version 0.3 is able to address this issue. The name of the patch is 27c1b443cff45c81d9d7d926a74c76f8b6ffc6cb. It is recommended to upgrade the affected component. The identifier VDB-217653 was assigned to this vulnerability.
GHSA-3355-xw7j-q4q7
Use-after-free vulnerability in the nsTextEditorState::PrepareEditor function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-4214.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-335p-4qjx-hp36 PCManager has a Weaknesses Introduced During Design vulnerability .Successful exploitation of this vulnerability may cause that the PIN of the subscriber is changed. | 0% Низкий | около 4 лет назад | ||
GHSA-335j-8h73-qjmc The WebReporting module in F-Secure Policy Manager 7.x, 8.00 before hotfix 2, 8.1x before hotfix 3 on Windows and hotfix 2 on Linux, and 9.00 before hotfix 4 on Windows and hotfix 2 on Linux, allows remote attackers to obtain sensitive information via a request to an invalid report, which reveals the installation path in an error message, as demonstrated with requests to (1) report/infection-table.html or (2) report/productsummary-table.html. | 0% Низкий | больше 3 лет назад | ||
GHSA-335h-x4pf-hpc2 A race condition was addressed with additional validation. This issue is fixed in tvOS 16.2, macOS Monterey 12.6.2, macOS Ventura 13.1, macOS Big Sur 11.7.2, iOS 15.7.2 and iPadOS 15.7.2, iOS 16.2 and iPadOS 16.2, watchOS 9.2. An app may be able to execute arbitrary code with kernel privileges. | CVSS3: 7 | 86% Высокий | около 3 лет назад | |
GHSA-335h-mvpr-rccp A vulnerability was found in Tenda AC15 15.03.20_multi. It has been rated as critical. This issue affects the function fromDhcpListClient of the file /goform/DhcpListClient. The manipulation of the argument page leads to stack-based buffer overflow. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-257669 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 8.8 | 0% Низкий | почти 2 года назад | |
GHSA-335h-h5hx-g42j Possible XSS in iManager URL for access Component has been discovered in OpenText™ iManager 3.2.5.0000. | CVSS3: 6.1 | 0% Низкий | около 1 года назад | |
GHSA-335g-xcjh-ghc2 Apache OpenMeetings vulnerable to SQL injection | CVSS3: 8.8 | 0% Низкий | больше 3 лет назад | |
GHSA-335g-mg6r-4m22 The theplus_more_post AJAX action of The Plus Addons for Elementor Page Builder WordPress plugin before 4.1.12 did not properly sanitise some of its fields, leading to a reflected Cross-Site Scripting (exploitable on both unauthenticated and authenticated users) | 54% Средний | больше 3 лет назад | ||
GHSA-335g-966f-cg64 Microsoft Exchange Server Remote Code Execution Vulnerability | CVSS3: 8 | 1% Низкий | около 2 лет назад | |
GHSA-335g-5x6x-7qgj Windows Event Tracing Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-38630. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-335g-4xxp-8f55 Local File Inclusion vulnerability in LA-Studio LA-Studio Element Kit for Elementor via "LaStudioKit Progress Bar" widget in New Post, specifically in the "progress_type" attribute.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.3.8.1. | CVSS3: 8.5 | 1% Низкий | больше 1 года назад | |
GHSA-335f-xvw7-xg9m 3D Viewer Information Disclosure Vulnerability | CVSS3: 5.5 | 4% Низкий | больше 3 лет назад | |
GHSA-335f-9mr2-fg88 A vulnerability in the getSelectedMimeTypesByRole function of the WP Upload Restriction WordPress plugin allows low-level authenticated users to view custom extensions added by administrators. This issue affects versions 2.2.3 and prior. | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад | |
GHSA-335c-7h8h-h64q Cross-Site Request Forgery (CSRF) vulnerability in Sourov Amin Word Freshener allows Stored XSS.This issue affects Word Freshener: from n/a through 1.3. | CVSS3: 7.1 | 0% Низкий | около 1 года назад | |
GHSA-3359-9p9h-8p54 The orinoco_ioctl_set_auth function in drivers/net/wireless/orinoco/wext.c in the Linux kernel before 2.6.37 does not properly implement a TKIP protection mechanism, which makes it easier for remote attackers to obtain access to a Wi-Fi network by reading Wi-Fi frames. | 0% Низкий | больше 3 лет назад | ||
GHSA-3359-8r4q-9r9p A CWE-120: Buffer Copy without Checking Size of Input (Classic Buffer Overflow) vulnerability exists that could cause user privilege escalation if a local user sends specific string input to a local function call. | CVSS3: 7.8 | 0% Низкий | больше 2 лет назад | |
GHSA-3359-25fv-h37v Mattermost Desktop App versions <=5.13.0 fail to manage modals in the Mattermost Desktop App that stops a user with a server that uses basic authentication from accessing their server which allows an attacker that provides a malicious server to the user to deny use of the Desktop App via having the user configure the malicious server and forcing a modal popup that cannot be closed. | CVSS3: 6.1 | 0% Низкий | 4 месяца назад | |
GHSA-3358-4f7f-p4j4 Use after free in generic-array | CVSS3: 7.5 | 0% Низкий | больше 4 лет назад | |
GHSA-3357-829x-m9pr Apache CXF Fediz application plugins are vulnerable to Denial of Service (DoS) attacks | CVSS3: 7.5 | 14% Средний | больше 7 лет назад | |
GHSA-3356-grh4-xpc8 A vulnerability was found in mrtnmtth joomla_mod_einsatz_stats up to 0.2. It has been classified as critical. This affects the function getStatsByType of the file helper.php. The manipulation of the argument year leads to sql injection. Upgrading to version 0.3 is able to address this issue. The name of the patch is 27c1b443cff45c81d9d7d926a74c76f8b6ffc6cb. It is recommended to upgrade the affected component. The identifier VDB-217653 was assigned to this vulnerability. | CVSS3: 9.8 | 0% Низкий | около 3 лет назад | |
GHSA-3355-xw7j-q4q7 Use-after-free vulnerability in the nsTextEditorState::PrepareEditor function in Mozilla Firefox before 17.0, Firefox ESR 10.x before 10.0.11, Thunderbird before 17.0, Thunderbird ESR 10.x before 10.0.11, and SeaMonkey before 2.14 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-4214. | 2% Низкий | больше 3 лет назад |
Уязвимостей на страницу