Количество 314 458
Количество 314 458
GHSA-32wm-p53q-684m
An Insecure Direct Object Reference (IDOR) vulnerability exists in the vehicleId parameter, allowing unauthorized access to sensitive information of other users’ vehicles. Exploiting this issue enables an attacker to retrieve data such as GPS coordinates, encryption keys, initialization vectors, model numbers, and fuel statistics belonging to other users, instead of being limited to their own vehicle data. This is a server-side authorization fix.
GHSA-32wm-927m-gppc
Cross-Site Request Forgery (CSRF) vulnerability in CMSaccount Photo Video Store allows Cross-Site Scripting (XSS).This issue affects Photo Video Store: from n/a through 21.07.
GHSA-32wh-5vv8-c8px
SQL injection vulnerability in show.php in PHPFootball 1.6 allows remote attackers to execute arbitrary SQL commands via the dbtable parameter.
GHSA-32wh-2cq7-f29f
A vulnerability was found in CodeAstro Blood Donor Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /pages/deletedannounce.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
GHSA-32wg-h523-82pp
Comodo Personal Firewall 2.3.6.81 relies on the Process Environment Block (PEB) to identify a process, which allows local users to bypass the product's controls on a process by spoofing the (1) ImagePathName, (2) CommandLine, and (3) WindowTitle fields in the PEB.
GHSA-32wg-gc37-9jjj
The wav_open_read function in frontend/input.c in Freeware Advanced Audio Coder (FAAC) 1.28 allows remote attackers to cause a denial of service (large loop) via a crafted wav file.
GHSA-32wf-9fvj-8hx8
A local privilege escalation vulnerability in Ivanti Secure Access Client for Windows allows a low privileged user to execute code as SYSTEM.
GHSA-32wf-3wxg-68pf
IBM BigFix Remote Control before 9.1.3 allows remote attackers to obtain sensitive cleartext information by sniffing the network.
GHSA-32w9-wxmj-7cv4
An issue was discovered in elfutils 0.175. A segmentation fault can occur in the function elf64_xlatetom in libelf/elf32_xlatetom.c, due to dwfl_segment_report_module not checking whether the dyn data read from a core file is truncated. A crafted input can cause a program crash, leading to denial-of-service, as demonstrated by eu-stack.
GHSA-32w9-cgpf-p2wf
Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's session to disable two-factor authentication
GHSA-32w9-2qpc-5f9v
Docker image code execution with Apache Mesos
GHSA-32w8-rwc8-j8q2
DB2 8.1 remote command server (DB2RCMD.EXE) executes the db2rcmdc.exe program as the db2admin administrator, which allows local users to gain privileges via the DB2REMOTECMD named pipe.
GHSA-32w7-9whp-cjp9
Session Fixation in Tryton
GHSA-32w7-8jrj-h2v7
Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.
GHSA-32w7-6rgv-w2xg
An issue was discovered in UC Berkeley RISE Opaque before 2018-12-01. There is no boundary check on ocall_malloc. The return value could be a pointer to enclave memory. It could cause an arbitrary enclave memory write.
GHSA-32w6-xw3w-3qh3
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
GHSA-32w5-785v-xx4q
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Weblizar Coming Soon allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Coming Soon: from n/a through 1.6.3.
GHSA-32w5-6g7q-f4f8
An issue was discovered in certain Apple products. macOS before 10.12.3 is affected. The issue involves the "Bluetooth" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (use-after-free) via a crafted app.
GHSA-32w5-2rp6-rg25
Permission bypass when importing or synchronizing entries in User vault in Devolutions Server 2022.3.13 and prior versions allows users with restricted rights to bypass entry permission via id collision.
GHSA-32w4-gwv8-pcf9
The DOM implementation in Google Chrome before 47.0.2526.73 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, a different vulnerability than CVE-2015-6768.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-32wm-p53q-684m An Insecure Direct Object Reference (IDOR) vulnerability exists in the vehicleId parameter, allowing unauthorized access to sensitive information of other users’ vehicles. Exploiting this issue enables an attacker to retrieve data such as GPS coordinates, encryption keys, initialization vectors, model numbers, and fuel statistics belonging to other users, instead of being limited to their own vehicle data. This is a server-side authorization fix. | CVSS3: 8.5 | 0% Низкий | 3 месяца назад | |
GHSA-32wm-927m-gppc Cross-Site Request Forgery (CSRF) vulnerability in CMSaccount Photo Video Store allows Cross-Site Scripting (XSS).This issue affects Photo Video Store: from n/a through 21.07. | CVSS3: 7.1 | 0% Низкий | около 1 года назад | |
GHSA-32wh-5vv8-c8px SQL injection vulnerability in show.php in PHPFootball 1.6 allows remote attackers to execute arbitrary SQL commands via the dbtable parameter. | 0% Низкий | почти 4 года назад | ||
GHSA-32wh-2cq7-f29f A vulnerability was found in CodeAstro Blood Donor Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /pages/deletedannounce.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 6.3 | 0% Низкий | около 1 года назад | |
GHSA-32wg-h523-82pp Comodo Personal Firewall 2.3.6.81 relies on the Process Environment Block (PEB) to identify a process, which allows local users to bypass the product's controls on a process by spoofing the (1) ImagePathName, (2) CommandLine, and (3) WindowTitle fields in the PEB. | 0% Низкий | почти 4 года назад | ||
GHSA-32wg-gc37-9jjj The wav_open_read function in frontend/input.c in Freeware Advanced Audio Coder (FAAC) 1.28 allows remote attackers to cause a denial of service (large loop) via a crafted wav file. | CVSS3: 5.5 | 1% Низкий | больше 3 лет назад | |
GHSA-32wf-9fvj-8hx8 A local privilege escalation vulnerability in Ivanti Secure Access Client for Windows allows a low privileged user to execute code as SYSTEM. | CVSS3: 7.8 | 0% Низкий | больше 1 года назад | |
GHSA-32wf-3wxg-68pf IBM BigFix Remote Control before 9.1.3 allows remote attackers to obtain sensitive cleartext information by sniffing the network. | CVSS3: 5.3 | 0% Низкий | больше 3 лет назад | |
GHSA-32w9-wxmj-7cv4 An issue was discovered in elfutils 0.175. A segmentation fault can occur in the function elf64_xlatetom in libelf/elf32_xlatetom.c, due to dwfl_segment_report_module not checking whether the dyn data read from a core file is truncated. A crafted input can cause a program crash, leading to denial-of-service, as demonstrated by eu-stack. | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
GHSA-32w9-cgpf-p2wf Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's session to disable two-factor authentication | 0% Низкий | больше 3 лет назад | ||
GHSA-32w9-2qpc-5f9v Docker image code execution with Apache Mesos | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-32w8-rwc8-j8q2 DB2 8.1 remote command server (DB2RCMD.EXE) executes the db2rcmdc.exe program as the db2admin administrator, which allows local users to gain privileges via the DB2REMOTECMD named pipe. | 32% Средний | почти 4 года назад | ||
GHSA-32w7-9whp-cjp9 Session Fixation in Tryton | CVSS3: 5.9 | 0% Низкий | около 7 лет назад | |
GHSA-32w7-8jrj-h2v7 Use after free in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally. | CVSS3: 7.4 | 0% Низкий | 4 месяца назад | |
GHSA-32w7-6rgv-w2xg An issue was discovered in UC Berkeley RISE Opaque before 2018-12-01. There is no boundary check on ocall_malloc. The return value could be a pointer to enclave memory. It could cause an arbitrary enclave memory write. | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
GHSA-32w6-xw3w-3qh3 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | 12 месяцев назад | |||
GHSA-32w5-785v-xx4q Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Weblizar Coming Soon allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Coming Soon: from n/a through 1.6.3. | CVSS3: 5.3 | 0% Низкий | больше 1 года назад | |
GHSA-32w5-6g7q-f4f8 An issue was discovered in certain Apple products. macOS before 10.12.3 is affected. The issue involves the "Bluetooth" component. It allows attackers to execute arbitrary code in a privileged context or cause a denial of service (use-after-free) via a crafted app. | CVSS3: 7.8 | 2% Низкий | больше 3 лет назад | |
GHSA-32w5-2rp6-rg25 Permission bypass when importing or synchronizing entries in User vault in Devolutions Server 2022.3.13 and prior versions allows users with restricted rights to bypass entry permission via id collision. | CVSS3: 6.5 | 0% Низкий | почти 3 года назад | |
GHSA-32w4-gwv8-pcf9 The DOM implementation in Google Chrome before 47.0.2526.73 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, a different vulnerability than CVE-2015-6768. | 1% Низкий | больше 3 лет назад |
Уязвимостей на страницу