Количество 312 573
Количество 312 573
GHSA-2rmm-r7j4-mw6g
Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0103, CVE-2016-0106, CVE-2016-0108, CVE-2016-0109, and CVE-2016-0114.
GHSA-2rmm-hwr3-75xq
A vulnerability classified as problematic was found in Faraday GM8181 and GM828x up to 20240429. Affected by this vulnerability is an unknown functionality of the component Request Handler. The manipulation leads to information disclosure. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. The identifier VDB-263305 was assigned to this vulnerability.
GHSA-2rmm-87v7-34rj
Improper Restriction of XML External Entity Reference in Any23
GHSA-2rmj-mq67-h97g
Spring Framework DoS via conditional HTTP request
GHSA-2rmj-3gh3-p952
Untrusted search path vulnerability in UltraVNC 1.0.8.2 allows local users to gain privileges via a Trojan horse vnclang.dll file in the current working directory, as demonstrated by a directory that contains a .vnc file. NOTE: some of these details are obtained from third party information.
GHSA-2rmh-3vpc-xqrj
PGP 5.5.x through 6.5.3 does not properly check if an Additional Decryption Key (ADK) is stored in the signed portion of a public certificate, which allows an attacker who can modify a victim's public certificate to decrypt any data that has been encrypted with the modified certificate.
GHSA-2rmf-wj7v-g6m7
NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a NULL pointer dereference may lead to denial of service or possible escalation of privileges.
GHSA-2rmf-9mpq-4vh6
The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated remote code execution due to a default component that permits arbitrary upload of PHP files, because the formmailer widget blocks .php files but not .php5 or .phtml files. This is related to /assets/php/formmailer/SendEmail.php and /assets/php/formmailer/functions.php.
GHSA-2rmf-3rpp-rfgh
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
GHSA-2rmc-v2mp-gxq4
In createFromParcel of GpsNavigationMessage.java, there is a possible Parcel serialization/deserialization mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-196970023
GHSA-2rmc-r8fj-3p89
Honeywell PC42t, PC42tp, and PC42d Printers, T10.19.020016 to T10.20.060398, contain a cross-site scripting vulnerability. A(n) attacker could potentially inject malicious code which may lead to information disclosure, session theft, or client-side request forgery. Honeywell recommends updating to the most recent version of this firmware, PC42 Printer Firmware Version 20.6 T10.20.060398.
GHSA-2rmc-p46g-jmrv
chfn in pwdutils 3.0.4 and earlier on SuSE Linux, and possibly other operating systems, does not properly check arguments for the GECOS field, which allows local users to gain privileges.
GHSA-2rmc-f234-xhg3
A null pointer deference issue exists in GNU LibreDWG 0.10 via read_2004_compressed_section ../../src/decode.c:2337.
GHSA-2rmc-2qhr-4jvg
A use-after-free can occur during buffer storage operations within the ANGLE graphics library, used for WebGL content. The buffer storage can be freed while still in use in some circumstances, leading to a potentially exploitable crash. Note: This issue is in "libGLES", which is only in use on Windows. Other operating systems are not affected. This vulnerability affects Firefox < 52 and Thunderbird < 52.
GHSA-2rm9-pcmr-fvfj
Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
GHSA-2rm8-gh6q-8wpp
Cross-Site Request Forgery (CSRF) vulnerability in pimwick PW WooCommerce Bulk Edit allows Cross Site Request Forgery. This issue affects PW WooCommerce Bulk Edit: from n/a through 2.134.
GHSA-2rm7-xxx8-35jh
MediaWiki Cross-site Scripting (XSS)
GHSA-2rm6-26jp-f4w2
A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.4, macOS Ventura 13.6.8. An attacker may be able to read information belonging to another user.
GHSA-2rm4-vgjw-r4jw
Unify OpenStage / OpenScape Desk Phone IP before V3 R3.11.0 SIP has an OS command injection vulnerability in the web based management interface
GHSA-2rm4-pxv9-x75c
The gdPngReadData function in libgd 2.0.34 allows user-assisted attackers to cause a denial of service (CPU consumption) via a crafted PNG image with truncated data, which causes an infinite loop in the png_read_info function in libpng.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2rmm-r7j4-mw6g Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0103, CVE-2016-0106, CVE-2016-0108, CVE-2016-0109, and CVE-2016-0114. | CVSS3: 7.5 | 17% Средний | больше 3 лет назад | |
GHSA-2rmm-hwr3-75xq A vulnerability classified as problematic was found in Faraday GM8181 and GM828x up to 20240429. Affected by this vulnerability is an unknown functionality of the component Request Handler. The manipulation leads to information disclosure. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. The identifier VDB-263305 was assigned to this vulnerability. | CVSS3: 5.3 | 0% Низкий | почти 2 года назад | |
GHSA-2rmm-87v7-34rj Improper Restriction of XML External Entity Reference in Any23 | CVSS3: 9.1 | 2% Низкий | почти 4 года назад | |
GHSA-2rmj-mq67-h97g Spring Framework DoS via conditional HTTP request | CVSS3: 5.3 | 0% Низкий | больше 1 года назад | |
GHSA-2rmj-3gh3-p952 Untrusted search path vulnerability in UltraVNC 1.0.8.2 allows local users to gain privileges via a Trojan horse vnclang.dll file in the current working directory, as demonstrated by a directory that contains a .vnc file. NOTE: some of these details are obtained from third party information. | 0% Низкий | больше 3 лет назад | ||
GHSA-2rmh-3vpc-xqrj PGP 5.5.x through 6.5.3 does not properly check if an Additional Decryption Key (ADK) is stored in the signed portion of a public certificate, which allows an attacker who can modify a victim's public certificate to decrypt any data that has been encrypted with the modified certificate. | 0% Низкий | почти 4 года назад | ||
GHSA-2rmf-wj7v-g6m7 NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a NULL pointer dereference may lead to denial of service or possible escalation of privileges. | CVSS3: 8.8 | 0% Низкий | больше 3 лет назад | |
GHSA-2rmf-9mpq-4vh6 The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated remote code execution due to a default component that permits arbitrary upload of PHP files, because the formmailer widget blocks .php files but not .php5 or .phtml files. This is related to /assets/php/formmailer/SendEmail.php and /assets/php/formmailer/functions.php. | CVSS3: 9.8 | 38% Средний | больше 3 лет назад | |
GHSA-2rmf-3rpp-rfgh Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | CVSS3: 8.8 | 8% Низкий | больше 1 года назад | |
GHSA-2rmc-v2mp-gxq4 In createFromParcel of GpsNavigationMessage.java, there is a possible Parcel serialization/deserialization mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-9Android ID: A-196970023 | 0% Низкий | около 4 лет назад | ||
GHSA-2rmc-r8fj-3p89 Honeywell PC42t, PC42tp, and PC42d Printers, T10.19.020016 to T10.20.060398, contain a cross-site scripting vulnerability. A(n) attacker could potentially inject malicious code which may lead to information disclosure, session theft, or client-side request forgery. Honeywell recommends updating to the most recent version of this firmware, PC42 Printer Firmware Version 20.6 T10.20.060398. | CVSS3: 3.5 | 0% Низкий | больше 1 года назад | |
GHSA-2rmc-p46g-jmrv chfn in pwdutils 3.0.4 and earlier on SuSE Linux, and possibly other operating systems, does not properly check arguments for the GECOS field, which allows local users to gain privileges. | 1% Низкий | почти 4 года назад | ||
GHSA-2rmc-f234-xhg3 A null pointer deference issue exists in GNU LibreDWG 0.10 via read_2004_compressed_section ../../src/decode.c:2337. | 0% Низкий | больше 3 лет назад | ||
GHSA-2rmc-2qhr-4jvg A use-after-free can occur during buffer storage operations within the ANGLE graphics library, used for WebGL content. The buffer storage can be freed while still in use in some circumstances, leading to a potentially exploitable crash. Note: This issue is in "libGLES", which is only in use on Windows. Other operating systems are not affected. This vulnerability affects Firefox < 52 and Thunderbird < 52. | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | |
GHSA-2rm9-pcmr-fvfj Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. | CVSS3: 7.8 | 0% Низкий | 8 месяцев назад | |
GHSA-2rm8-gh6q-8wpp Cross-Site Request Forgery (CSRF) vulnerability in pimwick PW WooCommerce Bulk Edit allows Cross Site Request Forgery. This issue affects PW WooCommerce Bulk Edit: from n/a through 2.134. | CVSS3: 5.4 | 0% Низкий | 9 месяцев назад | |
GHSA-2rm7-xxx8-35jh MediaWiki Cross-site Scripting (XSS) | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-2rm6-26jp-f4w2 A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.4, macOS Ventura 13.6.8. An attacker may be able to read information belonging to another user. | CVSS3: 7.5 | 0% Низкий | больше 1 года назад | |
GHSA-2rm4-vgjw-r4jw Unify OpenStage / OpenScape Desk Phone IP before V3 R3.11.0 SIP has an OS command injection vulnerability in the web based management interface | 5% Низкий | больше 3 лет назад | ||
GHSA-2rm4-pxv9-x75c The gdPngReadData function in libgd 2.0.34 allows user-assisted attackers to cause a denial of service (CPU consumption) via a crafted PNG image with truncated data, which causes an infinite loop in the png_read_info function in libpng. | 7% Низкий | почти 4 года назад |
Уязвимостей на страницу