Количество 314 458
Количество 314 458
GHSA-2wqp-mvhf-mj78
In BTA_GATTS_HandleValueIndication of bta_gatts_api.cc, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-245915315
GHSA-2wqp-jmcc-mc77
Regular expression denial of service (ReDoS) in EmailField component in Vaadin 14 and 15-17
GHSA-2wqp-c8qr-gw2j
Cross-site scripting (XSS) vulnerability in upload/install/index.php in PHCDownload 1.1 allows remote attackers to inject arbitrary web script or HTML via the step parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
GHSA-2wqp-2j8m-7925
emlog v6.0.0 has CSRF via the admin/user.php?action=new URI.
GHSA-2wqm-wj66-jfhg
The Simple Membership plugin before 3.8.5 for WordPress has CSRF affecting the Bulk Operation section.
GHSA-2wqm-v6p6-8mqx
ToolJet versions v0.6.0 to v1.10.2 are vulnerable to HTML injection where an attacker can inject malicious code inside the first name and last name field while inviting a new user which will be reflected in the invitational e-mail.
GHSA-2wqm-g7m4-4gj8
iptables before 1.2.4 does not accurately convert rate limits that are specified on the command line, which could allow attackers or users to generate more or less traffic than intended by the administrator.
GHSA-2wqh-23wf-9qr9
Deserialization of Untrusted Data vulnerability in WPClever WPC Shop as a Customer for WooCommerce allows Object Injection.This issue affects WPC Shop as a Customer for WooCommerce: from n/a through 1.2.6.
GHSA-2wqf-w23q-7294
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
GHSA-2wqf-4598-f4f3
Directory traversal vulnerability in index.php in Blank'N'Berg 0.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the _path parameter.
GHSA-2wqc-47g4-pm22
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Catch Themes Essential Widgets essential-widgets allows Stored XSS.This issue affects Essential Widgets: from n/a through <= 2.2.2.
GHSA-2wq9-hq2m-2hfq
The Blog2Social plugin for WordPress is vulnerable to authorization bypass due to missing capability checks in versions up to, and including, 6.9.11. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change some plugin settings intended to be modifiable by admins only.
GHSA-2wq8-q24x-h8rw
Espressif ESP-IDF 2.x, 3.0.x through 3.0.9, 3.1.x through 3.1.7, 3.2.x through 3.2.3, 3.3.x through 3.3.2, and 4.0.x through 4.0.1 has a Buffer Overflow in BluFi provisioning in btc_blufi_recv_handler function in blufi_prf.c. An attacker can send a crafted BluFi protocol Write Attribute command to characteristic 0xFF01. With manipulated packet fields, there is a buffer overflow.
GHSA-2wq8-mxfj-4758
A vulnerability found in UniFi Talk application V1.12.3 and earlier permits a malicious actor who has already gained access to a network to subsequently control Talk device(s) assigned to said network if they are not yet adopted. This vulnerability is fixed in UniFi Talk application V1.12.5 and later.
GHSA-2wq7-x39p-77fm
Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to media buffers.
GHSA-2wq7-p5vp-5q7g
In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper length check Validation in WLAN function can lead to driver writes the default rsn capabilities to the memory not allocated to the frame.
GHSA-2wq7-hx2p-5748
Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network.
GHSA-2wq7-hcmr-3vvx
In gatts_process_attribute_req of gatt_sc.cc, there is a possible read of uninitialized data due to a missing bounds check. This could lead to remote information disclosure in the Bluetooth process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-73172115.
GHSA-2wq6-27jx-rfq7
Inappropriate implementation in Navigation in Google Chrome on iOS prior to 90.0.4430.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page.
GHSA-2wq5-g96f-mv3v
Ouch! allows a segmentation fault due to use of uninitialized memory
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2wqp-mvhf-mj78 In BTA_GATTS_HandleValueIndication of bta_gatts_api.cc, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-245915315 | CVSS3: 7.8 | 0% Низкий | почти 3 года назад | |
GHSA-2wqp-jmcc-mc77 Regular expression denial of service (ReDoS) in EmailField component in Vaadin 14 and 15-17 | CVSS3: 7.5 | 0% Низкий | почти 5 лет назад | |
GHSA-2wqp-c8qr-gw2j Cross-site scripting (XSS) vulnerability in upload/install/index.php in PHCDownload 1.1 allows remote attackers to inject arbitrary web script or HTML via the step parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 0% Низкий | больше 3 лет назад | ||
GHSA-2wqp-2j8m-7925 emlog v6.0.0 has CSRF via the admin/user.php?action=new URI. | CVSS3: 8.8 | 0% Низкий | больше 3 лет назад | |
GHSA-2wqm-wj66-jfhg The Simple Membership plugin before 3.8.5 for WordPress has CSRF affecting the Bulk Operation section. | CVSS3: 8.8 | 0% Низкий | больше 3 лет назад | |
GHSA-2wqm-v6p6-8mqx ToolJet versions v0.6.0 to v1.10.2 are vulnerable to HTML injection where an attacker can inject malicious code inside the first name and last name field while inviting a new user which will be reflected in the invitational e-mail. | CVSS3: 5.4 | 0% Низкий | больше 3 лет назад | |
GHSA-2wqm-g7m4-4gj8 iptables before 1.2.4 does not accurately convert rate limits that are specified on the command line, which could allow attackers or users to generate more or less traffic than intended by the administrator. | 0% Низкий | почти 4 года назад | ||
GHSA-2wqh-23wf-9qr9 Deserialization of Untrusted Data vulnerability in WPClever WPC Shop as a Customer for WooCommerce allows Object Injection.This issue affects WPC Shop as a Customer for WooCommerce: from n/a through 1.2.6. | CVSS3: 8.8 | 1% Низкий | больше 1 года назад | |
GHSA-2wqf-w23q-7294 An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. | CVSS3: 8.8 | 1% Низкий | больше 3 лет назад | |
GHSA-2wqf-4598-f4f3 Directory traversal vulnerability in index.php in Blank'N'Berg 0.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the _path parameter. | 5% Низкий | почти 4 года назад | ||
GHSA-2wqc-47g4-pm22 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Catch Themes Essential Widgets essential-widgets allows Stored XSS.This issue affects Essential Widgets: from n/a through <= 2.2.2. | CVSS3: 6.5 | 0% Низкий | 2 месяца назад | |
GHSA-2wq9-hq2m-2hfq The Blog2Social plugin for WordPress is vulnerable to authorization bypass due to missing capability checks in versions up to, and including, 6.9.11. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to change some plugin settings intended to be modifiable by admins only. | CVSS3: 4.7 | 0% Низкий | больше 2 лет назад | |
GHSA-2wq8-q24x-h8rw Espressif ESP-IDF 2.x, 3.0.x through 3.0.9, 3.1.x through 3.1.7, 3.2.x through 3.2.3, 3.3.x through 3.3.2, and 4.0.x through 4.0.1 has a Buffer Overflow in BluFi provisioning in btc_blufi_recv_handler function in blufi_prf.c. An attacker can send a crafted BluFi protocol Write Attribute command to characteristic 0xFF01. With manipulated packet fields, there is a buffer overflow. | 0% Низкий | больше 3 лет назад | ||
GHSA-2wq8-mxfj-4758 A vulnerability found in UniFi Talk application V1.12.3 and earlier permits a malicious actor who has already gained access to a network to subsequently control Talk device(s) assigned to said network if they are not yet adopted. This vulnerability is fixed in UniFi Talk application V1.12.5 and later. | CVSS3: 8.8 | 1% Низкий | больше 3 лет назад | |
GHSA-2wq7-x39p-77fm Use-after-free vulnerability in Google Chrome before 15.0.874.102 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to media buffers. | 1% Низкий | больше 3 лет назад | ||
GHSA-2wq7-p5vp-5q7g In all android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the linux kernel, improper length check Validation in WLAN function can lead to driver writes the default rsn capabilities to the memory not allocated to the frame. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-2wq7-hx2p-5748 Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network. | CVSS3: 8.7 | 0% Низкий | 9 месяцев назад | |
GHSA-2wq7-hcmr-3vvx In gatts_process_attribute_req of gatt_sc.cc, there is a possible read of uninitialized data due to a missing bounds check. This could lead to remote information disclosure in the Bluetooth process with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-73172115. | CVSS3: 7.5 | 2% Низкий | больше 3 лет назад | |
GHSA-2wq6-27jx-rfq7 Inappropriate implementation in Navigation in Google Chrome on iOS prior to 90.0.4430.72 allowed a remote attacker to leak cross-origin data via a crafted HTML page. | 1% Низкий | больше 3 лет назад | ||
GHSA-2wq5-g96f-mv3v Ouch! allows a segmentation fault due to use of uninitialized memory | больше 1 года назад |
Уязвимостей на страницу