Количество 313 574
Количество 313 574
GHSA-2vc7-qfwp-f3cw
Transient DOS while processing 11AZ RTT management action frame received through OTA.
GHSA-2vc7-6w39-6rh2
An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulnerable to remote code execution. When the admin key was changed or the port of Admin API was changed to a port different from the data panel, the impact is lower. But there is still a risk to bypass the IP restriction of Apache APISIX's data panel. There is a check in the batch-requests plugin which overrides the client IP with its real remote IP. But due to a bug in the code, this check can be bypassed.
GHSA-2vc6-9c9h-vvhf
IBM Security Guardium 12.1 could allow a local privileged user to escalate their privileges to root due to insecure inherited permissions created by the program.
GHSA-2vc5-r994-6g7m
The Document Embedder WordPress plugin before 1.7.9 contains a AJAX action endpoint, which could allow any authenticated user, such as subscriber to enumerate the title of arbitrary private and draft posts.
GHSA-2vc4-3hx7-v7v7
Hax CMS Stored Cross-Site Scripting vulnerability
GHSA-2vc3-c2mw-f762
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rock Solid Responsive Modal Builder for High Conversion – Easy Popups allows Reflected XSS. This issue affects Responsive Modal Builder for High Conversion – Easy Popups: from n/a through 1.5.0.
GHSA-2vc3-4962-hqrf
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: connac: check for null before dereferencing The wcid can be NULL. It should be checked for validity before dereferencing it to avoid crash.
GHSA-2vc2-4346-vqmx
In Crea8social 2018.2, there is Reflected Cross-Site Scripting via the term parameter to the /search URI.
GHSA-2v9x-x358-276j
WayOS IBR-7150 <17.06.23 is vulnerable to Cross Site Scripting (XSS).
GHSA-2v9x-gpq4-8gg2
CSRF vulnerability in Jenkins Shared Objects Plugin
GHSA-2v9x-c45w-29qx
On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, a large HTTP POST request sent to the change password API will trigger the router to crash and enter an infinite boot loop.
GHSA-2v9x-58p7-6ch2
Digital Reality game engine, as used in Haegemonia 1.0 through 1.0.7 and Desert Rats vs. Afrika Korps 1.0, allows remote attackers to cause a denial of service (crash) via a chat message with a large message size, which triggers an out-of-bounds read.
GHSA-2v9w-j2pw-g467
Microsoft PowerPoint 2000 in Office 2000 SP3 has an interaction with Internet Explorer that allows remote attackers to obtain sensitive information via a PowerPoint presentation that attempts to access objects in the Temporary Internet Files Folder (TIFF).
GHSA-2v9v-6h75-597v
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix off by one in hdmi_14_process_transaction() The hdcp_i2c_offsets[] array did not have an entry for HDCP_MESSAGE_ID_WRITE_CONTENT_STREAM_TYPE so it led to an off by one read overflow. I added an entry and copied the 0x0 value for the offset from similar code in drivers/gpu/drm/amd/display/modules/hdcp/hdcp_ddc.c. I also declared several of these arrays as having HDCP_MESSAGE_ID_MAX entries. This doesn't change the code, but it's just a belt and suspenders approach to try future proof the code.
GHSA-2v9r-f76x-xq4j
D-Link G416 ovpncfg Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link G416 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the HTTP service listening on TCP port 80. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-21441.
GHSA-2v9r-9rfw-9hvf
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Adrenalin 5.4 HRMS Software. The user supplied input containing JavaScript is echoed back in JavaScript code in an HTML response via the ShiftEmployeeSearch.aspx prntFrmName or prntDDLCntrlName parameter.
GHSA-2v9r-8543-48mw
In the Lustre file system before 2.12.3, the ptlrpc module has an out-of-bounds access and panic due to the lack of validation for specific fields of packets sent by a client. In the function lustre_msg_string, there is no validation of a certain length value derived from lustre_msg_buflen_v2.
GHSA-2v9q-c3g9-f96r
Multiple vulnerabilities in Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allow remote attackers to cause a denial of service (crash) via crafted HTML that triggers memory corruption or assert errors.
GHSA-2v9p-rm2h-mp4j
Multiple open redirect vulnerabilities in NopCommerce 4.10 through 4.50.1 allow remote attackers to conduct phishing attacks by redirecting users to attacker-controlled web sites via the returnUrl parameter, processed by the (1) ChangePassword function, (2) SignInCustomerAsync function, (3) SuccessfulAuthentication method, or (4) NopRedirectResultExecutor class.
GHSA-2v9p-jv6j-hxqx
Icecast before 2.4.0 does not change the supplementary group privileges when <changeowner> is configured, which allows local users to gain privileges via unspecified vectors.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2vc7-qfwp-f3cw Transient DOS while processing 11AZ RTT management action frame received through OTA. | CVSS3: 7.5 | 0% Низкий | около 2 лет назад | |
GHSA-2vc7-6w39-6rh2 An attacker can abuse the batch-requests plugin to send requests to bypass the IP restriction of Admin API. A default configuration of Apache APISIX (with default API key) is vulnerable to remote code execution. When the admin key was changed or the port of Admin API was changed to a port different from the data panel, the impact is lower. But there is still a risk to bypass the IP restriction of Apache APISIX's data panel. There is a check in the batch-requests plugin which overrides the client IP with its real remote IP. But due to a bug in the code, this check can be bypassed. | CVSS3: 9.8 | 94% Критический | почти 4 года назад | |
GHSA-2vc6-9c9h-vvhf IBM Security Guardium 12.1 could allow a local privileged user to escalate their privileges to root due to insecure inherited permissions created by the program. | CVSS3: 6.7 | 0% Низкий | 8 месяцев назад | |
GHSA-2vc5-r994-6g7m The Document Embedder WordPress plugin before 1.7.9 contains a AJAX action endpoint, which could allow any authenticated user, such as subscriber to enumerate the title of arbitrary private and draft posts. | 0% Низкий | около 4 лет назад | ||
GHSA-2vc4-3hx7-v7v7 Hax CMS Stored Cross-Site Scripting vulnerability | CVSS3: 8.5 | 0% Низкий | 8 месяцев назад | |
GHSA-2vc3-c2mw-f762 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rock Solid Responsive Modal Builder for High Conversion – Easy Popups allows Reflected XSS. This issue affects Responsive Modal Builder for High Conversion – Easy Popups: from n/a through 1.5.0. | CVSS3: 7.1 | 0% Низкий | 12 месяцев назад | |
GHSA-2vc3-4962-hqrf In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: connac: check for null before dereferencing The wcid can be NULL. It should be checked for validity before dereferencing it to avoid crash. | CVSS3: 5.5 | 0% Низкий | больше 1 года назад | |
GHSA-2vc2-4346-vqmx In Crea8social 2018.2, there is Reflected Cross-Site Scripting via the term parameter to the /search URI. | CVSS3: 5.4 | 0% Низкий | больше 3 лет назад | |
GHSA-2v9x-x358-276j WayOS IBR-7150 <17.06.23 is vulnerable to Cross Site Scripting (XSS). | CVSS3: 4.7 | 0% Низкий | почти 2 года назад | |
GHSA-2v9x-gpq4-8gg2 CSRF vulnerability in Jenkins Shared Objects Plugin | CVSS3: 4.3 | 1% Низкий | больше 3 лет назад | |
GHSA-2v9x-c45w-29qx On Tenda AC1200 (Model AC6) 15.03.06.51_multi devices, a large HTTP POST request sent to the change password API will trigger the router to crash and enter an infinite boot loop. | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
GHSA-2v9x-58p7-6ch2 Digital Reality game engine, as used in Haegemonia 1.0 through 1.0.7 and Desert Rats vs. Afrika Korps 1.0, allows remote attackers to cause a denial of service (crash) via a chat message with a large message size, which triggers an out-of-bounds read. | 0% Низкий | почти 4 года назад | ||
GHSA-2v9w-j2pw-g467 Microsoft PowerPoint 2000 in Office 2000 SP3 has an interaction with Internet Explorer that allows remote attackers to obtain sensitive information via a PowerPoint presentation that attempts to access objects in the Temporary Internet Files Folder (TIFF). | 51% Средний | почти 4 года назад | ||
GHSA-2v9v-6h75-597v In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Fix off by one in hdmi_14_process_transaction() The hdcp_i2c_offsets[] array did not have an entry for HDCP_MESSAGE_ID_WRITE_CONTENT_STREAM_TYPE so it led to an off by one read overflow. I added an entry and copied the 0x0 value for the offset from similar code in drivers/gpu/drm/amd/display/modules/hdcp/hdcp_ddc.c. I also declared several of these arrays as having HDCP_MESSAGE_ID_MAX entries. This doesn't change the code, but it's just a belt and suspenders approach to try future proof the code. | CVSS3: 7.8 | 0% Низкий | почти 2 года назад | |
GHSA-2v9r-f76x-xq4j D-Link G416 ovpncfg Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of D-Link G416 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the HTTP service listening on TCP port 80. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-21441. | CVSS3: 8.8 | 4% Низкий | почти 2 года назад | |
GHSA-2v9r-9rfw-9hvf A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Adrenalin 5.4 HRMS Software. The user supplied input containing JavaScript is echoed back in JavaScript code in an HTML response via the ShiftEmployeeSearch.aspx prntFrmName or prntDDLCntrlName parameter. | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-2v9r-8543-48mw In the Lustre file system before 2.12.3, the ptlrpc module has an out-of-bounds access and panic due to the lack of validation for specific fields of packets sent by a client. In the function lustre_msg_string, there is no validation of a certain length value derived from lustre_msg_buflen_v2. | 1% Низкий | больше 3 лет назад | ||
GHSA-2v9q-c3g9-f96r Multiple vulnerabilities in Mozilla Firefox before 2.0.0.8, Thunderbird before 2.0.0.8, and SeaMonkey before 1.1.5 allow remote attackers to cause a denial of service (crash) via crafted HTML that triggers memory corruption or assert errors. | 25% Средний | почти 4 года назад | ||
GHSA-2v9p-rm2h-mp4j Multiple open redirect vulnerabilities in NopCommerce 4.10 through 4.50.1 allow remote attackers to conduct phishing attacks by redirecting users to attacker-controlled web sites via the returnUrl parameter, processed by the (1) ChangePassword function, (2) SignInCustomerAsync function, (3) SuccessfulAuthentication method, or (4) NopRedirectResultExecutor class. | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-2v9p-jv6j-hxqx Icecast before 2.4.0 does not change the supplementary group privileges when <changeowner> is configured, which allows local users to gain privileges via unspecified vectors. | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу