Количество 314 375
Количество 314 375
GHSA-2vq3-7wqx-v4r2
Unspecified vulnerability in the SMB component in Apple Mac OS X 10.4.11 and 10.5.6 allows remote SMB servers to cause a denial of service (memory exhaustion and system shutdown) via a crafted file system name.
GHSA-2vq2-xc55-3j5m
libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c.
GHSA-2vq2-p76v-j88p
Format string vulnerability in ypserv in Mandrake Linux 7.1 and earlier, and possibly other Linux operating systems, allows an attacker to gain root privileges when ypserv is built without a vsyslog() function.
GHSA-2vq2-77wm-755c
Computer Associates (CA) InoculateIT 6.0, eTrust Antivirus r6.0 through r7.1, eTrust Antivirus for the Gateway r7.0 and r7.1, eTrust Secure Content Manager, eTrust Intrusion Detection, EZ-Armor 2.0 through 2.4, and EZ-Antivirus 6.1 through 6.3 allow remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system.
GHSA-2vpx-p529-jx74
Use-after-free vulnerability in the SVG implementation in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
GHSA-2vpx-j6gq-83g2
Multiple out-of-bounds read vulnerabilities were identified in a system component responsible for handling certain data buffers. Due to insufficient validation of maximum buffer size values, the process may attempt to read beyond the intended memory region. Under specific conditions, this can result in a crash of the affected process and a potential denial-of-service of the compromised process.
GHSA-2vpx-cqm4-rqhq
An issue was discovered in Joomla! 3.0.0 through 3.9.27. Inadequate escaping in the rules field of the JForm API leads to a XSS vulnerability.
GHSA-2vpw-vxmx-p733
Mattermost Desktop fails to correctly handle permissions or prompt the user for consent on certain sensitive ones allowing media exploitation from a malicious mattermost server
GHSA-2vpw-mvv7-vfx4
Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_generator/classes/SystemSettings.php?f=update_settings. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.
GHSA-2vpw-h4q9-62fp
Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the crackaddr function of headers.c.
GHSA-2vpv-qp3f-2f8m
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gopiplus@hotmail.com Anything Popup allows Reflected XSS. This issue affects Anything Popup: from n/a through 7.3.
GHSA-2vpv-3c94-j6hf
oBike relies on Hangzhou Luoping Smart Locker to lock bicycles, which allows attackers to bypass the locking mechanism by using Bluetooth Low Energy (BLE) to replay ciphertext based on a predictable nonce used in the locking protocol.
GHSA-2vpr-vq4j-xqcm
SQL injection vulnerability in admin/news.php in PHP Forge 3.0 beta 2 allows remote attackers to execute arbitrary SQL commands via the id parameter in the news module to admin.php.
GHSA-2vpr-464c-8pg4
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing VENDOR specific action frame in the function lim_process_action_vendor_specific(), a comparison is performed with the incoming action frame body without validating if the action frame body received is of valid length, potentially leading to an out-of-bounds access.
GHSA-2vpq-rpjx-r98w
Unspecified vulnerability in HP ProCurve Manager and HP ProCurve Manager Plus 2.3 and earlier allows remote attackers to obtain sensitive information from the ProCurve Manager server via unknown attack vectors.
GHSA-2vpq-fh52-j3wv
snowflake-connector-python vulnerable to SQL Injection in write_pandas
GHSA-2vpq-2h36-8fq9
Sourcecodester Payroll Management System v1.0 is vulnerable to File Upload. Users can upload images via the "save_settings" page. An unauthenticated attacker can leverage this functionality to upload a malicious PHP file instead. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as the user running the web server.
GHSA-2vpp-qc37-v798
Rejected reason: Accidental request.
GHSA-2vpp-jh6p-cxcg
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tuyennv TZ PlusGallery allows Stored XSS. This issue affects TZ PlusGallery: from n/a through 1.5.5.
GHSA-2vpj-c9hx-wv3q
The Notices WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/notices.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 6.1.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2vq3-7wqx-v4r2 Unspecified vulnerability in the SMB component in Apple Mac OS X 10.4.11 and 10.5.6 allows remote SMB servers to cause a denial of service (memory exhaustion and system shutdown) via a crafted file system name. | 0% Низкий | почти 4 года назад | ||
GHSA-2vq2-xc55-3j5m libexpat before 2.4.9 has a use-after-free in the doContent function in xmlparse.c. | CVSS3: 9.8 | 1% Низкий | больше 3 лет назад | |
GHSA-2vq2-p76v-j88p Format string vulnerability in ypserv in Mandrake Linux 7.1 and earlier, and possibly other Linux operating systems, allows an attacker to gain root privileges when ypserv is built without a vsyslog() function. | 0% Низкий | почти 4 года назад | ||
GHSA-2vq2-77wm-755c Computer Associates (CA) InoculateIT 6.0, eTrust Antivirus r6.0 through r7.1, eTrust Antivirus for the Gateway r7.0 and r7.1, eTrust Secure Content Manager, eTrust Intrusion Detection, EZ-Armor 2.0 through 2.4, and EZ-Antivirus 6.1 through 6.3 allow remote attackers to bypass antivirus protection via a compressed file with both local and global headers set to zero, which does not prevent the compressed file from being opened on a target system. | 30% Средний | почти 4 года назад | ||
GHSA-2vpx-p529-jx74 Use-after-free vulnerability in the SVG implementation in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors. | 1% Низкий | больше 3 лет назад | ||
GHSA-2vpx-j6gq-83g2 Multiple out-of-bounds read vulnerabilities were identified in a system component responsible for handling certain data buffers. Due to insufficient validation of maximum buffer size values, the process may attempt to read beyond the intended memory region. Under specific conditions, this can result in a crash of the affected process and a potential denial-of-service of the compromised process. | CVSS3: 5.3 | 0% Низкий | 24 дня назад | |
GHSA-2vpx-cqm4-rqhq An issue was discovered in Joomla! 3.0.0 through 3.9.27. Inadequate escaping in the rules field of the JForm API leads to a XSS vulnerability. | 2% Низкий | больше 3 лет назад | ||
GHSA-2vpw-vxmx-p733 Mattermost Desktop fails to correctly handle permissions or prompt the user for consent on certain sensitive ones allowing media exploitation from a malicious mattermost server | CVSS3: 3.7 | 0% Низкий | больше 2 лет назад | |
GHSA-2vpw-mvv7-vfx4 Sourcecodester Online ID Generator System 1.0 was discovered to contain an arbitrary file upload vulnerability via id_generator/classes/SystemSettings.php?f=update_settings. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | CVSS3: 9.8 | 1% Низкий | 10 месяцев назад | |
GHSA-2vpw-h4q9-62fp Buffer overflow in Sendmail 5.79 to 8.12.7 allows remote attackers to execute arbitrary code via certain formatted address fields, related to sender and recipient header comments as processed by the crackaddr function of headers.c. | 64% Средний | почти 4 года назад | ||
GHSA-2vpv-qp3f-2f8m Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in gopiplus@hotmail.com Anything Popup allows Reflected XSS. This issue affects Anything Popup: from n/a through 7.3. | CVSS3: 7.1 | 0% Низкий | 10 месяцев назад | |
GHSA-2vpv-3c94-j6hf oBike relies on Hangzhou Luoping Smart Locker to lock bicycles, which allows attackers to bypass the locking mechanism by using Bluetooth Low Energy (BLE) to replay ciphertext based on a predictable nonce used in the locking protocol. | CVSS3: 5.3 | 0% Низкий | больше 3 лет назад | |
GHSA-2vpr-vq4j-xqcm SQL injection vulnerability in admin/news.php in PHP Forge 3.0 beta 2 allows remote attackers to execute arbitrary SQL commands via the id parameter in the news module to admin.php. | 1% Низкий | почти 4 года назад | ||
GHSA-2vpr-464c-8pg4 In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing VENDOR specific action frame in the function lim_process_action_vendor_specific(), a comparison is performed with the incoming action frame body without validating if the action frame body received is of valid length, potentially leading to an out-of-bounds access. | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | |
GHSA-2vpq-rpjx-r98w Unspecified vulnerability in HP ProCurve Manager and HP ProCurve Manager Plus 2.3 and earlier allows remote attackers to obtain sensitive information from the ProCurve Manager server via unknown attack vectors. | 1% Низкий | почти 4 года назад | ||
GHSA-2vpq-fh52-j3wv snowflake-connector-python vulnerable to SQL Injection in write_pandas | CVSS3: 7 | 0% Низкий | около 1 года назад | |
GHSA-2vpq-2h36-8fq9 Sourcecodester Payroll Management System v1.0 is vulnerable to File Upload. Users can upload images via the "save_settings" page. An unauthenticated attacker can leverage this functionality to upload a malicious PHP file instead. Successful exploitation of this vulnerability results in the ability to execute arbitrary code as the user running the web server. | CVSS3: 9.8 | 42% Средний | больше 1 года назад | |
GHSA-2vpp-qc37-v798 Rejected reason: Accidental request. | около 2 лет назад | |||
GHSA-2vpp-jh6p-cxcg Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tuyennv TZ PlusGallery allows Stored XSS. This issue affects TZ PlusGallery: from n/a through 1.5.5. | CVSS3: 5.9 | 0% Низкий | 5 месяцев назад | |
GHSA-2vpj-c9hx-wv3q The Notices WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to a reflected $_SERVER["PHP_SELF"] value in the ~/notices.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 6.1. | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу