Количество 312 573
Количество 312 573
GHSA-2mp4-3r7m-mmg9
Multiple cross-site scripting (XSS) vulnerabilities in MyWeight 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) date parameter to user_addfood.php, info parameter to (2) user_forgot_pwd_form.php and (3) user_login.php, and (4) return parameter to user_login.php.
GHSA-2mp3-mchr-79rx
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 33 of 46).
GHSA-2mp2-8rhv-p755
IBM Cloud Pak System 2.3 and 2.3.0.1 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server. IBM X-Force ID: 158280.
GHSA-2mmx-jx99-8cmf
HP ThinPro 8.1 System management application failed to verify user's true id. HP has released HP ThinPro 8.1 SP8, which includes updates to mitigate potential vulnerabilities.
GHSA-2mmx-5mfh-2536
An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It mishandles IP-based rate limiting.
GHSA-2mmx-452m-3qmq
Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.5 allows an attacker to inject arbitrary web script or HTML via "Rich text" function of the application "Memo".
GHSA-2mmw-g99r-5x3v
Internet Shortcut Files Security Feature Bypass Vulnerability
GHSA-2mmv-7rrp-g8xh
Weblate command-line client susceptible to SSL verification skip
GHSA-2mmr-w2qp-r5qp
A cross-site request forgery (csrf) vulnerability exists in the WEBVIEW-M functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted HTTP request can lead to unauthorized access. An attacker can stage a malicious webpage to trigger this vulnerability.
GHSA-2mmr-5x9x-4m97
Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, failed to require a user gesture for powerful download operations, which allowed a remote attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted HTML page.
GHSA-2mmr-2hq6-5c3v
The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the relay_send_end_cell_from_edge_ function via a malformed BEGIN cell.
GHSA-2mmq-prpj-ww9q
Improper input validation in the TLS 1.3 KeyShareEntry parsing in wolfSSL v5.8.2 on multiple platforms allows a remote unauthenticated attacker to cause a denial-of-service by sending a crafted ClientHello message containing duplicate KeyShareEntry values for the same supported group, leading to excessive CPU and memory consumption during ClientHello processing.
GHSA-2mmq-f6mj-fwfx
In several functions of SettingsState.java, there is a possible system crash loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-239415861
GHSA-2mmp-4p76-vmrq
In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112663886
GHSA-2mmm-qjp3-8j87
e-Excellence U-Office Force has a path traversal vulnerability within its file uploading and downloading functions. An unauthenticated remote attacker can exploit this vulnerability to read arbitrary system files, but can’t control system or disrupt service.
GHSA-2mmj-hgqm-x284
Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by a token spoofing vulnerability. Each payment terminal has a session token (called X-Terminal-Token) to access the marketplace. This allows the store to identify the terminal and make available the applications distributed by its reseller. By intercepting HTTPS traffic from the application store, it is possible to collect the request responsible for assigning the X-Terminal-Token to the terminal, which makes it possible to craft an X-Terminal-Token pretending to be another device. An attacker can use this behavior to authenticate its own payment terminal in the application store through token impersonation.
GHSA-2mmg-vhx9-xmqq
An unspecified version of youtube-php-mirroring is affected by a Cross Site Scripting (XSS) vulnerability in file ytproxy/index.php.
GHSA-2mmg-r5qc-hhcj
archive_read_support_format_tar.c in libarchive before 2.2.4 allows user-assisted remote attackers to cause a denial of service (infinite loop) via (1) an end-of-file condition within a pax extension header or (2) a malformed pax extension header in an (a) PAX or a (b) TAR archive.
GHSA-2mmf-rqvr-m9qr
Microsoft On-Prem Data Gateway Security Feature Bypass Vulnerability
GHSA-2mmf-r54m-7994
mwlib 0.13 through 0.13.4 has a denial of service vulnerability when parsing #iferror magic functions
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2mp4-3r7m-mmg9 Multiple cross-site scripting (XSS) vulnerabilities in MyWeight 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) date parameter to user_addfood.php, info parameter to (2) user_forgot_pwd_form.php and (3) user_login.php, and (4) return parameter to user_login.php. | 1% Низкий | почти 4 года назад | ||
GHSA-2mp3-mchr-79rx Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 33 of 46). | CVSS3: 8.8 | 7% Низкий | больше 3 лет назад | |
GHSA-2mp2-8rhv-p755 IBM Cloud Pak System 2.3 and 2.3.0.1 could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server. IBM X-Force ID: 158280. | 2% Низкий | больше 3 лет назад | ||
GHSA-2mmx-jx99-8cmf HP ThinPro 8.1 System management application failed to verify user's true id. HP has released HP ThinPro 8.1 SP8, which includes updates to mitigate potential vulnerabilities. | CVSS3: 9.8 | 0% Низкий | 3 месяца назад | |
GHSA-2mmx-5mfh-2536 An issue was discovered in Mattermost Server before 4.2.0, 4.1.1, and 4.0.5. It mishandles IP-based rate limiting. | 0% Низкий | больше 3 лет назад | ||
GHSA-2mmx-452m-3qmq Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.5 allows an attacker to inject arbitrary web script or HTML via "Rich text" function of the application "Memo". | CVSS3: 5.4 | 0% Низкий | больше 3 лет назад | |
GHSA-2mmw-g99r-5x3v Internet Shortcut Files Security Feature Bypass Vulnerability | CVSS3: 8.1 | 94% Критический | почти 2 года назад | |
GHSA-2mmv-7rrp-g8xh Weblate command-line client susceptible to SSL verification skip | CVSS3: 2.5 | 0% Низкий | 27 дней назад | |
GHSA-2mmr-w2qp-r5qp A cross-site request forgery (csrf) vulnerability exists in the WEBVIEW-M functionality of Socomec DIRIS Digiware M-70 1.6.9. A specially crafted HTTP request can lead to unauthorized access. An attacker can stage a malicious webpage to trigger this vulnerability. | CVSS3: 7.5 | 0% Низкий | 2 месяца назад | |
GHSA-2mmr-5x9x-4m97 Google Chrome prior to 56.0.2924.76 for Linux, Windows and Mac, and 56.0.2924.87 for Android, failed to require a user gesture for powerful download operations, which allowed a remote attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted HTML page. | CVSS3: 6.1 | 1% Низкий | больше 3 лет назад | |
GHSA-2mmr-2hq6-5c3v The hidden-service feature in Tor before 0.3.0.8 allows a denial of service (assertion failure and daemon exit) in the relay_send_end_cell_from_edge_ function via a malformed BEGIN cell. | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | |
GHSA-2mmq-prpj-ww9q Improper input validation in the TLS 1.3 KeyShareEntry parsing in wolfSSL v5.8.2 on multiple platforms allows a remote unauthenticated attacker to cause a denial-of-service by sending a crafted ClientHello message containing duplicate KeyShareEntry values for the same supported group, leading to excessive CPU and memory consumption during ClientHello processing. | CVSS3: 5.3 | 0% Низкий | 3 месяца назад | |
GHSA-2mmq-f6mj-fwfx In several functions of SettingsState.java, there is a possible system crash loop due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-239415861 | CVSS3: 5.5 | 0% Низкий | около 3 лет назад | |
GHSA-2mmp-4p76-vmrq In libAACdec, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-112663886 | 0% Низкий | больше 3 лет назад | ||
GHSA-2mmm-qjp3-8j87 e-Excellence U-Office Force has a path traversal vulnerability within its file uploading and downloading functions. An unauthenticated remote attacker can exploit this vulnerability to read arbitrary system files, but can’t control system or disrupt service. | CVSS3: 7.5 | 0% Низкий | больше 2 лет назад | |
GHSA-2mmj-hgqm-x284 Pax Technology PAXSTORE v7.0.8_20200511171508 and lower is affected by a token spoofing vulnerability. Each payment terminal has a session token (called X-Terminal-Token) to access the marketplace. This allows the store to identify the terminal and make available the applications distributed by its reseller. By intercepting HTTPS traffic from the application store, it is possible to collect the request responsible for assigning the X-Terminal-Token to the terminal, which makes it possible to craft an X-Terminal-Token pretending to be another device. An attacker can use this behavior to authenticate its own payment terminal in the application store through token impersonation. | 0% Низкий | больше 3 лет назад | ||
GHSA-2mmg-vhx9-xmqq An unspecified version of youtube-php-mirroring is affected by a Cross Site Scripting (XSS) vulnerability in file ytproxy/index.php. | CVSS3: 6.1 | 0% Низкий | около 4 лет назад | |
GHSA-2mmg-r5qc-hhcj archive_read_support_format_tar.c in libarchive before 2.2.4 allows user-assisted remote attackers to cause a denial of service (infinite loop) via (1) an end-of-file condition within a pax extension header or (2) a malformed pax extension header in an (a) PAX or a (b) TAR archive. | 13% Средний | почти 4 года назад | ||
GHSA-2mmf-rqvr-m9qr Microsoft On-Prem Data Gateway Security Feature Bypass Vulnerability | CVSS3: 8 | 0% Низкий | около 2 лет назад | |
GHSA-2mmf-r54m-7994 mwlib 0.13 through 0.13.4 has a denial of service vulnerability when parsing #iferror magic functions | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад |
Уязвимостей на страницу