Количество 314 691
Количество 314 691
GHSA-2mj3-vfvx-fc43
Moby Race Condition vulnerability
GHSA-2mj3-mc6h-qcgc
The installer in ICZ MATCHA INVOICE before 2.5.7 does not properly configure the database, which allows remote attackers to execute arbitrary PHP code via unspecified vectors.
GHSA-2mj3-95g6-565f
In the open build service before 201707022 the wipetrigger and rebuild actions checked the wrong project for permissions, allowing authenticated users to cause operations on projects where they did not have permissions leading to denial of service (resource consumption).
GHSA-2mj3-6grc-px38
Filebeat Beats has Buffer Overflow via Malformed Syslog Message or Malicious Tokenizer Pattern in Dissect Configuration
GHSA-2mj2-v476-v72f
IOMobileFramebuffer in Apple iOS before 8.3 and Apple TV before 7.2 allows attackers to obtain sensitive information about kernel memory via a crafted app.
GHSA-2mhx-hwp3-8q55
The RichEdit component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1; Office 2000 SP3, XP SP3, 2003 SP2, and Office 2004 for Mac; and Learning Essentials for Microsoft Office 1.0, 1.1, and 1.5 allows user-assisted remote attackers to execute arbitrary code via a malformed OLE object in an RTF file, which triggers memory corruption.
GHSA-2mhx-fmhx-vpcc
The N-able PassPortal extension before 3.29.2 for Chrome inserts sensitive information into a log file.
GHSA-2mhx-6p2w-94qg
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osamaesh WP Visitor Statistics (Real Time Traffic) allows Stored XSS. This issue affects WP Visitor Statistics (Real Time Traffic): from n/a through 7.2.
GHSA-2mhw-g2wf-7mpp
SysAid - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
GHSA-2mhw-3vvw-386g
Sudo VISudo 1.6.8 and earlier allows local users to corrupt arbitrary files via a symlink attack on temporary files.
GHSA-2mhv-m6h4-3h94
Improper privilege management in Zoom Rooms before version 5.14.5 may allow an authenticated user to enable an escalation of privilege via local access.
GHSA-2mhv-gvhq-ff4g
Office Tracker 11.2.5 has XSS via the logincount parameter to the /otweb/OTPClientLogin URI.
GHSA-2mhv-543f-h64j
A race condition was found in the way the Linux kernel's memory subsystem handled the copy-on-write (COW) breakage of private read-only shared memory mappings. This flaw allows an unprivileged, local user to gain write access to read-only memory mappings, increasing their privileges on the system.
GHSA-2mhr-7vwh-hrjc
SQL injection vulnerability in the password recovery feature in Yeager CMS 1.2.1 allows remote attackers to change the account credentials of known users via the "userEmail" parameter.
GHSA-2mhq-qg26-p24h
An Activation function in the RPCSS Service involved with DCOM activation for Microsoft Windows 2000, XP, and 2003 allows remote attackers to cause a denial of service (memory consumption) via an activation request with a large length field.
GHSA-2mhq-48gx-32rg
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in 8theme XStore allows Code Injection. This issue affects XStore: from n/a through 9.5.3.
GHSA-2mhq-3gfj-j2g2
Cross-site scripting (XSS) vulnerability in Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote attackers to inject arbitrary web script or HTML via the IP parameter to script/statistics/getconn.php.
GHSA-2mhp-j72r-j69f
Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1 might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-1188.
GHSA-2mhj-64gr-7wf9
IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request.
GHSA-2mhh-w6q8-5hxw
Remote Memory Disclosure in ws
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2mj3-vfvx-fc43 Moby Race Condition vulnerability | CVSS3: 6.5 | 0% Низкий | около 1 года назад | |
GHSA-2mj3-mc6h-qcgc The installer in ICZ MATCHA INVOICE before 2.5.7 does not properly configure the database, which allows remote attackers to execute arbitrary PHP code via unspecified vectors. | 1% Низкий | больше 3 лет назад | ||
GHSA-2mj3-95g6-565f In the open build service before 201707022 the wipetrigger and rebuild actions checked the wrong project for permissions, allowing authenticated users to cause operations on projects where they did not have permissions leading to denial of service (resource consumption). | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад | |
GHSA-2mj3-6grc-px38 Filebeat Beats has Buffer Overflow via Malformed Syslog Message or Malicious Tokenizer Pattern in Dissect Configuration | CVSS3: 6.5 | 0% Низкий | около 2 месяцев назад | |
GHSA-2mj2-v476-v72f IOMobileFramebuffer in Apple iOS before 8.3 and Apple TV before 7.2 allows attackers to obtain sensitive information about kernel memory via a crafted app. | 0% Низкий | больше 3 лет назад | ||
GHSA-2mhx-hwp3-8q55 The RichEdit component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1; Office 2000 SP3, XP SP3, 2003 SP2, and Office 2004 for Mac; and Learning Essentials for Microsoft Office 1.0, 1.1, and 1.5 allows user-assisted remote attackers to execute arbitrary code via a malformed OLE object in an RTF file, which triggers memory corruption. | 71% Высокий | почти 4 года назад | ||
GHSA-2mhx-fmhx-vpcc The N-able PassPortal extension before 3.29.2 for Chrome inserts sensitive information into a log file. | CVSS3: 7.5 | 0% Низкий | около 2 лет назад | |
GHSA-2mhx-6p2w-94qg Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in osamaesh WP Visitor Statistics (Real Time Traffic) allows Stored XSS. This issue affects WP Visitor Statistics (Real Time Traffic): from n/a through 7.2. | CVSS3: 6.5 | 0% Низкий | около 1 года назад | |
GHSA-2mhw-g2wf-7mpp SysAid - CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') | CVSS3: 9.1 | 0% Низкий | больше 1 года назад | |
GHSA-2mhw-3vvw-386g Sudo VISudo 1.6.8 and earlier allows local users to corrupt arbitrary files via a symlink attack on temporary files. | 0% Низкий | почти 4 года назад | ||
GHSA-2mhv-m6h4-3h94 Improper privilege management in Zoom Rooms before version 5.14.5 may allow an authenticated user to enable an escalation of privilege via local access. | CVSS3: 7.3 | 0% Низкий | больше 2 лет назад | |
GHSA-2mhv-gvhq-ff4g Office Tracker 11.2.5 has XSS via the logincount parameter to the /otweb/OTPClientLogin URI. | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-2mhv-543f-h64j A race condition was found in the way the Linux kernel's memory subsystem handled the copy-on-write (COW) breakage of private read-only shared memory mappings. This flaw allows an unprivileged, local user to gain write access to read-only memory mappings, increasing their privileges on the system. | CVSS3: 7 | 0% Низкий | больше 3 лет назад | |
GHSA-2mhr-7vwh-hrjc SQL injection vulnerability in the password recovery feature in Yeager CMS 1.2.1 allows remote attackers to change the account credentials of known users via the "userEmail" parameter. | CVSS3: 9.8 | 6% Низкий | больше 3 лет назад | |
GHSA-2mhq-qg26-p24h An Activation function in the RPCSS Service involved with DCOM activation for Microsoft Windows 2000, XP, and 2003 allows remote attackers to cause a denial of service (memory consumption) via an activation request with a large length field. | 54% Средний | почти 4 года назад | ||
GHSA-2mhq-48gx-32rg Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in 8theme XStore allows Code Injection. This issue affects XStore: from n/a through 9.5.3. | CVSS3: 5.3 | 0% Низкий | 5 месяцев назад | |
GHSA-2mhq-3gfj-j2g2 Cross-site scripting (XSS) vulnerability in Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote attackers to inject arbitrary web script or HTML via the IP parameter to script/statistics/getconn.php. | CVSS3: 6.1 | 1% Низкий | больше 3 лет назад | |
GHSA-2mhp-j72r-j69f Integer overflow in the SplashBitmap::SplashBitmap function in Xpdf 3.x before 3.02pl4 and Poppler before 0.12.1 might allow remote attackers to execute arbitrary code via a crafted PDF document that triggers a heap-based buffer overflow. NOTE: some of these details are obtained from third party information. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2009-1188. | 6% Низкий | почти 4 года назад | ||
GHSA-2mhj-64gr-7wf9 IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL they really request. | 53% Средний | почти 4 года назад | ||
GHSA-2mhh-w6q8-5hxw Remote Memory Disclosure in ws | 0% Низкий | почти 7 лет назад |
Уязвимостей на страницу