Количество 314 691
Количество 314 691
GHSA-2mhh-8chh-jm97
The WordOCX ActiveX control in WordViewer.ocx 3.2.0.5 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long (1) DoOleCommand, (2) FTPDownloadFile, (3) FTPUploadFile, (4) HttpUploadFile, (5) GotoPage, (6) Save, (7) SaveWebFile, (8) HttpDownloadFile, (9) Open, (10) OpenWebFile, (11) SaveAs, or (12) ShowWordStandardDialog property value.
GHSA-2mhh-27v7-3vcx
WWBN AVideo command injection vulnerability
GHSA-2mhg-3m7f-9876
Buffer Over-read in GitHub repository vim/vim prior to 8.2.
GHSA-2mhf-732c-q449
A cross-site scripting (XSS) vulnerability in the administration web panel on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices allows remote attackers to inject arbitrary web script or HTML via the language parameter.
GHSA-2mhc-xxvw-f39p
Multiple untrusted search path vulnerabilities in CyberLink StreamAuthor 4.0 build 3308 allow local users to gain privileges via a Trojan horse (1) mfc71loc.dll or (2) mfc71enu.dll file in the current working directory, as demonstrated by a directory that contains a .sta or .stp file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
GHSA-2mh9-wpgv-7xr8
Jenkins Cloud Foundry Plugin vulnerable to exposure of sensitive information
GHSA-2mh9-q72v-7c49
H3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack overflow via the function edditactionlist.
GHSA-2mh8-mqmp-3xq6
The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.3.2. This is due to missing authorization checks on the eh_crm_edit_agent AJAX action. This makes it possible for authenticated attackers, with Contributor-level access and above, to escalate their WSDesk privileges from limited "Reply Tickets" permissions to full helpdesk administrator capabilities, gaining unauthorized access to ticket management, settings configuration, agent administration, and sensitive customer data.
GHSA-2mh8-gx2m-mr75
Out-of-Memory Error in Bouncy Castle Crypto
GHSA-2mh8-69x2-q9m6
The joomsport_md_load AJAX action of the JoomSport WordPress plugin before 5.1.8, registered for both unauthenticated and unauthenticated users, unserialised user input from the shattr POST parameter, leading to a PHP Object Injection issue. Even though the plugin does not have a suitable gadget chain to exploit this, other installed plugins could, which might lead to more severe issues such as RCE
GHSA-2mh7-vhgj-ccgw
Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
GHSA-2mh7-qxcw-q39g
francoisjacquet/rosariosis vulnerable to Cross-Site Scripting (XSS)
GHSA-2mh7-fwqw-352w
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themewinter Eventin allows Stored XSS.This issue affects Eventin: from n/a through 3.3.57.
GHSA-2mh6-g78c-5h6c
The Shared Files WordPress plugin before 1.7.6 does not return the right Content-Type header for the specified uploaded file. Therefore, an attacker can upload an allowed file extension injected with malicious scripts.
GHSA-2mh6-5954-wmgr
Denial of service through Solaris 2.5.1 telnet by sending ^D characters.
GHSA-2mh3-x6j9-j554
The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions.
GHSA-2mh3-566h-4f4x
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and 6 Update 43 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Beans.
GHSA-2mh2-9xm5-m59q
In the Linux kernel, the following vulnerability has been resolved: bonding: change ipsec_lock from spin lock to mutex In the cited commit, bond->ipsec_lock is added to protect ipsec_list, hence xdo_dev_state_add and xdo_dev_state_delete are called inside this lock. As ipsec_lock is a spin lock and such xfrmdev ops may sleep, "scheduling while atomic" will be triggered when changing bond's active slave. [ 101.055189] BUG: scheduling while atomic: bash/902/0x00000200 [ 101.055726] Modules linked in: [ 101.058211] CPU: 3 PID: 902 Comm: bash Not tainted 6.9.0-rc4+ #1 [ 101.058760] Hardware name: [ 101.059434] Call Trace: [ 101.059436] <TASK> [ 101.060873] dump_stack_lvl+0x51/0x60 [ 101.061275] __schedule_bug+0x4e/0x60 [ 101.061682] __schedule+0x612/0x7c0 [ 101.062078] ? __mod_timer+0x25c/0x370 [ 101.062486] schedule+0x25/0xd0 [ 101.062845] schedule_timeout+0x77/0xf0 [ 101.063265] ? asm_common_interrupt+0x22/0x40 [ 101.063724] ? __bpf_trace_itimer_state+0x10/0x...
GHSA-2mgx-x7qr-pm5v
Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB21 for Statistics and (2) DB22 for Upgrade & Downgrade. NOTE: as of 20060719, Oracle has not disputed a claim by a reliable researcher that DB21 is for a local SQL injection vulnerability in SYS.DBMS_STATS, and that DB22 is for SQL injection in SYS.DBMS_UPGRADE.
GHSA-2mgx-qf67-h3rj
Unbound before 1.9.5 allows an out-of-bounds write in sldns_bget_token_par.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2mhh-8chh-jm97 The WordOCX ActiveX control in WordViewer.ocx 3.2.0.5 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long (1) DoOleCommand, (2) FTPDownloadFile, (3) FTPUploadFile, (4) HttpUploadFile, (5) GotoPage, (6) Save, (7) SaveWebFile, (8) HttpDownloadFile, (9) Open, (10) OpenWebFile, (11) SaveAs, or (12) ShowWordStandardDialog property value. | 7% Низкий | почти 4 года назад | ||
GHSA-2mhh-27v7-3vcx WWBN AVideo command injection vulnerability | CVSS3: 8.8 | 4% Низкий | больше 2 лет назад | |
GHSA-2mhg-3m7f-9876 Buffer Over-read in GitHub repository vim/vim prior to 8.2. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-2mhf-732c-q449 A cross-site scripting (XSS) vulnerability in the administration web panel on NETGEAR JGS516PE/GS116Ev2 v2.6.0.43 devices allows remote attackers to inject arbitrary web script or HTML via the language parameter. | 0% Низкий | больше 3 лет назад | ||
GHSA-2mhc-xxvw-f39p Multiple untrusted search path vulnerabilities in CyberLink StreamAuthor 4.0 build 3308 allow local users to gain privileges via a Trojan horse (1) mfc71loc.dll or (2) mfc71enu.dll file in the current working directory, as demonstrated by a directory that contains a .sta or .stp file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 0% Низкий | больше 3 лет назад | ||
GHSA-2mh9-wpgv-7xr8 Jenkins Cloud Foundry Plugin vulnerable to exposure of sensitive information | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад | |
GHSA-2mh9-q72v-7c49 H3C Magic NX18 Plus NX18PV100R003 was discovered to contain a stack overflow via the function edditactionlist. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-2mh8-mqmp-3xq6 The ELEX WordPress HelpDesk & Customer Ticketing System plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.3.2. This is due to missing authorization checks on the eh_crm_edit_agent AJAX action. This makes it possible for authenticated attackers, with Contributor-level access and above, to escalate their WSDesk privileges from limited "Reply Tickets" permissions to full helpdesk administrator capabilities, gaining unauthorized access to ticket management, settings configuration, agent administration, and sensitive customer data. | CVSS3: 6.3 | 0% Низкий | 2 месяца назад | |
GHSA-2mh8-gx2m-mr75 Out-of-Memory Error in Bouncy Castle Crypto | CVSS3: 7.5 | 8% Низкий | больше 6 лет назад | |
GHSA-2mh8-69x2-q9m6 The joomsport_md_load AJAX action of the JoomSport WordPress plugin before 5.1.8, registered for both unauthenticated and unauthenticated users, unserialised user input from the shattr POST parameter, leading to a PHP Object Injection issue. Even though the plugin does not have a suitable gadget chain to exploit this, other installed plugins could, which might lead to more severe issues such as RCE | 4% Низкий | больше 3 лет назад | ||
GHSA-2mh7-vhgj-ccgw Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used. | около 1 года назад | |||
GHSA-2mh7-qxcw-q39g francoisjacquet/rosariosis vulnerable to Cross-Site Scripting (XSS) | CVSS3: 5.4 | 0% Низкий | больше 3 лет назад | |
GHSA-2mh7-fwqw-352w Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Themewinter Eventin allows Stored XSS.This issue affects Eventin: from n/a through 3.3.57. | CVSS3: 6.5 | 0% Низкий | больше 1 года назад | |
GHSA-2mh6-g78c-5h6c The Shared Files WordPress plugin before 1.7.6 does not return the right Content-Type header for the specified uploaded file. Therefore, an attacker can upload an allowed file extension injected with malicious scripts. | CVSS3: 6.1 | 0% Низкий | больше 2 лет назад | |
GHSA-2mh6-5954-wmgr Denial of service through Solaris 2.5.1 telnet by sending ^D characters. | 1% Низкий | почти 4 года назад | ||
GHSA-2mh3-x6j9-j554 The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions. | CVSS3: 6.1 | 0% Низкий | больше 1 года назад | |
GHSA-2mh3-566h-4f4x Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and 6 Update 43 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Beans. | 5% Низкий | больше 3 лет назад | ||
GHSA-2mh2-9xm5-m59q In the Linux kernel, the following vulnerability has been resolved: bonding: change ipsec_lock from spin lock to mutex In the cited commit, bond->ipsec_lock is added to protect ipsec_list, hence xdo_dev_state_add and xdo_dev_state_delete are called inside this lock. As ipsec_lock is a spin lock and such xfrmdev ops may sleep, "scheduling while atomic" will be triggered when changing bond's active slave. [ 101.055189] BUG: scheduling while atomic: bash/902/0x00000200 [ 101.055726] Modules linked in: [ 101.058211] CPU: 3 PID: 902 Comm: bash Not tainted 6.9.0-rc4+ #1 [ 101.058760] Hardware name: [ 101.059434] Call Trace: [ 101.059436] <TASK> [ 101.060873] dump_stack_lvl+0x51/0x60 [ 101.061275] __schedule_bug+0x4e/0x60 [ 101.061682] __schedule+0x612/0x7c0 [ 101.062078] ? __mod_timer+0x25c/0x370 [ 101.062486] schedule+0x25/0xd0 [ 101.062845] schedule_timeout+0x77/0xf0 [ 101.063265] ? asm_common_interrupt+0x22/0x40 [ 101.063724] ? __bpf_trace_itimer_state+0x10/0x... | CVSS3: 5.5 | 0% Низкий | больше 1 года назад | |
GHSA-2mgx-x7qr-pm5v Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB21 for Statistics and (2) DB22 for Upgrade & Downgrade. NOTE: as of 20060719, Oracle has not disputed a claim by a reliable researcher that DB21 is for a local SQL injection vulnerability in SYS.DBMS_STATS, and that DB22 is for SQL injection in SYS.DBMS_UPGRADE. | 4% Низкий | почти 4 года назад | ||
GHSA-2mgx-qf67-h3rj Unbound before 1.9.5 allows an out-of-bounds write in sldns_bget_token_par. | CVSS3: 9.8 | 1% Низкий | больше 3 лет назад |
Уязвимостей на страницу