Количество 314 458
Количество 314 458
GHSA-2j8g-w8gx-h43r
The vulnerability, if exploited, could allow an authenticated miscreant (with privileges to create or access publication targets of type Text File or HDFS) to upload and persist files that could potentially be executed.
GHSA-2j8f-gpq9-f2mv
The publish-event event-manager feature in Cisco IOS 15.5(2)S and 15.5(3)S on Cloud Services Router 1000V devices allows local users to execute arbitrary commands with root privileges by leveraging administrative access to enter crafted environment variables, aka Bug ID CSCux14943.
GHSA-2j8f-8h4h-8pf6
Microsoft Edge allows remote attackers to bypass the Same Origin Policy for HTML elements in other browser windows, aka "Microsoft Edge Security Feature Bypass Vulnerability." This vulnerability is different from those described in CVE-2017-0066 and CVE-2017-0140.
GHSA-2j89-jv64-pjgc
A vulnerability was found in Campcodes House Rental Management System 1.0. It has been classified as critical. Affected is an unknown function of the file ajax.php. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-257982 is the identifier assigned to this vulnerability.
GHSA-2j88-c6j2-6283
NETGEAR R8000 devices before 1.0.4.2 are affected by a stack-based buffer overflow by an authenticated user.
GHSA-2j87-xqc2-j362
Multiple cross-site scripting (XSS) vulnerabilities in vbzoom 1.11 allow remote attackers to inject arbitrary web script or HTML via the UserID parameter to (1) comment.php or (2) contact.php. NOTE: the profile.php/UserName vector is already covered by CVE-2005-2441.
GHSA-2j87-rjcp-pm33
An issue existed in screen sharing. This issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1. A user with screen sharing access may be able to view another user's screen.
GHSA-2j87-p623-8cc2
Mattermost vulnerable to Observable Timing Discrepancy
GHSA-2j86-v657-3w4j
Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network.
GHSA-2j86-rvw9-5557
Buffer overflow in YoungZSoft CCProxy 6.5 might allow remote attackers to execute arbitrary code via a CONNECTION request with a long hostname.
GHSA-2j86-h6vf-9889
An issue was discovered on GL.iNet devices before 3.216. There is an arbitrary file write in which an empty file can be created anywhere on the filesystem. This is caused by a command injection vulnerability with a filter applied.
GHSA-2j85-3j4x-cwwf
WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.
GHSA-2j83-r83x-cccw
An issue was discovered in the Linux kernel before 6.3.10. fs/smb/server/smb2misc.c in ksmbd does not validate the relationship between the command payload size and the RFC1002 length specification, leading to an out-of-bounds read.
GHSA-2j83-qwg6-584r
A viewbatchtaskresultdetailfact expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
GHSA-2j83-8xf9-8m28
Cross-Site Request Forgery (CSRF) vulnerability in Anton Skorobogatov Rus-To-Lat plugin <= 0.3 versions.
GHSA-2j83-334m-g9w4
A buffer overflow vulnerability was found in the NVM Express (NVMe) driver in the Linux kernel. An unprivileged user could specify a small meta buffer and let the device perform larger Direct Memory Access (DMA) into the same buffer, overwriting unrelated kernel memory, causing random kernel crashes and memory corruption.
GHSA-2j82-v6wc-3928
Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions
GHSA-2j82-ggvf-vjmx
In the Linux kernel, the following vulnerability has been resolved: f2fs: fix dereference of stale list iterator after loop body The list iterator variable will be a bogus pointer if no break was hit. Dereferencing it (cur->page in this case) could load an out-of-bounds/undefined value making it unsafe to use that in the comparision to determine if the specific element was found. Since 'cur->page' *can* be out-ouf-bounds it cannot be guaranteed that by chance (or intention of an attacker) it matches the value of 'page' even though the correct element was not found. This is fixed by using a separate list iterator variable for the loop and only setting the original variable if a suitable element was found. Then determing if the element was found is simply checking if the variable is set.
GHSA-2j82-cf92-x9qh
In the Linux kernel, the following vulnerability has been resolved: be2net: Fix NULL pointer dereference in be_cmd_get_mac_from_list When the parameter pmac_id_valid argument of be_cmd_get_mac_from_list() is set to false, the driver may request the PMAC_ID from the firmware of the network card, and this function will store that PMAC_ID at the provided address pmac_id. This is the contract of this function. However, there is a location within the driver where both pmac_id_valid == false and pmac_id == NULL are being passed. This could result in dereferencing a NULL pointer. To resolve this issue, it is necessary to pass the address of a stub variable to the function.
GHSA-2j7x-g4cv-2735
Discourse before v2.4.0.beta2 lacks a confirmation screen when logging in via a user-api OTP.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2j8g-w8gx-h43r The vulnerability, if exploited, could allow an authenticated miscreant (with privileges to create or access publication targets of type Text File or HDFS) to upload and persist files that could potentially be executed. | CVSS3: 7.1 | 0% Низкий | 6 месяцев назад | |
GHSA-2j8f-gpq9-f2mv The publish-event event-manager feature in Cisco IOS 15.5(2)S and 15.5(3)S on Cloud Services Router 1000V devices allows local users to execute arbitrary commands with root privileges by leveraging administrative access to enter crafted environment variables, aka Bug ID CSCux14943. | 0% Низкий | больше 3 лет назад | ||
GHSA-2j8f-8h4h-8pf6 Microsoft Edge allows remote attackers to bypass the Same Origin Policy for HTML elements in other browser windows, aka "Microsoft Edge Security Feature Bypass Vulnerability." This vulnerability is different from those described in CVE-2017-0066 and CVE-2017-0140. | CVSS3: 4.2 | 22% Средний | больше 3 лет назад | |
GHSA-2j89-jv64-pjgc A vulnerability was found in Campcodes House Rental Management System 1.0. It has been classified as critical. Affected is an unknown function of the file ajax.php. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-257982 is the identifier assigned to this vulnerability. | CVSS3: 7.3 | 0% Низкий | почти 2 года назад | |
GHSA-2j88-c6j2-6283 NETGEAR R8000 devices before 1.0.4.2 are affected by a stack-based buffer overflow by an authenticated user. | 0% Низкий | больше 3 лет назад | ||
GHSA-2j87-xqc2-j362 Multiple cross-site scripting (XSS) vulnerabilities in vbzoom 1.11 allow remote attackers to inject arbitrary web script or HTML via the UserID parameter to (1) comment.php or (2) contact.php. NOTE: the profile.php/UserName vector is already covered by CVE-2005-2441. | 6% Низкий | почти 4 года назад | ||
GHSA-2j87-rjcp-pm33 An issue existed in screen sharing. This issue was addressed with improved state management. This issue is fixed in macOS Big Sur 11.0.1. A user with screen sharing access may be able to view another user's screen. | 0% Низкий | больше 3 лет назад | ||
GHSA-2j87-p623-8cc2 Mattermost vulnerable to Observable Timing Discrepancy | CVSS3: 5.3 | 0% Низкий | 10 месяцев назад | |
GHSA-2j86-v657-3w4j Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network. | CVSS3: 8.8 | 1% Низкий | 9 месяцев назад | |
GHSA-2j86-rvw9-5557 Buffer overflow in YoungZSoft CCProxy 6.5 might allow remote attackers to execute arbitrary code via a CONNECTION request with a long hostname. | 6% Низкий | больше 3 лет назад | ||
GHSA-2j86-h6vf-9889 An issue was discovered on GL.iNet devices before 3.216. There is an arbitrary file write in which an empty file can be created anywhere on the filesystem. This is caused by a command injection vulnerability with a filter applied. | CVSS3: 7.5 | 26% Средний | больше 2 лет назад | |
GHSA-2j85-3j4x-cwwf WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1. | 4% Низкий | больше 3 лет назад | ||
GHSA-2j83-r83x-cccw An issue was discovered in the Linux kernel before 6.3.10. fs/smb/server/smb2misc.c in ksmbd does not validate the relationship between the command payload size and the RFC1002 length specification, leading to an out-of-bounds read. | CVSS3: 9.1 | 0% Низкий | больше 2 лет назад | |
GHSA-2j83-qwg6-584r A viewbatchtaskresultdetailfact expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07). | 2% Низкий | больше 3 лет назад | ||
GHSA-2j83-8xf9-8m28 Cross-Site Request Forgery (CSRF) vulnerability in Anton Skorobogatov Rus-To-Lat plugin <= 0.3 versions. | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад | |
GHSA-2j83-334m-g9w4 A buffer overflow vulnerability was found in the NVM Express (NVMe) driver in the Linux kernel. An unprivileged user could specify a small meta buffer and let the device perform larger Direct Memory Access (DMA) into the same buffer, overwriting unrelated kernel memory, causing random kernel crashes and memory corruption. | CVSS3: 7 | 0% Низкий | около 2 лет назад | |
GHSA-2j82-v6wc-3928 Some Honor products are affected by incorrect privilege assignment vulnerability, successful exploitation could cause device service exceptions | CVSS3: 4 | 0% Низкий | около 2 лет назад | |
GHSA-2j82-ggvf-vjmx In the Linux kernel, the following vulnerability has been resolved: f2fs: fix dereference of stale list iterator after loop body The list iterator variable will be a bogus pointer if no break was hit. Dereferencing it (cur->page in this case) could load an out-of-bounds/undefined value making it unsafe to use that in the comparision to determine if the specific element was found. Since 'cur->page' *can* be out-ouf-bounds it cannot be guaranteed that by chance (or intention of an attacker) it matches the value of 'page' even though the correct element was not found. This is fixed by using a separate list iterator variable for the loop and only setting the original variable if a suitable element was found. Then determing if the element was found is simply checking if the variable is set. | CVSS3: 5.5 | 0% Низкий | 4 месяца назад | |
GHSA-2j82-cf92-x9qh In the Linux kernel, the following vulnerability has been resolved: be2net: Fix NULL pointer dereference in be_cmd_get_mac_from_list When the parameter pmac_id_valid argument of be_cmd_get_mac_from_list() is set to false, the driver may request the PMAC_ID from the firmware of the network card, and this function will store that PMAC_ID at the provided address pmac_id. This is the contract of this function. However, there is a location within the driver where both pmac_id_valid == false and pmac_id == NULL are being passed. This could result in dereferencing a NULL pointer. To resolve this issue, it is necessary to pass the address of a stub variable to the function. | 0% Низкий | 4 дня назад | ||
GHSA-2j7x-g4cv-2735 Discourse before v2.4.0.beta2 lacks a confirmation screen when logging in via a user-api OTP. | CVSS3: 5.3 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу