Количество 306 231
Количество 306 231
GHSA-23h9-m55m-c5jp
Jenkins Token Macro Plugin's recursive token expansion results in information disclosure and DoS
GHSA-23h9-h5hh-w97x
Buffer overflow in cgi.c in www-sql before 0.5.7 allows local users to execute arbitrary code via a web page that is processed by www-sql.
GHSA-23h8-xfh3-46wm
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Themefic Ultimate Addons for Contact Form 7 plugin <= 3.2.0 versions.
GHSA-23h8-ggh4-vmhv
Aria Operations for Networks contains a local file read vulnerability. A malicious actor with admin privileges may exploit this vulnerability leading to unauthorized access to sensitive information.
GHSA-23h8-7x35-v9v9
In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: fix potential memory leak by cleaning ops_filter in damon_destroy_scheme Currently, damon_destroy_scheme() only cleans up the filter list but leaves ops_filter untouched, which could lead to memory leaks when a scheme is destroyed. This patch ensures both filter and ops_filter are properly freed in damon_destroy_scheme(), preventing potential memory leaks.
GHSA-23h8-4q9g-xc4f
A maliciously crafted STP file in ASMKERN228A.dll or ASMDATAX228A.dll when parsed through Autodesk AutoCAD could lead to a memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
GHSA-23h5-8ph6-7rfc
Path traversal vulnerability in Jenkins Fortify Plugin
GHSA-23h3-wmf9-7x9c
The Move Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.5 via the render function in includes/widgets/accordion/widget.php, includes/widgets/remote-template/widget.php, and other widget.php files. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft template data.
GHSA-23h3-v846-4gxf
Stack-based buffer overflow in the C++ sample client in Schneider Electric OPC Factory Server (OFS) TLXCDSUOFS33 - 3.35, TLXCDSTOFS33 - 3.35, TLXCDLUOFS33 - 3.35, TLXCDLTOFS33 - 3.35, and TLXCDLFOFS33 - 3.35 allows local users to gain privileges via vectors involving a malformed configuration file.
GHSA-23h3-jvqq-m7vh
Modbus Tools Modbus Slave (versions 7.4.2 and prior) is vulnerable to a stack-based buffer overflow in the registration field. This may cause the program to crash when a long character string is used.
GHSA-23h3-7c7m-q7q6
Level Platforms, Inc. (LPI) Managed Workplace Service Center 4.x, 5.x and 6.x allows remote attackers to obtain sensitive information via a direct request to About/SC_About.htm, which provides version and patch information.
GHSA-23h2-xx79-4xwr
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.3, iOS 18.3 and iPadOS 18.3. An app may be able to view a contact's phone number in system logs.
GHSA-23h2-xqvf-mj5r
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Survey Maker team Survey Maker allows Stored XSS.This issue affects Survey Maker: from n/a through 4.0.5.
GHSA-23gx-cm6v-952g
HDF5 1.13.1-1 is affected by: segmentation fault, which causes a Denial of Service.
GHSA-23gw-vp8h-4v98
PHP remote file inclusion vulnerability in catalogshop.php in the CatalogShop component for Mambo (com_catalogshop) allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
GHSA-23gw-f65f-5rw8
The dnp3_al_process_object function in epan/dissectors/packet-dnp.c in the DNP3 dissector in Wireshark 1.12.x before 1.12.10 and 2.0.x before 2.0.2 allows remote attackers to cause a denial of service (infinite loop) via a crafted packet.
GHSA-23gw-97jj-g7f2
Remote attackers can perform a denial of service in Windows machines using malicious ARP packets, forcing a message box display for each packet or filling up log files.
GHSA-23gv-xgv3-fvq9
Microsoft Word Remote Code Execution Vulnerability
GHSA-23gr-x4f6-vrp6
Ypsomed mylife Cloud, mylife Mobile Application:Ypsomed mylife Cloud,All versions prior to 1.7.2,Ypsomed mylife App,All versions prior to 1.7.5,he Ypsomed mylife Cloud reflects the user password during the login process after redirecting the user from a HTTPS endpoint to a HTTP endpoint.
GHSA-23gq-p5v8-4xh3
A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926. A specially crafted series of HTTP requests can lead to remote code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.This vulnerability refers specifically to the overflow that occurs via the `profile` parameter at offset `0x4224b0` of the `httpd` binary shipped with v5.0.4 Build 20220216 of the EAP115.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-23h9-m55m-c5jp Jenkins Token Macro Plugin's recursive token expansion results in information disclosure and DoS | CVSS3: 6.5 | 1% Низкий | больше 3 лет назад | |
GHSA-23h9-h5hh-w97x Buffer overflow in cgi.c in www-sql before 0.5.7 allows local users to execute arbitrary code via a web page that is processed by www-sql. | 0% Низкий | больше 3 лет назад | ||
GHSA-23h8-xfh3-46wm Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Themefic Ultimate Addons for Contact Form 7 plugin <= 3.2.0 versions. | CVSS3: 7.1 | 0% Низкий | около 2 лет назад | |
GHSA-23h8-ggh4-vmhv Aria Operations for Networks contains a local file read vulnerability. A malicious actor with admin privileges may exploit this vulnerability leading to unauthorized access to sensitive information. | CVSS3: 4.9 | 1% Низкий | почти 2 года назад | |
GHSA-23h8-7x35-v9v9 In the Linux kernel, the following vulnerability has been resolved: mm/damon/core: fix potential memory leak by cleaning ops_filter in damon_destroy_scheme Currently, damon_destroy_scheme() only cleans up the filter list but leaves ops_filter untouched, which could lead to memory leaks when a scheme is destroyed. This patch ensures both filter and ops_filter are properly freed in damon_destroy_scheme(), preventing potential memory leaks. | 0% Низкий | 14 дней назад | ||
GHSA-23h8-4q9g-xc4f A maliciously crafted STP file in ASMKERN228A.dll or ASMDATAX228A.dll when parsed through Autodesk AutoCAD could lead to a memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process. | CVSS3: 7.5 | 0% Низкий | почти 2 года назад | |
GHSA-23h5-8ph6-7rfc Path traversal vulnerability in Jenkins Fortify Plugin | CVSS3: 4.3 | 0% Низкий | почти 4 года назад | |
GHSA-23h3-wmf9-7x9c The Move Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.5 via the render function in includes/widgets/accordion/widget.php, includes/widgets/remote-template/widget.php, and other widget.php files. This makes it possible for authenticated attackers, with Contributor-level access and above, to extract sensitive private, pending, and draft template data. | CVSS3: 4.3 | 0% Низкий | около 1 года назад | |
GHSA-23h3-v846-4gxf Stack-based buffer overflow in the C++ sample client in Schneider Electric OPC Factory Server (OFS) TLXCDSUOFS33 - 3.35, TLXCDSTOFS33 - 3.35, TLXCDLUOFS33 - 3.35, TLXCDLTOFS33 - 3.35, and TLXCDLFOFS33 - 3.35 allows local users to gain privileges via vectors involving a malformed configuration file. | 0% Низкий | больше 3 лет назад | ||
GHSA-23h3-jvqq-m7vh Modbus Tools Modbus Slave (versions 7.4.2 and prior) is vulnerable to a stack-based buffer overflow in the registration field. This may cause the program to crash when a long character string is used. | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
GHSA-23h3-7c7m-q7q6 Level Platforms, Inc. (LPI) Managed Workplace Service Center 4.x, 5.x and 6.x allows remote attackers to obtain sensitive information via a direct request to About/SC_About.htm, which provides version and patch information. | 3% Низкий | больше 3 лет назад | ||
GHSA-23h2-xx79-4xwr A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia 15.3, iOS 18.3 and iPadOS 18.3. An app may be able to view a contact's phone number in system logs. | CVSS3: 3.3 | 0% Низкий | 11 месяцев назад | |
GHSA-23h2-xqvf-mj5r Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Survey Maker team Survey Maker allows Stored XSS.This issue affects Survey Maker: from n/a through 4.0.5. | CVSS3: 5.9 | 0% Низкий | больше 1 года назад | |
GHSA-23gx-cm6v-952g HDF5 1.13.1-1 is affected by: segmentation fault, which causes a Denial of Service. | 0% Низкий | почти 4 года назад | ||
GHSA-23gw-vp8h-4v98 PHP remote file inclusion vulnerability in catalogshop.php in the CatalogShop component for Mambo (com_catalogshop) allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | 1% Низкий | больше 3 лет назад | ||
GHSA-23gw-f65f-5rw8 The dnp3_al_process_object function in epan/dissectors/packet-dnp.c in the DNP3 dissector in Wireshark 1.12.x before 1.12.10 and 2.0.x before 2.0.2 allows remote attackers to cause a denial of service (infinite loop) via a crafted packet. | CVSS3: 5.9 | 5% Низкий | больше 3 лет назад | |
GHSA-23gw-97jj-g7f2 Remote attackers can perform a denial of service in Windows machines using malicious ARP packets, forcing a message box display for each packet or filling up log files. | 7% Низкий | больше 3 лет назад | ||
GHSA-23gv-xgv3-fvq9 Microsoft Word Remote Code Execution Vulnerability | CVSS3: 7.8 | 1% Низкий | больше 3 лет назад | |
GHSA-23gr-x4f6-vrp6 Ypsomed mylife Cloud, mylife Mobile Application:Ypsomed mylife Cloud,All versions prior to 1.7.2,Ypsomed mylife App,All versions prior to 1.7.5,he Ypsomed mylife Cloud reflects the user password during the login process after redirecting the user from a HTTPS endpoint to a HTTP endpoint. | 0% Низкий | больше 3 лет назад | ||
GHSA-23gq-p5v8-4xh3 A stack-based buffer overflow vulnerability exists in the web interface Radio Scheduling functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926. A specially crafted series of HTTP requests can lead to remote code execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.This vulnerability refers specifically to the overflow that occurs via the `profile` parameter at offset `0x4224b0` of the `httpd` binary shipped with v5.0.4 Build 20220216 of the EAP115. | CVSS3: 7.2 | 1% Низкий | больше 1 года назад |
Уязвимостей на страницу