Количество 314 458
Количество 314 458
GHSA-2h2x-8hh2-mfq8
NATS Server and Streaming Server fails to enforce negative user permissions, may allow denied subjects
GHSA-2h2w-vccm-6fx5
Vulnerability that cards can call unauthorized APIs in the FRS process Impact: Successful exploitation of this vulnerability may affect availability.
GHSA-2h2w-cg7r-99fh
In Messaging, there is a possible way to attach files to a message without proper access checks due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-226134095
GHSA-2h2v-vcj6-9g2j
Multiple SQL injection vulnerabilities in ImageAlbum 2.0.0b2 allow remote attackers to execute arbitrary SQL commands via the id, which is not properly handled in (1) classes/IADomain.php, (2) classes/IACollection.php, and (3) classes/IAUser.php, as demonstrated via the id parameter in a collection.imageview action.
GHSA-2h2v-8cgx-wfvj
A information disclosure vulnerability in the HTC sound driver. Product: Android. Versions: Android kernel. Android ID: A-35384879.
GHSA-2h2r-w6vh-2w6r
DaviewIndy 8.98.7 and earlier version contain Use-After-Free vulnerability, triggered when the user opens a malformed specific file that is mishandled by Daview.exe. Attackers could exploit this and arbitrary code execution.
GHSA-2h2r-cg5q-pf39
A logic issue was addressed with improved state management. This issue is fixed in iOS 15.6 and iPadOS 15.6. A user may be able to view restricted content from the lock screen.
GHSA-2h2q-fhfv-pjvj
The Windows Graphics Component in Microsoft Office 2010 SP2; Windows Server 2008 R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via a crafted web site, aka "Windows Graphics Component Remote Code Execution Vulnerability." This vulnerability is different from that described in CVE-2017-0108.
GHSA-2h2q-cpp4-qphp
Cross-site scripting (XSS) vulnerability in init.inc.php in Coppermine Photo Gallery 1.3.x allows remote attackers to inject arbitrary web script or HTML via the X-Forwarded-For parameter.
GHSA-2h2q-74g8-r928
Cross-Site Request Forgery (CSRF) vulnerability in AntoineH Football Pool allows Cross Site Request Forgery. This issue affects Football Pool: from n/a through 2.12.2.
GHSA-2h2q-6mw2-pq7r
A flaw has been found in PHPGurukul Curfew e-Pass Management System 1.0. Impacted is an unknown function of the file view-pass-detail.php. This manipulation of the argument Fullname/Category causes cross site scripting. The attack may be initiated remotely. The exploit has been published and may be used.
GHSA-2h2q-4chj-wggp
Multiple format string vulnerabilities in OpenTTD before 0.4.0.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.
GHSA-2h2q-3qrx-m3j7
Improper neutralization of Livestatus command delimiters in autocomplete endpoint within the RestAPI of Checkmk versions <2.4.0p6, <2.3.0p35, <2.2.0p44, and 2.1.0 (EOL) allows an authenticated user to inject arbitrary Livestatus commands.
GHSA-2h2q-247m-jhjc
A vulnerability has been found in Whistle 2.9.98 and classified as problematic. This vulnerability affects unknown code of the file /cgi-bin/sessions/get-temp-file. The manipulation of the argument filename leads to path traversal. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
GHSA-2h2p-h37h-5phg
IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to read the source code of ASP and other files, aka the "Virtualized UNC Share" vulnerability.
GHSA-2h2m-v2mg-656c
Craft Commerce has Stored XSS in Product Type Name
GHSA-2h2m-7hfv-6h4g
Cross-site scripting (XSS) vulnerability in WebAccess in Novell GroupWise 8.x before 8.0 SP2 allows remote attackers to inject arbitrary web script or HTML via a crafted message, related to "replies."
GHSA-2h2m-3wv3-pqw4
mshtml.dll in Microsoft Windows XP, Server 2003, and Internet Explorer 6.0 SP1 allows attackers to cause a denial of service (access violation) by causing mshtml.dll to process button-focus events at the same time that a document is reloading, as seen in Microsoft Office InfoPath 2003 by repeatedly clicking the "Delete" button in a repeating section in a form. NOTE: the normal operation of InfoPath appears to involve a local user without any privilege boundaries, so this might not be a vulnerability in InfoPath. If no realistic scenarios exist for this problem in other products, then perhaps it should be excluded from CVE.
GHSA-2h2j-mg4w-wm75
cPanel before 74.0.8 allows self stored XSS on the Security Questions login page (SEC-446).
GHSA-2h2j-hwh4-6vfv
VP9 Video Extensions Remote Code Execution Vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2h2x-8hh2-mfq8 NATS Server and Streaming Server fails to enforce negative user permissions, may allow denied subjects | CVSS3: 6.5 | 0% Низкий | больше 1 года назад | |
GHSA-2h2w-vccm-6fx5 Vulnerability that cards can call unauthorized APIs in the FRS process Impact: Successful exploitation of this vulnerability may affect availability. | CVSS3: 4.4 | 0% Низкий | 8 месяцев назад | |
GHSA-2h2w-cg7r-99fh In Messaging, there is a possible way to attach files to a message without proper access checks due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-226134095 | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-2h2v-vcj6-9g2j Multiple SQL injection vulnerabilities in ImageAlbum 2.0.0b2 allow remote attackers to execute arbitrary SQL commands via the id, which is not properly handled in (1) classes/IADomain.php, (2) classes/IACollection.php, and (3) classes/IAUser.php, as demonstrated via the id parameter in a collection.imageview action. | 0% Низкий | почти 4 года назад | ||
GHSA-2h2v-8cgx-wfvj A information disclosure vulnerability in the HTC sound driver. Product: Android. Versions: Android kernel. Android ID: A-35384879. | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
GHSA-2h2r-w6vh-2w6r DaviewIndy 8.98.7 and earlier version contain Use-After-Free vulnerability, triggered when the user opens a malformed specific file that is mishandled by Daview.exe. Attackers could exploit this and arbitrary code execution. | 1% Низкий | больше 3 лет назад | ||
GHSA-2h2r-cg5q-pf39 A logic issue was addressed with improved state management. This issue is fixed in iOS 15.6 and iPadOS 15.6. A user may be able to view restricted content from the lock screen. | CVSS3: 5.5 | 0% Низкий | почти 3 года назад | |
GHSA-2h2q-fhfv-pjvj The Windows Graphics Component in Microsoft Office 2010 SP2; Windows Server 2008 R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via a crafted web site, aka "Windows Graphics Component Remote Code Execution Vulnerability." This vulnerability is different from that described in CVE-2017-0108. | CVSS3: 7.5 | 24% Средний | больше 3 лет назад | |
GHSA-2h2q-cpp4-qphp Cross-site scripting (XSS) vulnerability in init.inc.php in Coppermine Photo Gallery 1.3.x allows remote attackers to inject arbitrary web script or HTML via the X-Forwarded-For parameter. | 0% Низкий | почти 4 года назад | ||
GHSA-2h2q-74g8-r928 Cross-Site Request Forgery (CSRF) vulnerability in AntoineH Football Pool allows Cross Site Request Forgery. This issue affects Football Pool: from n/a through 2.12.2. | CVSS3: 4.3 | 0% Низкий | 11 месяцев назад | |
GHSA-2h2q-6mw2-pq7r A flaw has been found in PHPGurukul Curfew e-Pass Management System 1.0. Impacted is an unknown function of the file view-pass-detail.php. This manipulation of the argument Fullname/Category causes cross site scripting. The attack may be initiated remotely. The exploit has been published and may be used. | CVSS3: 2.4 | 0% Низкий | 3 месяца назад | |
GHSA-2h2q-4chj-wggp Multiple format string vulnerabilities in OpenTTD before 0.4.0.1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors. | 2% Низкий | почти 4 года назад | ||
GHSA-2h2q-3qrx-m3j7 Improper neutralization of Livestatus command delimiters in autocomplete endpoint within the RestAPI of Checkmk versions <2.4.0p6, <2.3.0p35, <2.2.0p44, and 2.1.0 (EOL) allows an authenticated user to inject arbitrary Livestatus commands. | CVSS3: 8.8 | 0% Низкий | 7 месяцев назад | |
GHSA-2h2q-247m-jhjc A vulnerability has been found in Whistle 2.9.98 and classified as problematic. This vulnerability affects unknown code of the file /cgi-bin/sessions/get-temp-file. The manipulation of the argument filename leads to path traversal. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 4.3 | 0% Низкий | 8 месяцев назад | |
GHSA-2h2p-h37h-5phg IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, which allows remote attackers to read the source code of ASP and other files, aka the "Virtualized UNC Share" vulnerability. | 84% Высокий | почти 4 года назад | ||
GHSA-2h2m-v2mg-656c Craft Commerce has Stored XSS in Product Type Name | 0% Низкий | 6 дней назад | ||
GHSA-2h2m-7hfv-6h4g Cross-site scripting (XSS) vulnerability in WebAccess in Novell GroupWise 8.x before 8.0 SP2 allows remote attackers to inject arbitrary web script or HTML via a crafted message, related to "replies." | 1% Низкий | больше 3 лет назад | ||
GHSA-2h2m-3wv3-pqw4 mshtml.dll in Microsoft Windows XP, Server 2003, and Internet Explorer 6.0 SP1 allows attackers to cause a denial of service (access violation) by causing mshtml.dll to process button-focus events at the same time that a document is reloading, as seen in Microsoft Office InfoPath 2003 by repeatedly clicking the "Delete" button in a repeating section in a form. NOTE: the normal operation of InfoPath appears to involve a local user without any privilege boundaries, so this might not be a vulnerability in InfoPath. If no realistic scenarios exist for this problem in other products, then perhaps it should be excluded from CVE. | 16% Средний | почти 4 года назад | ||
GHSA-2h2j-mg4w-wm75 cPanel before 74.0.8 allows self stored XSS on the Security Questions login page (SEC-446). | CVSS3: 5.4 | 0% Низкий | больше 3 лет назад | |
GHSA-2h2j-hwh4-6vfv VP9 Video Extensions Remote Code Execution Vulnerability | CVSS3: 7.8 | 9% Низкий | больше 3 лет назад |
Уязвимостей на страницу