Количество 314 212
Количество 314 212
GHSA-2fh4-45ph-7q27
The ACEManager component of ALEOS 4.16 and earlier does not perform input sanitization during authentication, which could potentially result in a Denial of Service (DoS) condition for ACEManager without impairing other router functions. ACEManager recovers from the DoS condition by restarting within ten seconds of becoming unavailable.
GHSA-2fh3-xg72-f7vx
FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUploadedHotspotLogoFile and then visiting Assets/temp/hotspot/img/logohotspot.asp.
GHSA-2fh3-rm73-hjxf
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NicheAddons Primary Addon for Elementor allows Stored XSS.This issue affects Primary Addon for Elementor: from n/a through 1.6.0.
GHSA-2fh2-r4pq-hx4f
An issue was discovered in Samsung Mobile Processor Exynos 2200, Exynos 1480, Exynos 2400. It lacks proper buffer length checking, which can result in an Out-of-Bounds Write.
GHSA-2fgx-cg4f-9pgq
The buddyboss-media plugin through 3.2.3 for WordPress has stored XSS.
GHSA-2fgw-qh65-pxv5
The issue was addressed with improved input sanitization. This issue is fixed in macOS Sequoia 15.4, macOS Ventura 13.7.6, macOS Sonoma 14.7.6. An app may be able to gain elevated privileges.
GHSA-2fgw-hpx5-xjx3
A cross-site scripting (XSS) vulnerability in PHPFox v4.8.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the History parameter.
GHSA-2fgw-ch33-hpgq
Cross-Site Request Forgery (CSRF) vulnerability in LiveChat LiveChat – WP live chat plugin for WordPress.This issue affects LiveChat – WP live chat plugin for WordPress: from n/a through 4.5.15.
GHSA-2fgw-2v2m-w7mc
useradd in shadow-utils before 4.0.3, and possibly other versions before 4.0.8, does not provide a required argument to the open function when creating a new user mailbox, which causes the mailbox to be created with unpredictable permissions and possibly allows attackers to read or modify the mailbox.
GHSA-2fgv-c9q9-5wwh
Integer overflow in Apple CoreGraphics, as used in Safari before 4.0.3, Mozilla Firefox before 3.0.12, and Mac OS X 10.4.11 and 10.5.8, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long text run that triggers a heap-based buffer overflow during font glyph rendering, a related issue to CVE-2009-1194.
GHSA-2fgr-v6mx-rmch
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quadlayers Perfect Brands for WooCommerce allows SQL Injection. This issue affects Perfect Brands for WooCommerce: from n/a through 3.6.0.
GHSA-2fgq-wq42-4xxq
Cross-site scripting (XSS) vulnerability in Search.php in DiMeMa CONTENTdm (CDM) allows remote attackers to inject arbitrary web script or HTML via a search, probably related to the CISOBOX1 parameter to results.php in CDM 4.2.
GHSA-2fgq-8829-2c9j
Lenosp 1.0.0-1.2.0 is vulnerable to SQL Injection via the log query module.
GHSA-2fgp-4w27-wc8x
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in designingmedia Hostiko allows PHP Local File Inclusion.This issue affects Hostiko: from n/a before 30.1.
GHSA-2fgj-xr9x-3qq6
Sympa before 5.4 allows remote attackers to cause a denial of service (daemon crash) via an e-mail message with a malformed value of the Content-Type header and unspecified other headers. NOTE: some of these details are obtained from third party information.
GHSA-2fgj-q22q-g9pg
Nordic Semiconductor, Microchip Technology NRF5340-DK DT100112 was discovered to contain an issue which allows attackers to cause a Denial of Service (DoS) via a crafted ConReq packet.
GHSA-2fgh-m45q-cgrh
Firefox before 1.0 does not properly distinguish between user-generated and synthetic click events, which allows remote attackers to use Javascript to bypass the file download prompt when the user uses the Alt-click feature.
GHSA-2fgh-jwqp-hr3r
zabbix_agentd in ZABBIX 1.4.4 allows remote attackers to cause a denial of service (CPU and connection consumption) via multiple vfs.file.cksum commands with a special device node such as /dev/urandom or /dev/zero.
GHSA-2fgh-jjh6-cvr4
Path Traversal and Insecure Direct Object Reference (IDOR) vulnerabilities in the eSignaViewer component in eSigna product versions 1.0 to 1.5 on all platforms allow an unauthenticated attacker to access arbitrary files in the document system via manipulation of file paths and object identifiers.
GHSA-2fgh-78wf-f9v9
Authentication Bypass Using an Alternate Path or Channel vulnerability in WPExperts Post SMTP allows Authentication Bypass.This issue affects Post SMTP: from n/a through 3.2.0.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2fh4-45ph-7q27 The ACEManager component of ALEOS 4.16 and earlier does not perform input sanitization during authentication, which could potentially result in a Denial of Service (DoS) condition for ACEManager without impairing other router functions. ACEManager recovers from the DoS condition by restarting within ten seconds of becoming unavailable. | CVSS3: 7.5 | 0% Низкий | около 2 лет назад | |
GHSA-2fh3-xg72-f7vx FortiLogger 4.4.2.2 is affected by Arbitrary File Upload by sending a "Content-Type: image/png" header to Config/SaveUploadedHotspotLogoFile and then visiting Assets/temp/hotspot/img/logohotspot.asp. | 93% Критический | больше 3 лет назад | ||
GHSA-2fh3-rm73-hjxf Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NicheAddons Primary Addon for Elementor allows Stored XSS.This issue affects Primary Addon for Elementor: from n/a through 1.6.0. | CVSS3: 6.5 | 0% Низкий | около 1 года назад | |
GHSA-2fh2-r4pq-hx4f An issue was discovered in Samsung Mobile Processor Exynos 2200, Exynos 1480, Exynos 2400. It lacks proper buffer length checking, which can result in an Out-of-Bounds Write. | CVSS3: 8.4 | 0% Низкий | больше 1 года назад | |
GHSA-2fgx-cg4f-9pgq The buddyboss-media plugin through 3.2.3 for WordPress has stored XSS. | CVSS3: 5.4 | 0% Низкий | больше 3 лет назад | |
GHSA-2fgw-qh65-pxv5 The issue was addressed with improved input sanitization. This issue is fixed in macOS Sequoia 15.4, macOS Ventura 13.7.6, macOS Sonoma 14.7.6. An app may be able to gain elevated privileges. | CVSS3: 7.8 | 0% Низкий | 9 месяцев назад | |
GHSA-2fgw-hpx5-xjx3 A cross-site scripting (XSS) vulnerability in PHPFox v4.8.9 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the History parameter. | CVSS3: 7.1 | 0% Низкий | почти 2 года назад | |
GHSA-2fgw-ch33-hpgq Cross-Site Request Forgery (CSRF) vulnerability in LiveChat LiveChat – WP live chat plugin for WordPress.This issue affects LiveChat – WP live chat plugin for WordPress: from n/a through 4.5.15. | CVSS3: 5.4 | 0% Низкий | около 2 лет назад | |
GHSA-2fgw-2v2m-w7mc useradd in shadow-utils before 4.0.3, and possibly other versions before 4.0.8, does not provide a required argument to the open function when creating a new user mailbox, which causes the mailbox to be created with unpredictable permissions and possibly allows attackers to read or modify the mailbox. | 0% Низкий | почти 4 года назад | ||
GHSA-2fgv-c9q9-5wwh Integer overflow in Apple CoreGraphics, as used in Safari before 4.0.3, Mozilla Firefox before 3.0.12, and Mac OS X 10.4.11 and 10.5.8, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long text run that triggers a heap-based buffer overflow during font glyph rendering, a related issue to CVE-2009-1194. | 24% Средний | почти 4 года назад | ||
GHSA-2fgr-v6mx-rmch Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quadlayers Perfect Brands for WooCommerce allows SQL Injection. This issue affects Perfect Brands for WooCommerce: from n/a through 3.6.0. | CVSS3: 8.5 | 0% Низкий | 5 месяцев назад | |
GHSA-2fgq-wq42-4xxq Cross-site scripting (XSS) vulnerability in Search.php in DiMeMa CONTENTdm (CDM) allows remote attackers to inject arbitrary web script or HTML via a search, probably related to the CISOBOX1 parameter to results.php in CDM 4.2. | 1% Низкий | почти 4 года назад | ||
GHSA-2fgq-8829-2c9j Lenosp 1.0.0-1.2.0 is vulnerable to SQL Injection via the log query module. | CVSS3: 6.5 | 0% Низкий | больше 2 лет назад | |
GHSA-2fgp-4w27-wc8x Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in designingmedia Hostiko allows PHP Local File Inclusion.This issue affects Hostiko: from n/a before 30.1. | CVSS3: 7.5 | 0% Низкий | 11 месяцев назад | |
GHSA-2fgj-xr9x-3qq6 Sympa before 5.4 allows remote attackers to cause a denial of service (daemon crash) via an e-mail message with a malformed value of the Content-Type header and unspecified other headers. NOTE: some of these details are obtained from third party information. | 2% Низкий | почти 4 года назад | ||
GHSA-2fgj-q22q-g9pg Nordic Semiconductor, Microchip Technology NRF5340-DK DT100112 was discovered to contain an issue which allows attackers to cause a Denial of Service (DoS) via a crafted ConReq packet. | CVSS3: 6.5 | 0% Низкий | почти 3 года назад | |
GHSA-2fgh-m45q-cgrh Firefox before 1.0 does not properly distinguish between user-generated and synthetic click events, which allows remote attackers to use Javascript to bypass the file download prompt when the user uses the Alt-click feature. | 0% Низкий | почти 4 года назад | ||
GHSA-2fgh-jwqp-hr3r zabbix_agentd in ZABBIX 1.4.4 allows remote attackers to cause a denial of service (CPU and connection consumption) via multiple vfs.file.cksum commands with a special device node such as /dev/urandom or /dev/zero. | 6% Низкий | почти 4 года назад | ||
GHSA-2fgh-jjh6-cvr4 Path Traversal and Insecure Direct Object Reference (IDOR) vulnerabilities in the eSignaViewer component in eSigna product versions 1.0 to 1.5 on all platforms allow an unauthenticated attacker to access arbitrary files in the document system via manipulation of file paths and object identifiers. | CVSS3: 7.5 | 0% Низкий | около 1 года назад | |
GHSA-2fgh-78wf-f9v9 Authentication Bypass Using an Alternate Path or Channel vulnerability in WPExperts Post SMTP allows Authentication Bypass.This issue affects Post SMTP: from n/a through 3.2.0. | CVSS3: 8.8 | 0% Низкий | 6 месяцев назад |
Уязвимостей на страницу