Количество 313 281
Количество 313 281
GHSA-23x2-xqxm-pxwj
libcroco through 0.6.13 has excessive recursion in cr_parser_parse_any_core in cr-parser.c, leading to stack consumption.
GHSA-23x2-rwgc-35fv
IBM CICS TX 11.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 229333.
GHSA-23x2-p68q-c69p
A Server-Side Request Forgery (SSRF) in the getFileBinary function of nbnbk cms 3 allows attackers to force the application to make arbitrary requests via injection of arbitrary URLs into the URL parameter.
GHSA-23x2-f488-jm35
Samsung Gallery on the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).
GHSA-23x2-c6m6-m9c7
Vulnerability in ppl in HP-UX 10.x and earlier allows local users to gain root privileges by forcing ppl to core dump.
GHSA-23wx-cgxq-vpwx
Prototype Pollution in dset
GHSA-23wx-6wm2-v53g
SQL Injection vulnerability in gnuboard5 <=v5.3.2.8 via the table_prefix parameter in install_db.php.
GHSA-23ww-hxf9-47fc
A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011 and classified as problematic. This issue affects some unknown processing of the file /boafrm/formPortFw of the component Virtual Server Page. The manipulation of the argument service_type leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
GHSA-23ww-2jh7-98f9
search.dll Sambar ISAPI Search utility in Sambar Server 4.4 Beta 3 allows remote attackers to read arbitrary directories by specifying the directory in the query parameter.
GHSA-23wv-w3v2-hcrj
Multiple Cross Site Scripting (XSS) vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the docname parameter in /admin/add-doctor.php and /admin/edit-doctor.php
GHSA-23wv-q9m5-hq8q
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: aspeed: Add NULL pointer check in ast_vhub_init_dev() The variable d->name, returned by devm_kasprintf(), could be NULL. A pointer check is added to prevent potential NULL pointer dereference. This is similar to the fix in commit 3027e7b15b02 ("ice: Fix some null pointer dereference issues in ice_ptp.c"). This issue is found by our static analysis tool
GHSA-23wv-pq77-4gp7
SiberianCMS - CWE-284 Improper Access Control Authorized user may disable a security feature over the network
GHSA-23wr-h929-wh3j
Out-of-bounds read in some Intel(R) Core(TM) processors with Radeon(TM) RX Vega M GL integrated graphics before version 21.10 may allow an authenticated user to potentially enable information disclosure via local access.
GHSA-23wq-qm4c-6497
A cross-site scripting (XSS) vulnerability in skycaiji v2.8 allows attackers to execute arbitrary web scripts or HTML via a crafted payload using eval(String.fromCharCode()).
GHSA-23wp-rxm7-f6f3
Biometric Shift Employee Management System has XSS via the Last_Name parameter in an index.php?user=ajax request.
GHSA-23wp-pqh4-8w8f
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25114. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of script within a Calculate action of a text field. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-9044.
GHSA-23wj-wvvj-vgcc
Multiple SQL injection vulnerabilities in admin/login_submit.php in Whole Hog Password Protect: Enhanced 1.x allow remote attackers to execute arbitrary SQL commands via (1) the uid parameter (aka Username field) or (2) the pwd parameter (aka Password field). NOTE: some of these details are obtained from third party information.
GHSA-23wj-r557-8c5p
tinyexr 0.9.5 has an assertion failure in DecodePixelData in tinyexr.h.
GHSA-23wj-h8fm-chf2
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9650, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 808, SD 810, SD 820, SD 820A, SD 835, SD 845, and SD 850, a buffer over-read can occur in a DRM API.
GHSA-23wj-fq4f-57vr
An issue was discovered in MiniCMS 1.10. There is a post.php?date= XSS vulnerability.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-23x2-xqxm-pxwj libcroco through 0.6.13 has excessive recursion in cr_parser_parse_any_core in cr-parser.c, leading to stack consumption. | CVSS3: 7.1 | 4% Низкий | больше 3 лет назад | |
GHSA-23x2-rwgc-35fv IBM CICS TX 11.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 229333. | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-23x2-p68q-c69p A Server-Side Request Forgery (SSRF) in the getFileBinary function of nbnbk cms 3 allows attackers to force the application to make arbitrary requests via injection of arbitrary URLs into the URL parameter. | CVSS3: 9.1 | 0% Низкий | больше 3 лет назад | |
GHSA-23x2-f488-jm35 Samsung Gallery on the Samsung Galaxy S6 allows local users to cause a denial of service (process crash). | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
GHSA-23x2-c6m6-m9c7 Vulnerability in ppl in HP-UX 10.x and earlier allows local users to gain root privileges by forcing ppl to core dump. | 0% Низкий | почти 4 года назад | ||
GHSA-23wx-cgxq-vpwx Prototype Pollution in dset | CVSS3: 6.5 | 1% Низкий | почти 4 года назад | |
GHSA-23wx-6wm2-v53g SQL Injection vulnerability in gnuboard5 <=v5.3.2.8 via the table_prefix parameter in install_db.php. | CVSS3: 9.8 | 0% Низкий | больше 3 лет назад | |
GHSA-23ww-hxf9-47fc A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011 and classified as problematic. This issue affects some unknown processing of the file /boafrm/formPortFw of the component Virtual Server Page. The manipulation of the argument service_type leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 2.4 | 0% Низкий | 8 месяцев назад | |
GHSA-23ww-2jh7-98f9 search.dll Sambar ISAPI Search utility in Sambar Server 4.4 Beta 3 allows remote attackers to read arbitrary directories by specifying the directory in the query parameter. | 4% Низкий | почти 4 года назад | ||
GHSA-23wv-w3v2-hcrj Multiple Cross Site Scripting (XSS) vulnerabilities exist in PHPGurukul Hospital Management System 4.0 via the docname parameter in /admin/add-doctor.php and /admin/edit-doctor.php | CVSS3: 5.9 | 0% Низкий | больше 1 года назад | |
GHSA-23wv-q9m5-hq8q In the Linux kernel, the following vulnerability has been resolved: usb: gadget: aspeed: Add NULL pointer check in ast_vhub_init_dev() The variable d->name, returned by devm_kasprintf(), could be NULL. A pointer check is added to prevent potential NULL pointer dereference. This is similar to the fix in commit 3027e7b15b02 ("ice: Fix some null pointer dereference issues in ice_ptp.c"). This issue is found by our static analysis tool | CVSS3: 5.5 | 0% Низкий | 9 месяцев назад | |
GHSA-23wv-pq77-4gp7 SiberianCMS - CWE-284 Improper Access Control Authorized user may disable a security feature over the network | CVSS3: 6.5 | 0% Низкий | больше 2 лет назад | |
GHSA-23wr-h929-wh3j Out-of-bounds read in some Intel(R) Core(TM) processors with Radeon(TM) RX Vega M GL integrated graphics before version 21.10 may allow an authenticated user to potentially enable information disclosure via local access. | CVSS3: 5.5 | 0% Низкий | почти 4 года назад | |
GHSA-23wq-qm4c-6497 A cross-site scripting (XSS) vulnerability in skycaiji v2.8 allows attackers to execute arbitrary web scripts or HTML via a crafted payload using eval(String.fromCharCode()). | CVSS3: 6.1 | 0% Низкий | больше 1 года назад | |
GHSA-23wp-rxm7-f6f3 Biometric Shift Employee Management System has XSS via the Last_Name parameter in an index.php?user=ajax request. | CVSS3: 5.4 | 0% Низкий | больше 3 лет назад | |
GHSA-23wp-pqh4-8w8f This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PhantomPDF 9.6.0.25114. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of script within a Calculate action of a text field. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-9044. | CVSS3: 8.8 | 1% Низкий | больше 3 лет назад | |
GHSA-23wj-wvvj-vgcc Multiple SQL injection vulnerabilities in admin/login_submit.php in Whole Hog Password Protect: Enhanced 1.x allow remote attackers to execute arbitrary SQL commands via (1) the uid parameter (aka Username field) or (2) the pwd parameter (aka Password field). NOTE: some of these details are obtained from third party information. | 0% Низкий | почти 4 года назад | ||
GHSA-23wj-r557-8c5p tinyexr 0.9.5 has an assertion failure in DecodePixelData in tinyexr.h. | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
GHSA-23wj-h8fm-chf2 In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9650, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 808, SD 810, SD 820, SD 820A, SD 835, SD 845, and SD 850, a buffer over-read can occur in a DRM API. | CVSS3: 9.8 | 0% Низкий | больше 3 лет назад | |
GHSA-23wj-fq4f-57vr An issue was discovered in MiniCMS 1.10. There is a post.php?date= XSS vulnerability. | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу