Количество 326 185
Количество 326 185
GHSA-2gw6-v2h7-g6vm
A vulnerability using PendingIntent in Bixby Vision prior to versions 3.7.60.8 in Android S(12), 3.7.50.6 in Andorid R(11) and below allows attackers to execute privileged action by hijacking and modifying the intent.
GHSA-2gw6-73wc-x88f
Apache Geode information disclosure vulnerability
GHSA-2gw5-9px7-vp56
In canvas rendering, a compromised content process could have caused a surface to change unexpectedly, leading to a memory leak of a privileged process. This memory leak could be used to effect a sandbox escape if the correct data was leaked. This vulnerability affects Firefox < 118.
GHSA-2gw3-mxrj-jwhh
Juniper Networks Contrail Service Orchestration releases prior to 3.3.0 use hardcoded credentials to access Keystone service. These credentials allow network based attackers unauthorized access to information stored in keystone.
GHSA-2gw2-qgjg-xh6p
Namada-apps allows Post-Genesis Validator Bypass
GHSA-2gw2-8q9w-cw8p
Ruby-ffi has a DLL loading issue
GHSA-2gvx-rx63-w97c
Apple iOS before 8.4.1 and OS X before 10.10.5 allow local users to bypass a code-signing protection mechanism via a crafted Mach-O file, a different vulnerability than CVE-2015-3802.
GHSA-2gvx-cpxc-42hj
Unrestricted file upload vulnerability in the fileUnzip->unzip method in Dotclear before 2.10.3 allows remote authenticated users with permissions to manage media items to execute arbitrary code by uploading a ZIP file containing a file with a crafted extension, as demonstrated by .php.txt or .php%20.
GHSA-2gvx-5frj-6px5
Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the mitInterface parameter in ip/goform/addressNat.
GHSA-2gvw-w6fj-7m3c
Argo CD's API server does not enforce project sourceNamespaces
GHSA-2gvw-r9m5-r3m7
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
GHSA-2gvw-95cm-ffm9
provider/server/ECServer.cpp in Zarafa Collaboration Platform (ZCP) before 7.1.13 and 7.2.x before 7.2.1 allows local users to write to arbitrary files via a symlink attack on /tmp/zarafa-upgrade-lock.
GHSA-2gvv-xcmg-4m9m
OX App Suite through 7.10.2 has Incorrect Access Control.
GHSA-2gvv-fwhv-83hw
An issue was discovered in WSO2 API Manager 2.1.0 and 2.6.0. A DOM-based XSS exists in the store part of the product.
GHSA-2gvv-8pww-2c2x
Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors.
GHSA-2gvv-5vxj-jrw7
A CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.
GHSA-2gvr-pmm6-8pmw
Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4051.
GHSA-2gvr-mfrj-8q6g
A vulnerability exists in the Aruba ClearPass C1000 S-1200 R4 HW-Based Appliance Analytics and Location Engine (ALE) web management interface 2.1.0.2 and earlier firmware that allows an already authenticated administrative user to arbitrarily modify files as an underlying privileged operating system user.
GHSA-2gvr-f7wx-9x96
Buffer overflow in Kingsoft Writer 2007 and 2010 before 2724 allows remote attackers to execute arbitrary code via a crafted RTF document.
GHSA-2gvr-cr49-92f3
Multiple format string vulnerabilities in FileZilla before 2.2.32 allow remote attackers to execute arbitrary code via format string specifiers in (1) FTP server responses or (2) data sent by an FTP server. NOTE: some of these details are obtained from third party information.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2gw6-v2h7-g6vm A vulnerability using PendingIntent in Bixby Vision prior to versions 3.7.60.8 in Android S(12), 3.7.50.6 in Andorid R(11) and below allows attackers to execute privileged action by hijacking and modifying the intent. | 0% Низкий | около 4 лет назад | ||
GHSA-2gw6-73wc-x88f Apache Geode information disclosure vulnerability | CVSS3: 7.5 | 0% Низкий | почти 4 года назад | |
GHSA-2gw5-9px7-vp56 In canvas rendering, a compromised content process could have caused a surface to change unexpectedly, leading to a memory leak of a privileged process. This memory leak could be used to effect a sandbox escape if the correct data was leaked. This vulnerability affects Firefox < 118. | CVSS3: 7.4 | 0% Низкий | больше 2 лет назад | |
GHSA-2gw3-mxrj-jwhh Juniper Networks Contrail Service Orchestration releases prior to 3.3.0 use hardcoded credentials to access Keystone service. These credentials allow network based attackers unauthorized access to information stored in keystone. | CVSS3: 9.8 | 0% Низкий | почти 4 года назад | |
GHSA-2gw2-qgjg-xh6p Namada-apps allows Post-Genesis Validator Bypass | около 1 года назад | |||
GHSA-2gw2-8q9w-cw8p Ruby-ffi has a DLL loading issue | CVSS3: 7.8 | 0% Низкий | больше 7 лет назад | |
GHSA-2gvx-rx63-w97c Apple iOS before 8.4.1 and OS X before 10.10.5 allow local users to bypass a code-signing protection mechanism via a crafted Mach-O file, a different vulnerability than CVE-2015-3802. | 0% Низкий | почти 4 года назад | ||
GHSA-2gvx-cpxc-42hj Unrestricted file upload vulnerability in the fileUnzip->unzip method in Dotclear before 2.10.3 allows remote authenticated users with permissions to manage media items to execute arbitrary code by uploading a ZIP file containing a file with a crafted extension, as demonstrated by .php.txt or .php%20. | CVSS3: 8.8 | 2% Низкий | почти 4 года назад | |
GHSA-2gvx-5frj-6px5 Tenda FH1206 V1.2.0.8(8155)_EN was discovered to contain a stack-based buffer overflow vulnerability via the mitInterface parameter in ip/goform/addressNat. | CVSS3: 9.8 | 0% Низкий | почти 2 года назад | |
GHSA-2gvw-w6fj-7m3c Argo CD's API server does not enforce project sourceNamespaces | CVSS3: 4.8 | 0% Низкий | почти 2 года назад | |
GHSA-2gvw-r9m5-r3m7 Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none. | почти 2 года назад | |||
GHSA-2gvw-95cm-ffm9 provider/server/ECServer.cpp in Zarafa Collaboration Platform (ZCP) before 7.1.13 and 7.2.x before 7.2.1 allows local users to write to arbitrary files via a symlink attack on /tmp/zarafa-upgrade-lock. | 0% Низкий | почти 4 года назад | ||
GHSA-2gvv-xcmg-4m9m OX App Suite through 7.10.2 has Incorrect Access Control. | 0% Низкий | почти 4 года назад | ||
GHSA-2gvv-fwhv-83hw An issue was discovered in WSO2 API Manager 2.1.0 and 2.6.0. A DOM-based XSS exists in the store part of the product. | CVSS3: 5.4 | 0% Низкий | почти 4 года назад | |
GHSA-2gvv-8pww-2c2x Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to bypass intended access restrictions and obtain sensitive information via unspecified vectors. | 2% Низкий | почти 4 года назад | ||
GHSA-2gvv-5vxj-jrw7 A CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition. | 1% Низкий | почти 4 года назад | ||
GHSA-2gvr-pmm6-8pmw Microsoft Internet Explorer 8 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulnerability than CVE-2014-4051. | 16% Средний | почти 4 года назад | ||
GHSA-2gvr-mfrj-8q6g A vulnerability exists in the Aruba ClearPass C1000 S-1200 R4 HW-Based Appliance Analytics and Location Engine (ALE) web management interface 2.1.0.2 and earlier firmware that allows an already authenticated administrative user to arbitrarily modify files as an underlying privileged operating system user. | 0% Низкий | почти 4 года назад | ||
GHSA-2gvr-f7wx-9x96 Buffer overflow in Kingsoft Writer 2007 and 2010 before 2724 allows remote attackers to execute arbitrary code via a crafted RTF document. | 11% Средний | почти 4 года назад | ||
GHSA-2gvr-cr49-92f3 Multiple format string vulnerabilities in FileZilla before 2.2.32 allow remote attackers to execute arbitrary code via format string specifiers in (1) FTP server responses or (2) data sent by an FTP server. NOTE: some of these details are obtained from third party information. | 2% Низкий | почти 4 года назад |
Уязвимостей на страницу