Количество 326 121
Количество 326 121
GHSA-2ghq-8m9c-mqjm
STRATO HiDrive Desktop Client 5.0.1.0 for Windows suffers from a SYSTEM privilege escalation vulnerability through the HiDriveMaintenanceService service. This service establishes a NetNamedPipe endpoint that allows applications to connect and call publicly exposed methods. An attacker can inject and execute code by hijacking the insecure communications with the service. This vulnerability also affects Telekom MagentaCLOUD through 5.7.0.0 and 1&1 Online Storage through 6.1.0.0.
GHSA-2ghp-ghc5-jw25
Rejected reason: Not used
GHSA-2ghp-fh92-8w9r
Memory safety bugs present in Firefox 145 and Thunderbird 145. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 146.
GHSA-2ghm-r75j-pjx2
Cross-site Scripting in DOMSanitizer
GHSA-2ghm-cqrg-hhpv
IBM Security Directory Server 6.4.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 166624.
GHSA-2ghj-g7p4-5ff7
Multiple integer overflows in Google Chrome before 11.0.696.57 allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to float rendering.
GHSA-2ghj-fm9g-w3jm
A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on macOS allows a local administrator to disable the agent. This issue could be leveraged by malware to perform malicious activity without detection.
GHSA-2ghj-7h29-wmc5
The gnucommerce plugin before 0.5.7-BETA for WordPress has XSS.
GHSA-2ghh-xmvf-53hw
Out-of-bounds read in decoding malformed bitstream for smp4vtd in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to read arbitrary memory. User interaction is required for triggering this vulnerability.
GHSA-2ghh-4f9c-3725
Adventia Chat 3.1 and Server Pro 3.0 allows remote attackers to inject arbitrary web script or HTML into the chat space, which leaves other users vulnerable to cross-site scripting (XSS) attacks.
GHSA-2ghg-fvx3-9q3q
Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Subtotal and Paidbill parameters under the Add New Put section.
GHSA-2ghg-c3m2-fxfm
The airPASS from NetVision Information has an OS Command Injection vulnerability, allowing remote attackers with regular privileges to inject and execute arbitrary OS commands.
GHSA-2ghg-9rgq-99xh
In XBLRamDump mode, there is a debug feature that can be used to dump memory contents, if an attacker has physical access to the device. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-64610940.
GHSA-2ghc-9393-f9wv
NVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with unnecessary privileges. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, information disclosure and data tampering.
GHSA-2ghc-6v89-pw9j
body-parser-xml vulnerable to Prototype Pollution
GHSA-2gh9-j675-j2ff
An attacker with no prior authentication could craft and send malicious script to SAP GUI for HTML within Fiori Launchpad, resulting in reflected cross-site scripting attack. This could lead to stealing session information and impersonating the affected user.
GHSA-2gh9-f6jf-23hq
Use of Externally-Controlled Format String vulnerability in Merge DICOM Toolkit C/C++ on Windows. When MC_Open_Association() function is used to open DICOM Association and gets DICOM Application Context Name with illegal characters, it might result in an unhandled exception.
GHSA-2gh8-q6wj-fwpq
Cross-site scripting (XSS) vulnerability in the Devel module before 5.x-0.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via a site variable, related to lack of escaping of the variable table.
GHSA-2gh8-prg6-5v63
The proc_oom_score function in fs/proc/base.c in the Linux kernel before 2.6.34-rc4 uses inappropriate data structures during selection of a candidate for the OOM killer, which might allow local users to cause a denial of service via unspecified patterns of task creation.
GHSA-2gh8-gx83-42h9
LemonLDAP::NG -2.0.3 has Incorrect Access Control.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2ghq-8m9c-mqjm STRATO HiDrive Desktop Client 5.0.1.0 for Windows suffers from a SYSTEM privilege escalation vulnerability through the HiDriveMaintenanceService service. This service establishes a NetNamedPipe endpoint that allows applications to connect and call publicly exposed methods. An attacker can inject and execute code by hijacking the insecure communications with the service. This vulnerability also affects Telekom MagentaCLOUD through 5.7.0.0 and 1&1 Online Storage through 6.1.0.0. | 1% Низкий | почти 4 года назад | ||
GHSA-2ghp-ghc5-jw25 Rejected reason: Not used | 9 месяцев назад | |||
GHSA-2ghp-fh92-8w9r Memory safety bugs present in Firefox 145 and Thunderbird 145. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 146. | CVSS3: 7.3 | 0% Низкий | 4 месяца назад | |
GHSA-2ghm-r75j-pjx2 Cross-site Scripting in DOMSanitizer | CVSS3: 6.1 | 0% Низкий | больше 2 лет назад | |
GHSA-2ghm-cqrg-hhpv IBM Security Directory Server 6.4.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 166624. | 0% Низкий | почти 4 года назад | ||
GHSA-2ghj-g7p4-5ff7 Multiple integer overflows in Google Chrome before 11.0.696.57 allow remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to float rendering. | 1% Низкий | почти 4 года назад | ||
GHSA-2ghj-fm9g-w3jm A problem with a protection mechanism in the Palo Alto Networks Cortex XDR agent on macOS allows a local administrator to disable the agent. This issue could be leveraged by malware to perform malicious activity without detection. | 0% Низкий | около 1 месяца назад | ||
GHSA-2ghj-7h29-wmc5 The gnucommerce plugin before 0.5.7-BETA for WordPress has XSS. | CVSS3: 6.1 | 0% Низкий | почти 4 года назад | |
GHSA-2ghh-xmvf-53hw Out-of-bounds read in decoding malformed bitstream for smp4vtd in libsthmbc.so prior to SMR Jan-2025 Release 1 allows local attackers to read arbitrary memory. User interaction is required for triggering this vulnerability. | CVSS3: 5.3 | 0% Низкий | около 1 года назад | |
GHSA-2ghh-4f9c-3725 Adventia Chat 3.1 and Server Pro 3.0 allows remote attackers to inject arbitrary web script or HTML into the chat space, which leaves other users vulnerable to cross-site scripting (XSS) attacks. | 1% Низкий | почти 4 года назад | ||
GHSA-2ghg-fvx3-9q3q Multiple cross-site scripting (XSS) vulnerabilities in Free and Open Source Inventory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Subtotal and Paidbill parameters under the Add New Put section. | CVSS3: 6.1 | 0% Низкий | больше 2 лет назад | |
GHSA-2ghg-c3m2-fxfm The airPASS from NetVision Information has an OS Command Injection vulnerability, allowing remote attackers with regular privileges to inject and execute arbitrary OS commands. | CVSS3: 8.8 | 2% Низкий | около 1 года назад | |
GHSA-2ghg-9rgq-99xh In XBLRamDump mode, there is a debug feature that can be used to dump memory contents, if an attacker has physical access to the device. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android kernel. Android ID: A-64610940. | CVSS3: 4.2 | 0% Низкий | почти 4 года назад | |
GHSA-2ghc-9393-f9wv NVIDIA Isaac Launchable contains a vulnerability where an attacker could cause an execution with unnecessary privileges. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, denial of service, information disclosure and data tampering. | CVSS3: 9.8 | 0% Низкий | 4 месяца назад | |
GHSA-2ghc-6v89-pw9j body-parser-xml vulnerable to Prototype Pollution | CVSS3: 7.6 | 0% Низкий | больше 4 лет назад | |
GHSA-2gh9-j675-j2ff An attacker with no prior authentication could craft and send malicious script to SAP GUI for HTML within Fiori Launchpad, resulting in reflected cross-site scripting attack. This could lead to stealing session information and impersonating the affected user. | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-2gh9-f6jf-23hq Use of Externally-Controlled Format String vulnerability in Merge DICOM Toolkit C/C++ on Windows. When MC_Open_Association() function is used to open DICOM Association and gets DICOM Application Context Name with illegal characters, it might result in an unhandled exception. | CVSS3: 5.7 | 0% Низкий | почти 2 года назад | |
GHSA-2gh8-q6wj-fwpq Cross-site scripting (XSS) vulnerability in the Devel module before 5.x-0.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via a site variable, related to lack of escaping of the variable table. | 0% Низкий | почти 4 года назад | ||
GHSA-2gh8-prg6-5v63 The proc_oom_score function in fs/proc/base.c in the Linux kernel before 2.6.34-rc4 uses inappropriate data structures during selection of a candidate for the OOM killer, which might allow local users to cause a denial of service via unspecified patterns of task creation. | 0% Низкий | почти 4 года назад | ||
GHSA-2gh8-gx83-42h9 LemonLDAP::NG -2.0.3 has Incorrect Access Control. | CVSS3: 9.8 | 1% Низкий | почти 4 года назад |
Уязвимостей на страницу