Количество 326 109
Количество 326 109
GHSA-2g83-93g3-qr66
Race condition in the setreuid system-call implementation in the kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 allows attackers to cause a denial of service via a crafted app.
GHSA-2g83-7hf9-c7mr
Cross Site Scripting Exposure in McAfee True Key (TK) 4.0.0.0 and earlier allows local users to expose confidential data via a crafted web site.
GHSA-2g83-63pc-qvx7
An exploitable integer overflow exists in the way that the Blender open-source 3d creation suite v2.78c draws a Particle object. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to open the file or use the file as a library in order to trigger this vulnerability.
GHSA-2g7w-59mh-c4mv
Sun Chili!Soft 3.5.2 on Linux and 3.6 on AIX creates a default admin username and password in the default installation, which can allow a remote attacker to gain additional privileges.
GHSA-2g7v-hgr5-5mvv
Huawei eSpace U2980 unified gateway with software before V100R001C10 and U2990 with software before V200R001C10 allow remote authenticated users to cause a denial of service via crafted signaling packets from a registered device.
GHSA-2g7v-hghf-grg4
mcp-maigret vulnerable to command injection
GHSA-2g7v-9r87-x6xh
In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Wrap dcn301_calculate_wm_and_dlg for FPU. Mirrors the logic for dcn30. Cue lots of WARNs and some kernel panics without this fix.
GHSA-2g7v-93hf-j2h4
Cross-site scripting (XSS) vulnerability in sendcard.php in Sendcard 3.4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the form parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
GHSA-2g7v-6q7q-7mp6
A security flaw has been discovered in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. This vulnerability affects unknown code of the file /admin/editposts.php. Performing manipulation of the argument image results in unrestricted upload. The attack may be initiated remotely. The exploit has been released to the public and may be exploited.
GHSA-2g7r-9xq5-c6hv
Cross-Site Request Forgery (CSRF) in usememos/memos
GHSA-2g7q-wj3m-7h2r
packages/core/contact.php in Archon 3.21 rev-1 has XSS in the referer parameter in an index.php?p=core/contact request, aka Open Bug Bounty ID OBB-278503.
GHSA-2g7p-7mvp-pw7m
Improper Control of Generation of Code ('Code Injection') vulnerability in Inpersttion Slivery Extender allows Code Injection.This issue affects Slivery Extender: from n/a through 1.0.2.
GHSA-2g7m-ph9x-7q7m
Calibre Web and Autocaliweb have a ReDoS vulnerability
GHSA-2g7j-m3mp-pr8p
An exploitable command injection vulnerability exists in the cloud connectivity feature of WAGO PFC200. An attacker can inject operating system commands into any of the parameter values contained in the firmware update command. This affects WAGO PFC200 Firmware version 03.02.02(14), version 03.01.07(13), and version 03.00.39(12)
GHSA-2g7j-7338-6vq9
Netwide Assembler (NASM) 2.14rc0 has an endless while loop in the assemble_file function of asm/nasm.c because of a globallineno integer overflow.
GHSA-2g7h-x5vj-qp64
IBM Financial Transaction Manager 3.0.1 and 3.0.2 does not properly update the SESSIONID with each request, which could allow a user to obtain the ID in further attacks against the system. IBM X-Force ID: 122293.
GHSA-2g7h-7rqr-9p4r
Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output
GHSA-2g7h-4jrf-ppfh
The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the section title tag attribute in all versions up to, and including, 7.7.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
GHSA-2g7f-fm5g-52cj
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
GHSA-2g7c-w4c3-p872
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.20. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2g83-93g3-qr66 Race condition in the setreuid system-call implementation in the kernel in Apple iOS before 8.3, Apple OS X before 10.10.3, and Apple TV before 7.2 allows attackers to cause a denial of service via a crafted app. | 0% Низкий | почти 4 года назад | ||
GHSA-2g83-7hf9-c7mr Cross Site Scripting Exposure in McAfee True Key (TK) 4.0.0.0 and earlier allows local users to expose confidential data via a crafted web site. | CVSS3: 6.1 | 0% Низкий | почти 4 года назад | |
GHSA-2g83-63pc-qvx7 An exploitable integer overflow exists in the way that the Blender open-source 3d creation suite v2.78c draws a Particle object. A specially crafted .blend file can cause an integer overflow resulting in a buffer overflow which can allow for code execution under the context of the application. An attacker can convince a user to open the file or use the file as a library in order to trigger this vulnerability. | CVSS3: 7.8 | 1% Низкий | почти 4 года назад | |
GHSA-2g7w-59mh-c4mv Sun Chili!Soft 3.5.2 on Linux and 3.6 on AIX creates a default admin username and password in the default installation, which can allow a remote attacker to gain additional privileges. | 1% Низкий | почти 4 года назад | ||
GHSA-2g7v-hgr5-5mvv Huawei eSpace U2980 unified gateway with software before V100R001C10 and U2990 with software before V200R001C10 allow remote authenticated users to cause a denial of service via crafted signaling packets from a registered device. | 0% Низкий | почти 4 года назад | ||
GHSA-2g7v-hghf-grg4 mcp-maigret vulnerable to command injection | CVSS3: 6.3 | 0% Низкий | 2 месяца назад | |
GHSA-2g7v-9r87-x6xh In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Wrap dcn301_calculate_wm_and_dlg for FPU. Mirrors the logic for dcn30. Cue lots of WARNs and some kernel panics without this fix. | CVSS3: 5.5 | 0% Низкий | почти 2 года назад | |
GHSA-2g7v-93hf-j2h4 Cross-site scripting (XSS) vulnerability in sendcard.php in Sendcard 3.4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the form parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 0% Низкий | почти 4 года назад | ||
GHSA-2g7v-6q7q-7mp6 A security flaw has been discovered in code-projects/anirbandutta9 Content Management System and News-Buzz 1.0. This vulnerability affects unknown code of the file /admin/editposts.php. Performing manipulation of the argument image results in unrestricted upload. The attack may be initiated remotely. The exploit has been released to the public and may be exploited. | CVSS3: 4.7 | 0% Низкий | 3 месяца назад | |
GHSA-2g7r-9xq5-c6hv Cross-Site Request Forgery (CSRF) in usememos/memos | CVSS3: 8.8 | 0% Низкий | больше 2 лет назад | |
GHSA-2g7q-wj3m-7h2r packages/core/contact.php in Archon 3.21 rev-1 has XSS in the referer parameter in an index.php?p=core/contact request, aka Open Bug Bounty ID OBB-278503. | CVSS3: 6.1 | 0% Низкий | почти 4 года назад | |
GHSA-2g7p-7mvp-pw7m Improper Control of Generation of Code ('Code Injection') vulnerability in Inpersttion Slivery Extender allows Code Injection.This issue affects Slivery Extender: from n/a through 1.0.2. | CVSS3: 8.5 | 0% Низкий | около 2 лет назад | |
GHSA-2g7m-ph9x-7q7m Calibre Web and Autocaliweb have a ReDoS vulnerability | 0% Низкий | 9 месяцев назад | ||
GHSA-2g7j-m3mp-pr8p An exploitable command injection vulnerability exists in the cloud connectivity feature of WAGO PFC200. An attacker can inject operating system commands into any of the parameter values contained in the firmware update command. This affects WAGO PFC200 Firmware version 03.02.02(14), version 03.01.07(13), and version 03.00.39(12) | 2% Низкий | почти 4 года назад | ||
GHSA-2g7j-7338-6vq9 Netwide Assembler (NASM) 2.14rc0 has an endless while loop in the assemble_file function of asm/nasm.c because of a globallineno integer overflow. | CVSS3: 5.5 | 0% Низкий | почти 4 года назад | |
GHSA-2g7h-x5vj-qp64 IBM Financial Transaction Manager 3.0.1 and 3.0.2 does not properly update the SESSIONID with each request, which could allow a user to obtain the ID in further attacks against the system. IBM X-Force ID: 122293. | CVSS3: 4.3 | 0% Низкий | почти 4 года назад | |
GHSA-2g7h-7rqr-9p4r Vikunja has iCalendar Property Injection via CRLF in CalDAV Task Output | CVSS3: 4.1 | 1 день назад | ||
GHSA-2g7h-4jrf-ppfh The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the section title tag attribute in all versions up to, and including, 7.7.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | CVSS3: 6.4 | 0% Низкий | почти 2 года назад | |
GHSA-2g7f-fm5g-52cj Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | CVSS3: 8.8 | 5% Низкий | больше 1 года назад | |
GHSA-2g7c-w4c3-p872 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is Prior to 6.1.20. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H). | CVSS3: 7.5 | 0% Низкий | почти 4 года назад |
Уязвимостей на страницу