Количество 324 648
Количество 324 648
GHSA-28f7-g5r5-mpx5
In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges.
GHSA-28f6-9xpw-pwcr
Cross-site scripting (XSS) vulnerability in core/summary_api.php in MantisBT before 1.2.3 allows remote attackers to inject arbitrary web script or HTML via the Summary field, a different vector than CVE-2010-3303.
GHSA-28f6-647f-xq87
Buffer overflow in SonicWall SMA100 allows an authenticated user to execute arbitrary code in DEARegister CGI script. This vulnerability impacted SMA100 version 9.0.0.3 and earlier.
GHSA-28f5-mg2c-r34c
Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass intended restrictions on JavaScript API execution via unspecified vectors, a different vulnerability than CVE-2015-3060, CVE-2015-3061, CVE-2015-3062, CVE-2015-3063, CVE-2015-3064, CVE-2015-3065, CVE-2015-3066, CVE-2015-3067, CVE-2015-3068, CVE-2015-3069, CVE-2015-3071, CVE-2015-3072, and CVE-2015-3074.
GHSA-28f5-7mw6-mfmc
In AccountManager, there is a possible bypass of a permissions check due to a confused deputy. This could lead to local information disclosure, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-123700107
GHSA-28f5-7fwx-xrf3
When SWFTools 0.9.2 processes a crafted file in png2swf, it can lead to a Segmentation Violation in the png_load() function in lib/png.c.
GHSA-28f5-3rf2-gpm8
Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12.
GHSA-28f4-mjfq-qrvf
Malicious Package in buffes-xor
GHSA-28f4-f5wq-36wr
The WooCommerce POS plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 1.4.11. This is due to the plugin not properly verifying the authentication and authorization of the current user This makes it possible for authenticated attackers, with customer-level access and above, to view potentially sensitive information about other users by leveraging their order id
GHSA-28f4-9qfp-6f7v
An issue was discovered in Xpdf 4.01.01. There is an FPE in the function ImageStream::ImageStream at Stream.cc for nBits.
GHSA-28f3-rf96-2vvg
Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'txtPass' parameter of the login.php resource does not validate the characters received and they are sent unfiltered to the database.
GHSA-28f3-c95g-f4g3
In Wireshark 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11, the IxVeriWave file parser could crash. This was addressed in wiretap/vwr.c by correcting the signature timestamp bounds checks.
GHSA-28f2-gw74-5cpj
The setpermissions function in the auto-updater in Arq before 5.9.7 for Mac allows local users to gain root privileges via a symlink attack on the updater binary itself.
GHSA-28cx-j4v5-m5fv
Pluck CMS 4.7.18 does not restrict failed login attempts, allowing attackers to execute a brute force attack.
GHSA-28cx-hxv4-g5q7
Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/admin/vehicles/manage_vehicle.php?id=.
GHSA-28cx-5f85-hrh4
FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/page/edit/10.
GHSA-28cw-rx3r-6f3c
Palo Alto Networks Traps ESM Console before 3.4.4 allows attackers to cause a denial of service by leveraging improper validation of requests to revoke a Traps agent license.
GHSA-28cw-qr46-rx46
The php_zip_make_relative_path function in php_zip.c in PHP 5.2.x before 5.2.9 allows context-dependent attackers to cause a denial of service (crash) via a ZIP file that contains filenames with relative paths, which is not properly handled during extraction.
GHSA-28cw-qjjv-g5g8
IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to a Log Injection attack by constructing URLs from user-controlled data. This could enable attackers to make arbitrary requests to the internal network or to the local file system. IBM X-Force ID: 240266.
GHSA-28cw-3j6f-3fv3
A vulnerability exists that could allow the execution of operating system commands on systems running MiPlatform 2019.05.16 and earlier. An attacker could execute arbitrary remote command by sending parameters to WinExec function in ExtCommandApi.dll module of MiPlatform.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-28f7-g5r5-mpx5 In audio service, there is a possible missing permission check. This could lead to local escalation of privilege with no additional execution privileges. | CVSS3: 7.8 | 0% Низкий | почти 3 года назад | |
GHSA-28f6-9xpw-pwcr Cross-site scripting (XSS) vulnerability in core/summary_api.php in MantisBT before 1.2.3 allows remote attackers to inject arbitrary web script or HTML via the Summary field, a different vector than CVE-2010-3303. | 1% Низкий | почти 4 года назад | ||
GHSA-28f6-647f-xq87 Buffer overflow in SonicWall SMA100 allows an authenticated user to execute arbitrary code in DEARegister CGI script. This vulnerability impacted SMA100 version 9.0.0.3 and earlier. | 1% Низкий | почти 4 года назад | ||
GHSA-28f5-mg2c-r34c Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass intended restrictions on JavaScript API execution via unspecified vectors, a different vulnerability than CVE-2015-3060, CVE-2015-3061, CVE-2015-3062, CVE-2015-3063, CVE-2015-3064, CVE-2015-3065, CVE-2015-3066, CVE-2015-3067, CVE-2015-3068, CVE-2015-3069, CVE-2015-3071, CVE-2015-3072, and CVE-2015-3074. | 31% Средний | почти 4 года назад | ||
GHSA-28f5-7mw6-mfmc In AccountManager, there is a possible bypass of a permissions check due to a confused deputy. This could lead to local information disclosure, with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-123700107 | 0% Низкий | почти 4 года назад | ||
GHSA-28f5-7fwx-xrf3 When SWFTools 0.9.2 processes a crafted file in png2swf, it can lead to a Segmentation Violation in the png_load() function in lib/png.c. | CVSS3: 8.8 | 0% Низкий | почти 4 года назад | |
GHSA-28f5-3rf2-gpm8 Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects RBK852 before 3.2.17.12, RBK853 before 3.2.17.12, RBK854 before 3.2.17.12, RBR850 before 3.2.17.12, and RBS850 before 3.2.17.12. | 0% Низкий | почти 4 года назад | ||
GHSA-28f4-mjfq-qrvf Malicious Package in buffes-xor | CVSS3: 9.8 | больше 5 лет назад | ||
GHSA-28f4-f5wq-36wr The WooCommerce POS plugin for WordPress is vulnerable to information disclosure in all versions up to, and including, 1.4.11. This is due to the plugin not properly verifying the authentication and authorization of the current user This makes it possible for authenticated attackers, with customer-level access and above, to view potentially sensitive information about other users by leveraging their order id | CVSS3: 4.3 | 0% Низкий | около 2 лет назад | |
GHSA-28f4-9qfp-6f7v An issue was discovered in Xpdf 4.01.01. There is an FPE in the function ImageStream::ImageStream at Stream.cc for nBits. | CVSS3: 5.5 | 0% Низкий | почти 4 года назад | |
GHSA-28f3-rf96-2vvg Job Portal v1.0 is vulnerable to multiple Unauthenticated SQL Injection vulnerabilities. The 'txtPass' parameter of the login.php resource does not validate the characters received and they are sent unfiltered to the database. | CVSS3: 9.8 | больше 2 лет назад | ||
GHSA-28f3-c95g-f4g3 In Wireshark 2.4.0 to 2.4.3 and 2.2.0 to 2.2.11, the IxVeriWave file parser could crash. This was addressed in wiretap/vwr.c by correcting the signature timestamp bounds checks. | CVSS3: 6.5 | 1% Низкий | почти 4 года назад | |
GHSA-28f2-gw74-5cpj The setpermissions function in the auto-updater in Arq before 5.9.7 for Mac allows local users to gain root privileges via a symlink attack on the updater binary itself. | CVSS3: 7.4 | 1% Низкий | почти 4 года назад | |
GHSA-28cx-j4v5-m5fv Pluck CMS 4.7.18 does not restrict failed login attempts, allowing attackers to execute a brute force attack. | CVSS3: 9.8 | 0% Низкий | больше 1 года назад | |
GHSA-28cx-hxv4-g5q7 Online Car Wash Booking System v1.0 is vulnerable to SQL Injection via /ocwbs/admin/vehicles/manage_vehicle.php?id=. | CVSS3: 9.8 | 0% Низкий | почти 4 года назад | |
GHSA-28cx-5f85-hrh4 FrogCMS v0.9.5 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/?/page/edit/10. | CVSS3: 5.4 | 0% Низкий | больше 1 года назад | |
GHSA-28cw-rx3r-6f3c Palo Alto Networks Traps ESM Console before 3.4.4 allows attackers to cause a denial of service by leveraging improper validation of requests to revoke a Traps agent license. | CVSS3: 7.5 | 1% Низкий | почти 4 года назад | |
GHSA-28cw-qr46-rx46 The php_zip_make_relative_path function in php_zip.c in PHP 5.2.x before 5.2.9 allows context-dependent attackers to cause a denial of service (crash) via a ZIP file that contains filenames with relative paths, which is not properly handled during extraction. | 2% Низкий | почти 4 года назад | ||
GHSA-28cw-qjjv-g5g8 IBM Cognos Analytics 11.1.7, 11.2.0, and 11.2.1 could be vulnerable to a Log Injection attack by constructing URLs from user-controlled data. This could enable attackers to make arbitrary requests to the internal network or to the local file system. IBM X-Force ID: 240266. | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
GHSA-28cw-3j6f-3fv3 A vulnerability exists that could allow the execution of operating system commands on systems running MiPlatform 2019.05.16 and earlier. An attacker could execute arbitrary remote command by sending parameters to WinExec function in ExtCommandApi.dll module of MiPlatform. | 1% Низкий | почти 4 года назад |
Уязвимостей на страницу