Количество 324 081
Количество 324 081
GHSA-27g2-4mxr-gqmm
Cross-Site Request Forgery (CSRF) vulnerability in Laborator Kalium allows Cross Site Request Forgery. This issue affects Kalium: from n/a through 3.18.3.
GHSA-27fx-q398-q8vr
masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the user parameter during a ping action.
GHSA-27fw-r78j-h898
Wikimedia MediaWiki allows CSRF
GHSA-27fw-99r5-fg9c
SQL Injection vulnerability in MegaBIP software allows attacker to obtain site administrator privileges, including access to the administration panel and the ability to change the administrator password. This issue affects MegaBIP software versions through 5.09.
GHSA-27fw-6hp8-fgww
The av_color_primaries_name function in libavutil/pixdesc.c in FFmpeg 3.3.3 may return a NULL pointer depending on a value contained in a file, but callers do not anticipate this, as demonstrated by the avcodec_string function in libavcodec/utils.c, leading to a NULL pointer dereference. (It is also conceivable that there is security relevance for a NULL pointer dereference in av_color_primaries_name calls within the ffprobe command-line program.)
GHSA-27fv-rpgj-4c6m
Drupal Currency allows Cross Site Request Forgery
GHSA-27fr-v43j-r34m
In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments.
GHSA-27fq-8xxm-gqgw
A security flaw has been discovered in Open5GS up to 2.7.5. This issue affects some unknown processing of the component Timer Handler. The manipulation results in resource consumption. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The patch is identified as c7c131f8d2cb1195ada5e0e691b6868ebcd8a845. It is best practice to apply a patch to resolve this issue.
GHSA-27fp-j2gf-67vv
peertube is vulnerable to Improper Access Control
GHSA-27fp-c3m4-phwv
A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.862_B20230228. It has been classified as critical. This affects the function setTracerouteCfg. The manipulation leads to os command injection. It is possible to initiate the attack remotely. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
GHSA-27fp-57pm-cw48
In register_app of btif_hd.cc, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-8.0 Android-8.1 Android-9. Android ID: A-119819889.
GHSA-27fj-mc8w-j9wg
RSA signature validation vulnerability on maleable encoded message in jsrsasign
GHSA-27fj-7xp4-5c3r
Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system.
GHSA-27fh-xm3c-9mq3
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Foliovision: Making the web work for you FV Flowplayer Video Player allows Stored XSS.This issue affects FV Flowplayer Video Player: from n/a through 7.5.41.7212.
GHSA-27fg-vf5m-qmjj
In the Linux kernel, the following vulnerability has been resolved: vfio/pci: fix potential memory leak in vfio_intx_enable() If vfio_irq_ctx_alloc() failed will lead to 'name' memory leak.
GHSA-27fg-888w-q9q3
Improper Control of Generation of Code ('Code Injection') vulnerability in Bearsthemes Alone allows Remote Code Inclusion. This issue affects Alone: from n/a through 7.8.2.
GHSA-27fg-773w-qwfr
An issue was discovered in Thunar before 4.16.7 and 4.17.x before 4.17.2. When called with a regular file as a command-line argument, it delegates to a different program (based on the file type) without user confirmation. This could be used to achieve code execution.
GHSA-27ff-f66w-789c
Memory leak in the icmp_push_reply function in Linux 2.6 before 2.6.12.6 and 2.6.13 allows remote attackers to cause a denial of service (memory consumption) via a large number of crafted packets that cause the ip_append_data function to fail, aka "DST leak in icmp_push_reply."
GHSA-27fc-vfp8-wfj8
Cisco WebEx Meetings Server 1.5 presents the same CAPTCHA challenge for each login attempt, which makes it easier for remote attackers to obtain access via a brute-force approach of guessing usernames, aka Bug ID CSCuj40321.
GHSA-27fc-mjrp-6g7x
XML external entity (XXE) injection in eyoucms v1.7.1 allows remote attackers to cause a denial of service via crafted body of a POST request.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-27g2-4mxr-gqmm Cross-Site Request Forgery (CSRF) vulnerability in Laborator Kalium allows Cross Site Request Forgery. This issue affects Kalium: from n/a through 3.18.3. | CVSS3: 4.3 | 0% Низкий | 8 месяцев назад | |
GHSA-27fx-q398-q8vr masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the user parameter during a ping action. | CVSS3: 9.8 | 94% Критический | почти 4 года назад | |
GHSA-27fw-r78j-h898 Wikimedia MediaWiki allows CSRF | CVSS3: 8.8 | 0% Низкий | почти 4 года назад | |
GHSA-27fw-99r5-fg9c SQL Injection vulnerability in MegaBIP software allows attacker to obtain site administrator privileges, including access to the administration panel and the ability to change the administrator password. This issue affects MegaBIP software versions through 5.09. | CVSS3: 9.8 | 0% Низкий | почти 2 года назад | |
GHSA-27fw-6hp8-fgww The av_color_primaries_name function in libavutil/pixdesc.c in FFmpeg 3.3.3 may return a NULL pointer depending on a value contained in a file, but callers do not anticipate this, as demonstrated by the avcodec_string function in libavcodec/utils.c, leading to a NULL pointer dereference. (It is also conceivable that there is security relevance for a NULL pointer dereference in av_color_primaries_name calls within the ffprobe command-line program.) | CVSS3: 8.8 | 0% Низкий | почти 4 года назад | |
GHSA-27fv-rpgj-4c6m Drupal Currency allows Cross Site Request Forgery | CVSS3: 6.5 | 0% Низкий | 5 месяцев назад | |
GHSA-27fr-v43j-r34m In Emacs before 29.3, LaTeX preview is enabled by default for e-mail attachments. | CVSS3: 2.8 | 0% Низкий | около 2 лет назад | |
GHSA-27fq-8xxm-gqgw A security flaw has been discovered in Open5GS up to 2.7.5. This issue affects some unknown processing of the component Timer Handler. The manipulation results in resource consumption. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. The patch is identified as c7c131f8d2cb1195ada5e0e691b6868ebcd8a845. It is best practice to apply a patch to resolve this issue. | CVSS3: 5.3 | 0% Низкий | 2 месяца назад | |
GHSA-27fp-j2gf-67vv peertube is vulnerable to Improper Access Control | 0% Низкий | около 4 лет назад | ||
GHSA-27fp-c3m4-phwv A vulnerability was found in TOTOLINK AC1200 T8 4.1.5cu.862_B20230228. It has been classified as critical. This affects the function setTracerouteCfg. The manipulation leads to os command injection. It is possible to initiate the attack remotely. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 6.3 | 2% Низкий | больше 1 года назад | |
GHSA-27fp-57pm-cw48 In register_app of btif_hd.cc, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-8.0 Android-8.1 Android-9. Android ID: A-119819889. | CVSS3: 7.8 | 0% Низкий | почти 4 года назад | |
GHSA-27fj-mc8w-j9wg RSA signature validation vulnerability on maleable encoded message in jsrsasign | CVSS3: 9.1 | 0% Низкий | почти 5 лет назад | |
GHSA-27fj-7xp4-5c3r Authenticated command injection vulnerabilities exist in the ArubaOS command line interface. Successful exploitation of these vulnerabilities result in the ability to execute arbitrary commands as a privileged user on the underlying operating system. | CVSS3: 7.2 | 1% Низкий | больше 2 лет назад | |
GHSA-27fh-xm3c-9mq3 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Foliovision: Making the web work for you FV Flowplayer Video Player allows Stored XSS.This issue affects FV Flowplayer Video Player: from n/a through 7.5.41.7212. | CVSS3: 6.5 | 0% Низкий | около 2 лет назад | |
GHSA-27fg-vf5m-qmjj In the Linux kernel, the following vulnerability has been resolved: vfio/pci: fix potential memory leak in vfio_intx_enable() If vfio_irq_ctx_alloc() failed will lead to 'name' memory leak. | CVSS3: 5.5 | 0% Низкий | почти 2 года назад | |
GHSA-27fg-888w-q9q3 Improper Control of Generation of Code ('Code Injection') vulnerability in Bearsthemes Alone allows Remote Code Inclusion. This issue affects Alone: from n/a through 7.8.2. | CVSS3: 7.2 | 0% Низкий | 9 месяцев назад | |
GHSA-27fg-773w-qwfr An issue was discovered in Thunar before 4.16.7 and 4.17.x before 4.17.2. When called with a regular file as a command-line argument, it delegates to a different program (based on the file type) without user confirmation. This could be used to achieve code execution. | CVSS3: 9.8 | 1% Низкий | почти 4 года назад | |
GHSA-27ff-f66w-789c Memory leak in the icmp_push_reply function in Linux 2.6 before 2.6.12.6 and 2.6.13 allows remote attackers to cause a denial of service (memory consumption) via a large number of crafted packets that cause the ip_append_data function to fail, aka "DST leak in icmp_push_reply." | 7% Низкий | почти 4 года назад | ||
GHSA-27fc-vfp8-wfj8 Cisco WebEx Meetings Server 1.5 presents the same CAPTCHA challenge for each login attempt, which makes it easier for remote attackers to obtain access via a brute-force approach of guessing usernames, aka Bug ID CSCuj40321. | 0% Низкий | почти 4 года назад | ||
GHSA-27fc-mjrp-6g7x XML external entity (XXE) injection in eyoucms v1.7.1 allows remote attackers to cause a denial of service via crafted body of a POST request. | CVSS3: 9.1 | 0% Низкий | 4 месяца назад |
Уязвимостей на страницу