Количество 377 914
Количество 377 914
GHSA-52rg-37rg-rfhm
The EXMAGE WordPress plugin before 1.0.7 does to ensure that images added via URLs are external images, which could lead to a blind SSRF issue by using local URLs
GHSA-52rf-xp84-3xvf
A vulnerability, which was classified as critical, was found in code-projects Modern Bag 1.0. This affects an unknown part of the file /admin/slide.php. The manipulation of the argument idSlide leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
GHSA-52rf-pfj9-676q
The wu_fnmatch function in wu_fnmatch.c in wu-ftpd 2.6.1 and 2.6.2 allows remote attackers to cause a denial of service (CPU exhaustion by recursion) via a glob pattern with a large number of * (wildcard) characters, as demonstrated using the dir command.
GHSA-52rf-25hq-5m33
GeoNetwork search end-point information disclosure in response headers
GHSA-52r9-g5g6-2hjp
Path Traversal in node-srv
GHSA-52r8-qcqv-p7v2
The communication module has a vulnerability of improper permission preservation. Successful exploitation of this vulnerability may affect system availability.
GHSA-52r8-phxr-cfq6
A vulnerability classified as critical has been found in code-projects Restaurant Reservation System 1.0. Affected is an unknown function of the file /filter.php. The manipulation of the argument from/to leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory only mentions the parameter "from" to be affected. But it must be assumed that parameter "to" is affected as well.
GHSA-52r7-gmhc-j7x9
Buffer overflow in a component of SQL-DMO for Microsoft Data Access Components (MDAC) 2.5 through 2.7 allows remote attackers to execute arbitrary code via a long response to a broadcast request to UDP port 1434.
GHSA-52r7-5244-6rfw
D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formSetWanPPPoE. This vulnerability allows attackers to cause a Denial of Service (DoS) via the curTime parameter.
GHSA-52r7-445m-rwcg
Inappropriate implementation in Permissions in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to tamper with the contents of the Omnibox (URL bar) via a crafted HTML page.
GHSA-52r6-x37j-435c
A vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5, 7.4.2.j could allow a remote authenticated attacker to perform stack buffer overflow using in “firmwaredownload” and “diagshow” commands.
GHSA-52r6-v45h-gh94
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lavacode Lava Ajax Search allows Stored XSS. This issue affects Lava Ajax Search: from n/a through 1.1.9.
GHSA-52r6-m74f-9g7w
A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.0.1.12430. By prematurely destroying annotation objects, a specially-crafted PDF document can trigger the reuse of previously freed memory, which can lead to arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially-crafted, malicious site if the browser plugin extension is enabled.
GHSA-52r6-fgpp-m7pq
The Fonts implementation in Google Chrome before 40.0.2214.91 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
GHSA-52r6-cp5p-c6x5
SQL injection vulnerability in Order Data Edit page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with editor (without setting authority) or higher privilege to perform unintended database operations.
GHSA-52r6-233g-595f
CRLF injection vulnerability in ownCloud Server before 4.0.8 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the url path parameter.
GHSA-52r5-vp3g-vg7r
DHCP Server Service Information Disclosure Vulnerability
GHSA-52r5-crc5-6473
An issue pertaining to CWE-319: Cleartext Transmission of Sensitive Information was discovered in Nexusoft NexusInterface v3.2.0-beta.2.
GHSA-52r5-7r4h-6hpf
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 allows remote authenticated users to affect confidentiality and integrity via vectors related to Oracle Agile PLM Framework.
GHSA-52r5-4x5p-ff7w
Cisco-Meraki MS, MR, and MX devices with firmware before 2014-09-24 allow physically proximate attackers to obtain shell access by opening a device's case and connecting a cable to a serial port, aka Cisco-Meraki defect ID 00302077.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-52rg-37rg-rfhm The EXMAGE WordPress plugin before 1.0.7 does to ensure that images added via URLs are external images, which could lead to a blind SSRF issue by using local URLs | CVSS3: 7.2 | 1% Низкий | больше 4 лет назад | |
GHSA-52rf-xp84-3xvf A vulnerability, which was classified as critical, was found in code-projects Modern Bag 1.0. This affects an unknown part of the file /admin/slide.php. The manipulation of the argument idSlide leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 7.3 | 0% Низкий | около 1 года назад | |
GHSA-52rf-pfj9-676q The wu_fnmatch function in wu_fnmatch.c in wu-ftpd 2.6.1 and 2.6.2 allows remote attackers to cause a denial of service (CPU exhaustion by recursion) via a glob pattern with a large number of * (wildcard) characters, as demonstrated using the dir command. | 5% Низкий | больше 4 лет назад | ||
GHSA-52rf-25hq-5m33 GeoNetwork search end-point information disclosure in response headers | CVSS3: 5.3 | 0% Низкий | больше 1 года назад | |
GHSA-52r9-g5g6-2hjp Path Traversal in node-srv | CVSS3: 6.5 | 9% Низкий | около 8 лет назад | |
GHSA-52r8-qcqv-p7v2 The communication module has a vulnerability of improper permission preservation. Successful exploitation of this vulnerability may affect system availability. | CVSS3: 5.5 | 0% Низкий | больше 4 лет назад | |
GHSA-52r8-phxr-cfq6 A vulnerability classified as critical has been found in code-projects Restaurant Reservation System 1.0. Affected is an unknown function of the file /filter.php. The manipulation of the argument from/to leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory only mentions the parameter "from" to be affected. But it must be assumed that parameter "to" is affected as well. | CVSS3: 6.3 | 1% Низкий | около 2 лет назад | |
GHSA-52r7-gmhc-j7x9 Buffer overflow in a component of SQL-DMO for Microsoft Data Access Components (MDAC) 2.5 through 2.7 allows remote attackers to execute arbitrary code via a long response to a broadcast request to UDP port 1434. | 22% Средний | больше 4 лет назад | ||
GHSA-52r7-5244-6rfw D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formSetWanPPPoE. This vulnerability allows attackers to cause a Denial of Service (DoS) via the curTime parameter. | CVSS3: 7.5 | 2% Низкий | больше 4 лет назад | |
GHSA-52r7-445m-rwcg Inappropriate implementation in Permissions in Google Chrome prior to 99.0.4844.51 allowed a remote attacker to tamper with the contents of the Omnibox (URL bar) via a crafted HTML page. | CVSS3: 6.5 | 1% Низкий | больше 4 лет назад | |
GHSA-52r6-x37j-435c A vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5, 7.4.2.j could allow a remote authenticated attacker to perform stack buffer overflow using in “firmwaredownload” and “diagshow” commands. | CVSS3: 8.8 | 2% Низкий | около 3 лет назад | |
GHSA-52r6-v45h-gh94 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in lavacode Lava Ajax Search allows Stored XSS. This issue affects Lava Ajax Search: from n/a through 1.1.9. | CVSS3: 5.9 | 0% Низкий | больше 1 года назад | |
GHSA-52r6-m74f-9g7w A use-after-free vulnerability exists in the JavaScript engine of Foxit Software's PDF Reader, version 12.0.1.12430. By prematurely destroying annotation objects, a specially-crafted PDF document can trigger the reuse of previously freed memory, which can lead to arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially-crafted, malicious site if the browser plugin extension is enabled. | CVSS3: 7.8 | 1% Низкий | почти 4 года назад | |
GHSA-52r6-fgpp-m7pq The Fonts implementation in Google Chrome before 40.0.2214.91 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors. | 2% Низкий | больше 4 лет назад | ||
GHSA-52r6-cp5p-c6x5 SQL injection vulnerability in Order Data Edit page of Welcart e-Commerce versions 2.7 to 2.8.21 allows a user with editor (without setting authority) or higher privilege to perform unintended database operations. | CVSS3: 8.8 | 1% Низкий | около 3 лет назад | |
GHSA-52r6-233g-595f CRLF injection vulnerability in ownCloud Server before 4.0.8 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the url path parameter. | 1% Низкий | больше 4 лет назад | ||
GHSA-52r5-vp3g-vg7r DHCP Server Service Information Disclosure Vulnerability | CVSS3: 5.3 | 2% Низкий | почти 3 года назад | |
GHSA-52r5-crc5-6473 An issue pertaining to CWE-319: Cleartext Transmission of Sensitive Information was discovered in Nexusoft NexusInterface v3.2.0-beta.2. | CVSS3: 7.5 | 0% Низкий | 7 месяцев назад | |
GHSA-52r5-7r4h-6hpf Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 allows remote authenticated users to affect confidentiality and integrity via vectors related to Oracle Agile PLM Framework. | 1% Низкий | больше 4 лет назад | ||
GHSA-52r5-4x5p-ff7w Cisco-Meraki MS, MR, and MX devices with firmware before 2014-09-24 allow physically proximate attackers to obtain shell access by opening a device's case and connecting a cable to a serial port, aka Cisco-Meraki defect ID 00302077. | 0% Низкий | больше 4 лет назад |
Уязвимостей на страницу