Количество 377 914
Количество 377 914
GHSA-52r4-jr79-62gj
Unauthenticated PHP Object Injection in Ashtanga <= 1.2 versions.
GHSA-52r3-m642-mp2f
Cross-site scripting (XSS) vulnerability in CA Release Automation (formerly iTKO LISA Release Automation) before 4.7.1 b448 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
GHSA-52r3-f6x8-h7v5
The Node Quick Find module 6.x-1.1 for Drupal does not use db_rewrite_sql when presenting node titles, which allows remote attackers to bypass intended access restrictions and read potentially sensitive node titles via the autocomplete feature.
GHSA-52r3-7vqc-4rq7
ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to delete any file on the file system due to a path traversal vulnerability in wallpaper.cgi.
GHSA-52r2-xf63-fp2q
Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
GHSA-52r2-7jx8-c8gc
The verify_host_key function in sshconnect.c in the client in OpenSSH 6.6 and earlier allows remote servers to trigger the skipping of SSHFP DNS RR checking by presenting an unacceptable HostCertificate.
GHSA-52qx-x9h4-rv8r
Input verification vulnerability in the log module. Impact: Successful exploitation of this vulnerability can affect integrity.
GHSA-52qw-w4c5-82h4
Unauthenticated Broken Access Control in POS Entegratör <= 3.7.103 versions.
GHSA-52qw-pvqg-c2g3
TalkBack 2.3.6 allows remote attackers to obtain configuration information via a direct request to install/info.php, which calls the phpinfo function.
GHSA-52qv-74wq-8rcv
AVer Information EH6108H+ devices with firmware X9.03.24.00.07l have hardcoded accounts, which allows remote attackers to obtain root access by leveraging knowledge of the credentials and establishing a TELNET session.
GHSA-52qv-5pm8-p78h
In isFileUri of UriUtil.java, there is a possible way to bypass ignoring file://URI attachment due to improper handling of case sensitivity. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-197328178
GHSA-52qr-8f69-pcpq
A race condition was addressed with improved state management. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to gain root privileges.
GHSA-52qr-2974-mpj9
A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. rtmp=start param is not object. An attacker can send an HTTP request to trigger this vulnerability.
GHSA-52qr-28j9-p9j3
Memory corruption issues in Intel(R) WIFI Drivers before version 21.40 may allow a privileged user to potentially enable escalation of privilege, denial of service, and information disclosure via local access.
GHSA-52qq-78xg-p62c
Improper Control of Generation of Code ('Code Injection') vulnerability in Bearsthemes Alone allows Code Injection. This issue affects Alone: from n/a through n/a.
GHSA-52qp-jpq7-6c54
Insecure Deserialization of untrusted data in rmccue/requests
GHSA-52qp-gwwh-qrg4
Missing Handler in @scandipwa/magento-scripts
GHSA-52qp-94q2-h5wv
The Dog Whistle (aka com.dogwhistle.dogtrainingandroidapp) application 1.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
GHSA-52qm-v8p3-wc8p
Heap-based buffer overflow in the nsBlockFrame::MarkLineDirty function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code via unspecified vectors.
GHSA-52qm-pr2g-7h6x
The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mongod.log file in plain text.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-52r4-jr79-62gj Unauthenticated PHP Object Injection in Ashtanga <= 1.2 versions. | CVSS3: 8.1 | 0% Низкий | 3 месяца назад | |
GHSA-52r3-m642-mp2f Cross-site scripting (XSS) vulnerability in CA Release Automation (formerly iTKO LISA Release Automation) before 4.7.1 b448 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 2% Низкий | больше 4 лет назад | ||
GHSA-52r3-f6x8-h7v5 The Node Quick Find module 6.x-1.1 for Drupal does not use db_rewrite_sql when presenting node titles, which allows remote attackers to bypass intended access restrictions and read potentially sensitive node titles via the autocomplete feature. | 1% Низкий | больше 4 лет назад | ||
GHSA-52r3-7vqc-4rq7 ASUSTOR Data Master 3.1.5 and below allows authenticated remote non-administrative users to delete any file on the file system due to a path traversal vulnerability in wallpaper.cgi. | CVSS3: 6.5 | 1% Низкий | больше 4 лет назад | |
GHSA-52r2-xf63-fp2q Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." | 16% Средний | больше 4 лет назад | ||
GHSA-52r2-7jx8-c8gc The verify_host_key function in sshconnect.c in the client in OpenSSH 6.6 and earlier allows remote servers to trigger the skipping of SSHFP DNS RR checking by presenting an unacceptable HostCertificate. | CVSS3: 6.5 | 2% Низкий | больше 4 лет назад | |
GHSA-52qx-x9h4-rv8r Input verification vulnerability in the log module. Impact: Successful exploitation of this vulnerability can affect integrity. | CVSS3: 7.5 | 0% Низкий | больше 2 лет назад | |
GHSA-52qw-w4c5-82h4 Unauthenticated Broken Access Control in POS Entegratör <= 3.7.103 versions. | CVSS3: 8.2 | 0% Низкий | 3 месяца назад | |
GHSA-52qw-pvqg-c2g3 TalkBack 2.3.6 allows remote attackers to obtain configuration information via a direct request to install/info.php, which calls the phpinfo function. | 3% Низкий | больше 4 лет назад | ||
GHSA-52qv-74wq-8rcv AVer Information EH6108H+ devices with firmware X9.03.24.00.07l have hardcoded accounts, which allows remote attackers to obtain root access by leveraging knowledge of the credentials and establishing a TELNET session. | CVSS3: 9.8 | 2% Низкий | больше 4 лет назад | |
GHSA-52qv-5pm8-p78h In isFileUri of UriUtil.java, there is a possible way to bypass ignoring file://URI attachment due to improper handling of case sensitivity. This could lead to local information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-12Android ID: A-197328178 | 0% Низкий | почти 5 лет назад | ||
GHSA-52qr-8f69-pcpq A race condition was addressed with improved state management. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe 26.6. An app may be able to gain root privileges. | CVSS3: 7 | 0% Низкий | 2 месяца назад | |
GHSA-52qr-2974-mpj9 A denial of service vulnerability exists in the cgiserver.cgi JSON command parser functionality of reolink RLC-410W v3.0.0.136_20121102. A specially-crafted HTTP request can lead to a reboot. rtmp=start param is not object. An attacker can send an HTTP request to trigger this vulnerability. | CVSS3: 6.5 | 1% Низкий | больше 4 лет назад | |
GHSA-52qr-28j9-p9j3 Memory corruption issues in Intel(R) WIFI Drivers before version 21.40 may allow a privileged user to potentially enable escalation of privilege, denial of service, and information disclosure via local access. | 0% Низкий | больше 4 лет назад | ||
GHSA-52qq-78xg-p62c Improper Control of Generation of Code ('Code Injection') vulnerability in Bearsthemes Alone allows Code Injection. This issue affects Alone: from n/a through n/a. | CVSS3: 6.5 | 0% Низкий | около 1 года назад | |
GHSA-52qp-jpq7-6c54 Insecure Deserialization of untrusted data in rmccue/requests | CVSS3: 9.8 | 2% Низкий | больше 5 лет назад | |
GHSA-52qp-gwwh-qrg4 Missing Handler in @scandipwa/magento-scripts | CVSS3: 6.2 | 1% Низкий | больше 5 лет назад | |
GHSA-52qp-94q2-h5wv The Dog Whistle (aka com.dogwhistle.dogtrainingandroidapp) application 1.9 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 0% Низкий | больше 4 лет назад | ||
GHSA-52qm-v8p3-wc8p Heap-based buffer overflow in the nsBlockFrame::MarkLineDirty function in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, Thunderbird ESR 10.x before 10.0.7, and SeaMonkey before 2.12 allows remote attackers to execute arbitrary code via unspecified vectors. | 8% Низкий | больше 4 лет назад | ||
GHSA-52qm-pr2g-7h6x The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mongod.log file in plain text. | CVSS3: 5.5 | 0% Низкий | 4 месяца назад |
Уязвимостей на страницу