Количество 376 080
Количество 376 080
GHSA-4x2c-gqrf-gvf9
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WpOpal Opal Widgets For Elementor allows Stored XSS.This issue affects Opal Widgets For Elementor: from n/a through 1.6.9.
GHSA-4x29-79gh-6v8q
Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M7 through 10.1.55, from 9.0.83 through 9.0.118. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fixes the issue.
GHSA-4x29-4984-2qcp
The av_rescale_rnd function in the AVI demuxer in FFmpeg 0.5 allows remote attackers to cause a denial of service (crash) via a crafted AVI file that triggers a divide-by-zero error.
GHSA-4x28-j85r-668q
ForkCMS Directory Traversal vulnerability
GHSA-4x28-f32q-r2qv
Zohocorp ManageEngine EndPoint Central versions 11.4.2516.1 and prior are vulnerable to XML Injection.
GHSA-4x27-7f5c-rg8p
A TOCTOU race condition in Samsung Mobile Processor Exynos 9820, Exynos 980, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, and Exynos 1380 can cause unexpected termination of a system.
GHSA-4x26-g7hr-m7g8
Dell PowerScale OneFS 8.2.x, 9.0.0.x-9.5.0.x contains an improper handling of insufficient permissions. A low privileged remote attacker could potentially exploit this vulnerability to cause information disclosure.
GHSA-4x26-g6p5-4wpg
Memory safety bugs were reported in Firefox 52, Firefox ESR 52, and Thunderbird 52. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53.
GHSA-4x25-wq2v-85f9
An issue was discovered in ThoughtWorks GoCD before 21.3.0. The business continuity add-on, which is enabled by default, leaks all secrets known to the GoCD server to unauthenticated attackers.
GHSA-4x25-pvhw-5224
Algorithms compute incorrect results in blake2
GHSA-4x25-gh54-whv9
App Sandbox in Apple OS X before 10.10 allows attackers to bypass a sandbox protection mechanism via the accessibility API.
GHSA-4x25-f45x-grv5
Missing encryption in Apache Directory Studio
GHSA-4x25-f42w-9g46
Multiple cross-site scripting (XSS) vulnerabilities in ui_stats.php in the bSuite plugin before 5 alpha 3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) s or (2) p parameters to index.php.
GHSA-4x25-3w8p-m6r3
HEVC Video Extensions Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-21844, CVE-2022-21926.
GHSA-4x24-p8p8-r7hm
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable use after free vulnerability in the ActionScript FileReference class. Successful exploitation could lead to arbitrary code execution.
GHSA-4x24-3v7p-2g45
A vulnerability was determined in itsourcecode sanitize or validate this input 1.0. This issue affects some unknown processing of the file /admin/subjects.php of the component Parameter Handler. This manipulation of the argument subject_code causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
GHSA-4x22-rf55-6p54
Rejected reason: Not used
GHSA-4x22-m2xr-v7q7
In the Linux kernel, the following vulnerability has been resolved: hwmon: (powerz) Fix missing usb_kill_urb() on signal interrupt wait_for_completion_interruptible_timeout() returns -ERESTARTSYS when interrupted. This needs to abort the URB and return an error. No data has been received from the device so any reads from the transfer buffer are invalid. The original code tests !ret, which only catches the timeout case (0). On signal delivery (-ERESTARTSYS), !ret is false so the function skips usb_kill_urb() and falls through to read from the unfilled transfer buffer. Fix by capturing the return value into a long (matching the function return type) and handling signal (negative) and timeout (zero) cases with separate checks that both call usb_kill_urb() before returning.
GHSA-4x22-h5rw-64w4
Cross-Site Request Forgery (CSRF) vulnerability in Vadim Bogaiskov Bg Orthodox Calendar allows Stored XSS. This issue affects Bg Orthodox Calendar: from n/a through 0.13.10.
GHSA-4x22-3827-w69r
Use after free in Microsoft Office Word allows an authorized attacker to disclose information locally.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4x2c-gqrf-gvf9 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WpOpal Opal Widgets For Elementor allows Stored XSS.This issue affects Opal Widgets For Elementor: from n/a through 1.6.9. | CVSS3: 6.5 | 0% Низкий | больше 2 лет назад | |
GHSA-4x29-79gh-6v8q Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M7 through 10.1.55, from 9.0.83 through 9.0.118. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fixes the issue. | CVSS3: 9.1 | 1% Низкий | 3 месяца назад | |
GHSA-4x29-4984-2qcp The av_rescale_rnd function in the AVI demuxer in FFmpeg 0.5 allows remote attackers to cause a denial of service (crash) via a crafted AVI file that triggers a divide-by-zero error. | 3% Низкий | больше 4 лет назад | ||
GHSA-4x28-j85r-668q ForkCMS Directory Traversal vulnerability | 2% Низкий | больше 4 лет назад | ||
GHSA-4x28-f32q-r2qv Zohocorp ManageEngine EndPoint Central versions 11.4.2516.1 and prior are vulnerable to XML Injection. | CVSS3: 5.2 | 0% Низкий | 11 месяцев назад | |
GHSA-4x27-7f5c-rg8p A TOCTOU race condition in Samsung Mobile Processor Exynos 9820, Exynos 980, Exynos 1080, Exynos 2100, Exynos 2200, Exynos 1280, and Exynos 1380 can cause unexpected termination of a system. | CVSS3: 6.3 | 0% Низкий | почти 3 года назад | |
GHSA-4x26-g7hr-m7g8 Dell PowerScale OneFS 8.2.x, 9.0.0.x-9.5.0.x contains an improper handling of insufficient permissions. A low privileged remote attacker could potentially exploit this vulnerability to cause information disclosure. | CVSS3: 4.3 | 0% Низкий | почти 3 года назад | |
GHSA-4x26-g6p5-4wpg Memory safety bugs were reported in Firefox 52, Firefox ESR 52, and Thunderbird 52. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Thunderbird < 52.1, Firefox ESR < 52.1, and Firefox < 53. | CVSS3: 9.8 | 3% Низкий | больше 4 лет назад | |
GHSA-4x25-wq2v-85f9 An issue was discovered in ThoughtWorks GoCD before 21.3.0. The business continuity add-on, which is enabled by default, leaks all secrets known to the GoCD server to unauthenticated attackers. | CVSS3: 7.5 | 28% Средний | больше 4 лет назад | |
GHSA-4x25-pvhw-5224 Algorithms compute incorrect results in blake2 | CVSS3: 9.8 | 1% Низкий | около 5 лет назад | |
GHSA-4x25-gh54-whv9 App Sandbox in Apple OS X before 10.10 allows attackers to bypass a sandbox protection mechanism via the accessibility API. | 1% Низкий | больше 4 лет назад | ||
GHSA-4x25-f45x-grv5 Missing encryption in Apache Directory Studio | CVSS3: 7.5 | 1% Низкий | около 5 лет назад | |
GHSA-4x25-f42w-9g46 Multiple cross-site scripting (XSS) vulnerabilities in ui_stats.php in the bSuite plugin before 5 alpha 3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) s or (2) p parameters to index.php. | CVSS3: 6.1 | 2% Низкий | больше 4 лет назад | |
GHSA-4x25-3w8p-m6r3 HEVC Video Extensions Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-21844, CVE-2022-21926. | CVSS3: 7.8 | 2% Низкий | больше 4 лет назад | |
GHSA-4x24-p8p8-r7hm Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable use after free vulnerability in the ActionScript FileReference class. Successful exploitation could lead to arbitrary code execution. | CVSS3: 9.8 | 6% Низкий | больше 4 лет назад | |
GHSA-4x24-3v7p-2g45 A vulnerability was determined in itsourcecode sanitize or validate this input 1.0. This issue affects some unknown processing of the file /admin/subjects.php of the component Parameter Handler. This manipulation of the argument subject_code causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. | CVSS3: 6.3 | 0% Низкий | 6 месяцев назад | |
GHSA-4x22-rf55-6p54 Rejected reason: Not used | 7 месяцев назад | |||
GHSA-4x22-m2xr-v7q7 In the Linux kernel, the following vulnerability has been resolved: hwmon: (powerz) Fix missing usb_kill_urb() on signal interrupt wait_for_completion_interruptible_timeout() returns -ERESTARTSYS when interrupted. This needs to abort the URB and return an error. No data has been received from the device so any reads from the transfer buffer are invalid. The original code tests !ret, which only catches the timeout case (0). On signal delivery (-ERESTARTSYS), !ret is false so the function skips usb_kill_urb() and falls through to read from the unfilled transfer buffer. Fix by capturing the return value into a long (matching the function return type) and handling signal (negative) and timeout (zero) cases with separate checks that both call usb_kill_urb() before returning. | CVSS3: 5.5 | 0% Низкий | 4 месяца назад | |
GHSA-4x22-h5rw-64w4 Cross-Site Request Forgery (CSRF) vulnerability in Vadim Bogaiskov Bg Orthodox Calendar allows Stored XSS. This issue affects Bg Orthodox Calendar: from n/a through 0.13.10. | CVSS3: 7.1 | 0% Низкий | больше 1 года назад | |
GHSA-4x22-3827-w69r Use after free in Microsoft Office Word allows an authorized attacker to disclose information locally. | CVSS3: 5.5 | 0% Низкий | 15 дней назад |
Уязвимостей на страницу