Количество 375 727
Количество 375 727
GHSA-4w97-57v2-3w44
False-negative validation results in MINT transactions with invalid baton
GHSA-4w96-3hrf-qq67
Use-after-free vulnerability in Google Chrome before 9.0.597.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to blocked plug-ins.
GHSA-4w94-xc6r-9grm
Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious input to trigger any of these vulnerabilities. An oob read vulnerability exists in Nef_S2/SNC_io_parser.h SNC_io_parser<EW>::read_vertex() vh->svertices_last().
GHSA-4w94-x732-jcmm
Authorization Bypass Through User-Controlled Key vulnerability in LatePoint LatePoint latepoint allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LatePoint: from n/a through <= 5.2.6.
GHSA-4w94-8ff7-4xmw
An improper authentication issue was discovered in Johnson & Johnson Ethicon Endo-Surgery Generator Gen11, all versions released before November 29, 2017. The security authentication mechanism used between the Ethicon Endo-Surgery Generator Gen11 and single-patient use products can be bypassed, allowing for unauthorized devices to be connected to the generator, which could result in a loss of integrity or availability.
GHSA-4w94-4xq8-3wqx
QL Office in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted office document.
GHSA-4w93-m9qg-7rwr
A vulnerability was discovered in GitLab versions prior to 13.1. Under certain conditions the restriction for Github project import could be bypassed.
GHSA-4w93-8r29-p2r9
JumpCloud Agent before 1.178.0 Creates a Temporary File in a Directory with Insecure Permissions. This allows privilege escalation to SYSTEM via a repair action in the installer.
GHSA-4w93-8hmg-4r2c
Directory traversal vulnerability in getfile.asp in Ultimate HelpDesk allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.
GHSA-4w93-6768-q548
The mintToken function of a smart contract implementation for ENTER (ENTR) (Contract Name: EnterCoin), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
GHSA-4w92-vgp9-22jp
Soft3304 04WebServer before 1.41 does not properly check file names, which allows remote attackers to obtain sensitive information (CGI source code).
GHSA-4w92-qgpc-qcc9
A vulnerability in ABB Aspect.This issue affects Aspect: before <3.08.04-s01.
GHSA-4w8x-p5gf-gh2h
IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a user to cause a denial of service due to missing API rate limiting. IBM X-Force ID: 248533.
GHSA-4w8v-rh82-h7w8
IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
GHSA-4w8v-46j6-77cf
The HTTPS implementation in Google Chrome before 28.0.1500.71 does not ensure that headers are terminated by \r\n\r\n (carriage return, newline, carriage return, newline), which allows man-in-the-middle attackers to have an unspecified impact via vectors that trigger header truncation.
GHSA-4w8r-4268-4w28
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weptile ShopApper allows Stored XSS. This issue affects ShopApper: from n/a through 0.4.39.
GHSA-4w8r-3xrw-v25g
Craft CMS Remote Code Execution vulnerability
GHSA-4w8q-c6h3-w87x
The multiplayer menu in OpenTTD 0.4.7 allows remote attackers to cause a denial of service via a UDP packet with an incorrect size, which causes the client to return to the main menu.
GHSA-4w8q-7wmj-6f3m
In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06126832; Issue ID: ALPS06126832.
GHSA-4w8p-xx38-h33q
An Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could allow an attacker to gain access to some user accounts.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4w97-57v2-3w44 False-negative validation results in MINT transactions with invalid baton | CVSS3: 8.6 | 1% Низкий | больше 6 лет назад | |
GHSA-4w96-3hrf-qq67 Use-after-free vulnerability in Google Chrome before 9.0.597.107 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to blocked plug-ins. | 2% Низкий | больше 4 лет назад | ||
GHSA-4w94-xc6r-9grm Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker can provide malicious input to trigger any of these vulnerabilities. An oob read vulnerability exists in Nef_S2/SNC_io_parser.h SNC_io_parser<EW>::read_vertex() vh->svertices_last(). | CVSS3: 8.8 | 2% Низкий | больше 4 лет назад | |
GHSA-4w94-x732-jcmm Authorization Bypass Through User-Controlled Key vulnerability in LatePoint LatePoint latepoint allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LatePoint: from n/a through <= 5.2.6. | CVSS3: 6.5 | 0% Низкий | 6 месяцев назад | |
GHSA-4w94-8ff7-4xmw An improper authentication issue was discovered in Johnson & Johnson Ethicon Endo-Surgery Generator Gen11, all versions released before November 29, 2017. The security authentication mechanism used between the Ethicon Endo-Surgery Generator Gen11 and single-patient use products can be bypassed, allowing for unauthorized devices to be connected to the generator, which could result in a loss of integrity or availability. | CVSS3: 4.8 | 0% Низкий | больше 4 лет назад | |
GHSA-4w94-4xq8-3wqx QL Office in Apple iOS before 8.4.1 and OS X before 10.10.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted office document. | 3% Низкий | больше 4 лет назад | ||
GHSA-4w93-m9qg-7rwr A vulnerability was discovered in GitLab versions prior to 13.1. Under certain conditions the restriction for Github project import could be bypassed. | 1% Низкий | больше 4 лет назад | ||
GHSA-4w93-8r29-p2r9 JumpCloud Agent before 1.178.0 Creates a Temporary File in a Directory with Insecure Permissions. This allows privilege escalation to SYSTEM via a repair action in the installer. | CVSS3: 5.9 | 0% Низкий | больше 2 лет назад | |
GHSA-4w93-8hmg-4r2c Directory traversal vulnerability in getfile.asp in Ultimate HelpDesk allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter. | 3% Низкий | больше 4 лет назад | ||
GHSA-4w93-6768-q548 The mintToken function of a smart contract implementation for ENTER (ENTR) (Contract Name: EnterCoin), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | CVSS3: 7.5 | 1% Низкий | больше 4 лет назад | |
GHSA-4w92-vgp9-22jp Soft3304 04WebServer before 1.41 does not properly check file names, which allows remote attackers to obtain sensitive information (CGI source code). | 1% Низкий | больше 4 лет назад | ||
GHSA-4w92-qgpc-qcc9 A vulnerability in ABB Aspect.This issue affects Aspect: before <3.08.04-s01. | CVSS3: 7 | около 1 года назад | ||
GHSA-4w8x-p5gf-gh2h IBM Aspera Faspex 5.0.0 through 5.0.7 could allow a user to cause a denial of service due to missing API rate limiting. IBM X-Force ID: 248533. | CVSS3: 6.5 | 1% Низкий | больше 2 лет назад | |
GHSA-4w8v-rh82-h7w8 IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | CVSS3: 6.4 | 0% Низкий | 3 месяца назад | |
GHSA-4w8v-46j6-77cf The HTTPS implementation in Google Chrome before 28.0.1500.71 does not ensure that headers are terminated by \r\n\r\n (carriage return, newline, carriage return, newline), which allows man-in-the-middle attackers to have an unspecified impact via vectors that trigger header truncation. | 1% Низкий | больше 4 лет назад | ||
GHSA-4w8r-4268-4w28 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in weptile ShopApper allows Stored XSS. This issue affects ShopApper: from n/a through 0.4.39. | CVSS3: 7.1 | 0% Низкий | больше 1 года назад | |
GHSA-4w8r-3xrw-v25g Craft CMS Remote Code Execution vulnerability | CVSS3: 10 | 94% Критический | около 3 лет назад | |
GHSA-4w8q-c6h3-w87x The multiplayer menu in OpenTTD 0.4.7 allows remote attackers to cause a denial of service via a UDP packet with an incorrect size, which causes the client to return to the main menu. | 9% Низкий | больше 4 лет назад | ||
GHSA-4w8q-7wmj-6f3m In Bluetooth, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06126832; Issue ID: ALPS06126832. | 0% Низкий | больше 4 лет назад | ||
GHSA-4w8p-xx38-h33q An Improper Authorization vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2023x through Release 3DEXPERIENCE R2026x could allow an attacker to gain access to some user accounts. | CVSS3: 9.3 | 0% Низкий | 27 дней назад |
Уязвимостей на страницу