Количество 375 727
Количество 375 727
GHSA-4w5x-gxff-8vr4
A correctness issue in the JIT was addressed with improved checks. This issue is fixed in tvOS 16.1, iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Processing maliciously crafted web content may disclose internal states of the app.
GHSA-4w5x-gf9f-6rv2
Fiyo CMS 2.0.1.8 allows remote attackers to obtain sensitive information via a direct request to the database backup file in .backup/.
GHSA-4w5x-6pmj-4m2q
NtRegmon before 6.12 allows local users to cause a denial of service (crash), while NtRegmon is running, via invalid pointers to hook functions such as ZwSetQueryValue.
GHSA-4w5w-mw5m-24wp
Subscriber Remote Code Execution (RCE) in RepairBuddy <= 4.1224 versions.
GHSA-4w5w-4fhm-q483
Open Babel has NULL pointer dereference in MOL2 OBAtom::SetFormalCharge
GHSA-4w5w-4c66-6rx9
SAP Adaptive Server Enterprise, before versions 15.7 and 16.0, under certain conditions exposes some sensitive information to the admin, leading to Information Disclosure.
GHSA-4w5v-j6gh-h3v3
Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "name" parameter, potentially leading to unauthorized execution of scripts within a user's web browser.
GHSA-4w5r-xgqv-25rr
Improper neutralization of argument delimiters in a command in Nagios XI 5.7.3 allows a remote, authenticated admin user to write to arbitrary files and ultimately execute code with the privileges of the apache user.
GHSA-4w5r-2wjg-hq97
Vulnerability in the PeopleSoft Enterprise ELM component of Oracle PeopleSoft Products (subcomponent: Enterprise Learning Mgmt). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise ELM. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise ELM accessible data. CVSS 3.0 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).
GHSA-4w5q-x8gv-qmwx
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in miniorange Malware Scanner.This issue affects Malware Scanner: from n/a through 4.7.2.
GHSA-4w5q-r88j-fm53
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress Eduma eduma allows Stored XSS.This issue affects Eduma: from n/a through <= 5.7.6.
GHSA-4w5q-gccf-crf5
The XrayWrapper implementation in Mozilla Firefox before 23.0 and SeaMonkey before 2.20 does not properly address the possibility of an XBL scope bypass resulting from non-native arguments in XBL function calls, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks by leveraging access to an unprivileged object.
GHSA-4w5p-qwh4-xc23
A vulnerability has been found in PHPGurukul Online Nurse Hiring System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/manage-nurse.php. The manipulation of the argument profilepic leads to path traversal: '../filedir'. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory mentions contradicting vulnerability classes.
GHSA-4w5p-p8f5-x7m9
Unauthenticated Sensitive Data Exposure in iCARRY <= 2.9 versions.
GHSA-4w5p-7c62-6g92
A permission issue in BigFix WebUI Insights site version 14 allows an authenticated, unprivileged operator to access an administrator page.
GHSA-4w5m-vg96-g85c
Cross-site scripting (CSS) vulnerability in Lotus Domino 5.0.6 allows remote attackers to execute script on other web clients via a URL that ends in Javascript, which generates an error message that does not quote the resulting script.
GHSA-4w5m-3w7v-8phf
An Argument Injection issue in the plugin management of Etherpad 1.8.13 allows privileged users to execute arbitrary code on the server by installing plugins from an attacker-controlled source.
GHSA-4w5j-fgfj-644h
Avahi before 0.6.15 does not verify the sender identity of netlink messages to ensure that they come from the kernel instead of another process, which allows local users to spoof network changes to Avahi.
GHSA-4w5j-8ww7-64rx
Stack-based buffer overflow in the diagnose service in the Sophos Cyberoam appliances with CyberoamOS before 10.6.1 GA allows remote attackers to execute arbitrary code via a crafted webpage or file.
GHSA-4w5h-pwr8-qh64
A vulnerability in the email parsing module Clam AntiVirus (ClamAV) Software versions 0.102.0, 0.101.4 and prior could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to inefficient MIME parsing routines that result in extremely long scan times of specially formatted email files. An attacker could exploit this vulnerability by sending a crafted email file to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process to scan the crafted email file indefinitely, resulting in a denial of service condition.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4w5x-gxff-8vr4 A correctness issue in the JIT was addressed with improved checks. This issue is fixed in tvOS 16.1, iOS 15.7.1 and iPadOS 15.7.1, macOS Ventura 13, watchOS 9.1, Safari 16.1, iOS 16.1 and iPadOS 16. Processing maliciously crafted web content may disclose internal states of the app. | CVSS3: 6.5 | 1% Низкий | почти 4 года назад | |
GHSA-4w5x-gf9f-6rv2 Fiyo CMS 2.0.1.8 allows remote attackers to obtain sensitive information via a direct request to the database backup file in .backup/. | CVSS3: 7.5 | 8% Низкий | больше 4 лет назад | |
GHSA-4w5x-6pmj-4m2q NtRegmon before 6.12 allows local users to cause a denial of service (crash), while NtRegmon is running, via invalid pointers to hook functions such as ZwSetQueryValue. | 1% Низкий | больше 4 лет назад | ||
GHSA-4w5w-mw5m-24wp Subscriber Remote Code Execution (RCE) in RepairBuddy <= 4.1224 versions. | CVSS3: 7.5 | 0% Низкий | 13 дней назад | |
GHSA-4w5w-4fhm-q483 Open Babel has NULL pointer dereference in MOL2 OBAtom::SetFormalCharge | CVSS3: 5.5 | 1% Низкий | 3 месяца назад | |
GHSA-4w5w-4c66-6rx9 SAP Adaptive Server Enterprise, before versions 15.7 and 16.0, under certain conditions exposes some sensitive information to the admin, leading to Information Disclosure. | 0% Низкий | больше 4 лет назад | ||
GHSA-4w5v-j6gh-h3v3 Os Commerce is currently susceptible to a Cross-Site Scripting (XSS) vulnerability. This vulnerability allows attackers to inject JS through the "name" parameter, potentially leading to unauthorized execution of scripts within a user's web browser. | CVSS3: 8.8 | 0% Низкий | почти 3 года назад | |
GHSA-4w5r-xgqv-25rr Improper neutralization of argument delimiters in a command in Nagios XI 5.7.3 allows a remote, authenticated admin user to write to arbitrary files and ultimately execute code with the privileges of the apache user. | CVSS3: 7.2 | 59% Средний | больше 4 лет назад | |
GHSA-4w5r-2wjg-hq97 Vulnerability in the PeopleSoft Enterprise ELM component of Oracle PeopleSoft Products (subcomponent: Enterprise Learning Mgmt). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise ELM. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise ELM accessible data. CVSS 3.0 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N). | 1% Низкий | больше 4 лет назад | ||
GHSA-4w5q-x8gv-qmwx Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in miniorange Malware Scanner.This issue affects Malware Scanner: from n/a through 4.7.2. | CVSS3: 7.6 | 1% Низкий | больше 2 лет назад | |
GHSA-4w5q-r88j-fm53 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress Eduma eduma allows Stored XSS.This issue affects Eduma: from n/a through <= 5.7.6. | CVSS3: 6.5 | 0% Низкий | 11 месяцев назад | |
GHSA-4w5q-gccf-crf5 The XrayWrapper implementation in Mozilla Firefox before 23.0 and SeaMonkey before 2.20 does not properly address the possibility of an XBL scope bypass resulting from non-native arguments in XBL function calls, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks by leveraging access to an unprivileged object. | 2% Низкий | больше 4 лет назад | ||
GHSA-4w5p-qwh4-xc23 A vulnerability has been found in PHPGurukul Online Nurse Hiring System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/manage-nurse.php. The manipulation of the argument profilepic leads to path traversal: '../filedir'. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory mentions contradicting vulnerability classes. | CVSS3: 6.5 | 1% Низкий | больше 1 года назад | |
GHSA-4w5p-p8f5-x7m9 Unauthenticated Sensitive Data Exposure in iCARRY <= 2.9 versions. | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
GHSA-4w5p-7c62-6g92 A permission issue in BigFix WebUI Insights site version 14 allows an authenticated, unprivileged operator to access an administrator page. | CVSS3: 3 | 0% Низкий | больше 3 лет назад | |
GHSA-4w5m-vg96-g85c Cross-site scripting (CSS) vulnerability in Lotus Domino 5.0.6 allows remote attackers to execute script on other web clients via a URL that ends in Javascript, which generates an error message that does not quote the resulting script. | 4% Низкий | больше 4 лет назад | ||
GHSA-4w5m-3w7v-8phf An Argument Injection issue in the plugin management of Etherpad 1.8.13 allows privileged users to execute arbitrary code on the server by installing plugins from an attacker-controlled source. | 2% Низкий | больше 4 лет назад | ||
GHSA-4w5j-fgfj-644h Avahi before 0.6.15 does not verify the sender identity of netlink messages to ensure that they come from the kernel instead of another process, which allows local users to spoof network changes to Avahi. | 0% Низкий | больше 4 лет назад | ||
GHSA-4w5j-8ww7-64rx Stack-based buffer overflow in the diagnose service in the Sophos Cyberoam appliances with CyberoamOS before 10.6.1 GA allows remote attackers to execute arbitrary code via a crafted webpage or file. | 4% Низкий | больше 4 лет назад | ||
GHSA-4w5h-pwr8-qh64 A vulnerability in the email parsing module Clam AntiVirus (ClamAV) Software versions 0.102.0, 0.101.4 and prior could allow an unauthenticated, remote attacker to cause a denial of service condition on an affected device. The vulnerability is due to inefficient MIME parsing routines that result in extremely long scan times of specially formatted email files. An attacker could exploit this vulnerability by sending a crafted email file to an affected device. An exploit could allow the attacker to cause the ClamAV scanning process to scan the crafted email file indefinitely, resulting in a denial of service condition. | CVSS3: 6.5 | 3% Низкий | больше 4 лет назад |
Уязвимостей на страницу