Количество 375 356
Количество 375 356
GHSA-4rh7-jwg9-m28m
openssl-encrypt accepts refresh tokens as URL query parameters causing token leakage
GHSA-4rh7-4h26-629j
The SEO Backlinks WordPress plugin is vulnerable to Cross-Site Request Forgery via the loc_config function found in the ~/seo-backlinks.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 4.0.1.
GHSA-4rh7-2jj4-cgm5
Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the key parameter.
GHSA-4rh6-rgjc-525r
InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to cross-site request forgery when unauthorized commands are submitted from a user the web application trusts. This may allow an attacker to remotely perform actions on the router’s management portal, such as making configuration changes, changing administrator credentials, and running system commands on the router.
GHSA-4rh6-83qm-cfmj
In versions of Akana in versions prior to and including 2022.1.3 validation is broken when using the SAML Single Sign-On (SSO) functionality.
GHSA-4rh6-7h5w-cvjv
NetBSD 3.0, 3.1, and 4.0, when a pppoe instance exists, does not properly check the length of a PPPoE packet tag, which allows remote attackers to cause a denial of service (system crash) via a crafted PPPoE packet.
GHSA-4rh5-mvp3-pqm7
The Panda Video plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.0 via the 'selected_button' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
GHSA-4rh4-3933-r7hw
Potential vulnerabilities have been identified in the audio package for certain HP PC products using the Sound Research SECOMN64 driver, which might allow escalation of privilege. Sound Research has released driver updates to mitigate the potential vulnerabilities.
GHSA-4rh4-3695-hmxr
Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.
GHSA-4rh3-rmh3-hv6h
A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
GHSA-4rgx-hjqw-p9f3
In the Linux kernel, the following vulnerability has been resolved: drm/amd/pm: ensure the fw_info is not null before using it This resolves the dereference null return value warning reported by Coverity.
GHSA-4rgw-hq9r-qp9v
The CMS CORBA listener in SAP BusinessObjects BI Edge 4.0 allows remote attackers to cause a denial of service (server shutdown) via crafted OSCAFactory::Session ORB message.
GHSA-4rgw-cq58-c8v4
admin/index.php in Monstra CMS 3.0.4 allows XSS via the page_meta_title parameter in an edit_page action for a page with no special role.
GHSA-4rgv-cpg8-f3hr
In the Linux kernel, the following vulnerability has been resolved: mm/shmem, swap: fix race of truncate and swap entry split The helper for shmem swap freeing is not handling the order of swap entries correctly. It uses xa_cmpxchg_irq to erase the swap entry, but it gets the entry order before that using xa_get_order without lock protection, and it may get an outdated order value if the entry is split or changed in other ways after the xa_get_order and before the xa_cmpxchg_irq. And besides, the order could grow and be larger than expected, and cause truncation to erase data beyond the end border. For example, if the target entry and following entries are swapped in or freed, then a large folio was added in place and swapped out, using the same entry, the xa_cmpxchg_irq will still succeed, it's very unlikely to happen though. To fix that, open code the Xarray cmpxchg and put the order retrieval and value checking in the same critical section. Also, ensure the order won't exc...
GHSA-4rgr-wmhw-58fg
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Tips and Tricks HQ WP eMember allows Retrieve Embedded Sensitive Data. This issue affects WP eMember: from n/a through v10.2.2.
GHSA-4rgr-v5ff-6hgp
In JetBrains TeamCity before 2023.05.2 a ReDoS attack was possible via integration with issue trackers
GHSA-4rgr-65fh-c67c
The OAuth implementation in librest before 0.7.93 incorrectly truncates the pointer returned by the rest_proxy_call_get_url function, which allows remote attackers to cause a denial of service (application crash) via running the EnsureCredentials method from the org.gnome.OnlineAccounts.Account interface on an object representing a Flickr account.
GHSA-4rgq-6973-6xxh
PVH guests have their ACPI tables constructed by the toolstack. The construction involves building the tables in local memory, which are then copied into guest memory. While actually used parts of the local memory are filled in correctly, excess space that is being allocated is left with its prior contents.
GHSA-4rgq-66fx-5hx2
The cookbible (aka net.bookjam.cookbible) application 1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
GHSA-4rgq-38mh-9xqg
Admidio PKCS#12 private key export action lacks CSRF protection
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4rh7-jwg9-m28m openssl-encrypt accepts refresh tokens as URL query parameters causing token leakage | 6 месяцев назад | |||
GHSA-4rh7-4h26-629j The SEO Backlinks WordPress plugin is vulnerable to Cross-Site Request Forgery via the loc_config function found in the ~/seo-backlinks.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 4.0.1. | 1% Низкий | больше 4 лет назад | ||
GHSA-4rh7-2jj4-cgm5 Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the key parameter. | 2% Низкий | больше 4 лет назад | ||
GHSA-4rh6-rgjc-525r InHand Networks IR615 Router's Versions 2.3.0.r4724 and 2.3.0.r4870 are vulnerable to cross-site request forgery when unauthorized commands are submitted from a user the web application trusts. This may allow an attacker to remotely perform actions on the router’s management portal, such as making configuration changes, changing administrator credentials, and running system commands on the router. | 1% Низкий | больше 4 лет назад | ||
GHSA-4rh6-83qm-cfmj In versions of Akana in versions prior to and including 2022.1.3 validation is broken when using the SAML Single Sign-On (SSO) functionality. | 0% Низкий | около 2 лет назад | ||
GHSA-4rh6-7h5w-cvjv NetBSD 3.0, 3.1, and 4.0, when a pppoe instance exists, does not properly check the length of a PPPoE packet tag, which allows remote attackers to cause a denial of service (system crash) via a crafted PPPoE packet. | 3% Низкий | больше 4 лет назад | ||
GHSA-4rh5-mvp3-pqm7 The Panda Video plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.0 via the 'selected_button' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included. | CVSS3: 8.8 | 1% Низкий | около 2 лет назад | |
GHSA-4rh4-3933-r7hw Potential vulnerabilities have been identified in the audio package for certain HP PC products using the Sound Research SECOMN64 driver, which might allow escalation of privilege. Sound Research has released driver updates to mitigate the potential vulnerabilities. | CVSS3: 8.8 | 0% Низкий | почти 2 года назад | |
GHSA-4rh4-3695-hmxr Use after free in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally. | CVSS3: 7 | 0% Низкий | 2 месяца назад | |
GHSA-4rh3-rmh3-hv6h A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution. | CVSS3: 9.8 | 20% Средний | 3 месяца назад | |
GHSA-4rgx-hjqw-p9f3 In the Linux kernel, the following vulnerability has been resolved: drm/amd/pm: ensure the fw_info is not null before using it This resolves the dereference null return value warning reported by Coverity. | CVSS3: 5.5 | 0% Низкий | почти 2 года назад | |
GHSA-4rgw-hq9r-qp9v The CMS CORBA listener in SAP BusinessObjects BI Edge 4.0 allows remote attackers to cause a denial of service (server shutdown) via crafted OSCAFactory::Session ORB message. | 3% Низкий | больше 4 лет назад | ||
GHSA-4rgw-cq58-c8v4 admin/index.php in Monstra CMS 3.0.4 allows XSS via the page_meta_title parameter in an edit_page action for a page with no special role. | CVSS3: 6.1 | 1% Низкий | больше 4 лет назад | |
GHSA-4rgv-cpg8-f3hr In the Linux kernel, the following vulnerability has been resolved: mm/shmem, swap: fix race of truncate and swap entry split The helper for shmem swap freeing is not handling the order of swap entries correctly. It uses xa_cmpxchg_irq to erase the swap entry, but it gets the entry order before that using xa_get_order without lock protection, and it may get an outdated order value if the entry is split or changed in other ways after the xa_get_order and before the xa_cmpxchg_irq. And besides, the order could grow and be larger than expected, and cause truncation to erase data beyond the end border. For example, if the target entry and following entries are swapped in or freed, then a large folio was added in place and swapped out, using the same entry, the xa_cmpxchg_irq will still succeed, it's very unlikely to happen though. To fix that, open code the Xarray cmpxchg and put the order retrieval and value checking in the same critical section. Also, ensure the order won't exc... | CVSS3: 4.7 | 0% Низкий | 7 месяцев назад | |
GHSA-4rgr-wmhw-58fg Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Tips and Tricks HQ WP eMember allows Retrieve Embedded Sensitive Data. This issue affects WP eMember: from n/a through v10.2.2. | CVSS3: 5.3 | 0% Низкий | 4 месяца назад | |
GHSA-4rgr-v5ff-6hgp In JetBrains TeamCity before 2023.05.2 a ReDoS attack was possible via integration with issue trackers | CVSS3: 4.3 | 2% Низкий | около 3 лет назад | |
GHSA-4rgr-65fh-c67c The OAuth implementation in librest before 0.7.93 incorrectly truncates the pointer returned by the rest_proxy_call_get_url function, which allows remote attackers to cause a denial of service (application crash) via running the EnsureCredentials method from the org.gnome.OnlineAccounts.Account interface on an object representing a Flickr account. | CVSS3: 7.5 | 3% Низкий | больше 4 лет назад | |
GHSA-4rgq-6973-6xxh PVH guests have their ACPI tables constructed by the toolstack. The construction involves building the tables in local memory, which are then copied into guest memory. While actually used parts of the local memory are filled in correctly, excess space that is being allocated is left with its prior contents. | CVSS3: 5.5 | 0% Низкий | почти 2 года назад | |
GHSA-4rgq-66fx-5hx2 The cookbible (aka net.bookjam.cookbible) application 1.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 0% Низкий | больше 4 лет назад | ||
GHSA-4rgq-38mh-9xqg Admidio PKCS#12 private key export action lacks CSRF protection | CVSS3: 4.3 | 0% Низкий | 4 месяца назад |
Уязвимостей на страницу