Количество 375 356
Количество 375 356
GHSA-4r9r-cpgw-cf98
Missing authentication in the SearchStudents method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction sensitive student data by unauthenticated attackers.
GHSA-4r9r-ch6f-vxmx
Picklescan missing detection when calling pytorch function torch.utils.bottleneck.__main__.run_cprofile
GHSA-4r9r-4425-74p7
Cedar-Java has policy injection, type confusion, and incorrect equality comparison vulnerabilities
GHSA-4r9q-wqcj-x85j
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability.
GHSA-4r9q-943r-vw7w
An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the image conversion module when processing metadata in JPEG images. A successful attack can lead to sensitive data exposure.
GHSA-4r9q-4cwx-mg9v
Dell iDRAC 9 prior to version 4.40.40.00 and iDRAC 8 prior to version 2.80.80.80 contain a Stack Buffer Overflow in Racadm. An authenticated remote attacker may potentially exploit this vulnerability to control process execution and gain access to the underlying operating system.
GHSA-4r9q-49xf-jvj3
The Lucas String Replace plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.0.5. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
GHSA-4r9p-m9h5-r8vm
Multiple cross-site scripting (XSS) vulnerabilities in Moodle 1.6.1 and earlier might allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) doc/index.php or (2) files/index.php.
GHSA-4r9p-cvjh-239m
The events-manager plugin before 5.5.7.1 for WordPress has DOM XSS.
GHSA-4r9m-prw4-64m4
SQL injection vulnerability in the Customer Reference List (ref_list) extension 1.0.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
GHSA-4r9m-hpcf-jwxq
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Arigato Autoresponder and Newsletter allows Reflected XSS. This issue affects Arigato Autoresponder and Newsletter: from n/a through 2.7.2.4.
GHSA-4r9m-gmj4-v54c
Multiple integer overflows in memcached 1.1.12 and 1.2.2 allow remote attackers to execute arbitrary code via vectors involving length attributes that trigger heap-based buffer overflows.
GHSA-4r9j-v95c-pgxw
Cross-Site Request Forgery (CSRF) vulnerability in odihost Easy 301 Redirects allows Cross Site Request Forgery. This issue affects Easy 301 Redirects: from n/a through 1.33.
GHSA-4r9h-x77w-mffv
collective.task Cross-site Scripting vulnerability
GHSA-4r9h-gpvv-2xg3
The /dev/block/mmcblk0rpmb driver kernel module on Qiku 360 Phone N6 Pro 1801-A01 devices allows attackers to cause a denial of service (NULL pointer dereference and device crash) via a crafted 0xc0d8b300 ioctl call.
GHSA-4r9h-gm76-v6c4
The Facebook Facts (aka com.wFacebookFacts) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
GHSA-4r9g-w48q-8jwm
HyperDown vulnerable to Cross-site Scripting
GHSA-4r9g-c2fj-783p
In the Linux kernel, the following vulnerability has been resolved: ice: Block switchdev mode when ADQ is active and vice versa ADQ and switchdev are not supported simultaneously. Enabling both at the same time can result in nullptr dereference. To prevent this, check if ADQ is active when changing devlink mode to switchdev mode, and check if switchdev is active when enabling ADQ.
GHSA-4r9f-wq7m-x6mw
Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
GHSA-4r9f-9cvp-xjm7
iManager Admin Console in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 was vulnerable to iFrame manipulation attacks, which could allow remote users to gain access to authentication credentials.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4r9r-cpgw-cf98 Missing authentication in the SearchStudents method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction sensitive student data by unauthenticated attackers. | CVSS3: 7.5 | 1% Низкий | почти 3 года назад | |
GHSA-4r9r-ch6f-vxmx Picklescan missing detection when calling pytorch function torch.utils.bottleneck.__main__.run_cprofile | около 1 года назад | |||
GHSA-4r9r-4425-74p7 Cedar-Java has policy injection, type confusion, and incorrect equality comparison vulnerabilities | CVSS3: 8.8 | 1% Низкий | около 2 месяцев назад | |
GHSA-4r9q-wqcj-x85j Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability. | CVSS3: 7.8 | 99% Критический | больше 4 лет назад | |
GHSA-4r9q-943r-vw7w An issue was discovered in Adobe Acrobat Reader 2018.009.20050 and earlier versions, 2017.011.30070 and earlier versions, 2015.006.30394 and earlier versions. This vulnerability occurs as a result of computation that reads data that is past the end of the target buffer; the computation is part of the image conversion module when processing metadata in JPEG images. A successful attack can lead to sensitive data exposure. | CVSS3: 6.5 | 11% Средний | больше 4 лет назад | |
GHSA-4r9q-4cwx-mg9v Dell iDRAC 9 prior to version 4.40.40.00 and iDRAC 8 prior to version 2.80.80.80 contain a Stack Buffer Overflow in Racadm. An authenticated remote attacker may potentially exploit this vulnerability to control process execution and gain access to the underlying operating system. | CVSS3: 7.2 | 28% Средний | больше 4 лет назад | |
GHSA-4r9q-49xf-jvj3 The Lucas String Replace plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.0.5. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. | CVSS3: 6.1 | 0% Низкий | около 2 лет назад | |
GHSA-4r9p-m9h5-r8vm Multiple cross-site scripting (XSS) vulnerabilities in Moodle 1.6.1 and earlier might allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) doc/index.php or (2) files/index.php. | 1% Низкий | больше 4 лет назад | ||
GHSA-4r9p-cvjh-239m The events-manager plugin before 5.5.7.1 for WordPress has DOM XSS. | CVSS3: 6.1 | 1% Низкий | больше 4 лет назад | |
GHSA-4r9m-prw4-64m4 SQL injection vulnerability in the Customer Reference List (ref_list) extension 1.0.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | 1% Низкий | больше 4 лет назад | ||
GHSA-4r9m-hpcf-jwxq Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Arigato Autoresponder and Newsletter allows Reflected XSS. This issue affects Arigato Autoresponder and Newsletter: from n/a through 2.7.2.4. | CVSS3: 7.1 | 0% Низкий | больше 1 года назад | |
GHSA-4r9m-gmj4-v54c Multiple integer overflows in memcached 1.1.12 and 1.2.2 allow remote attackers to execute arbitrary code via vectors involving length attributes that trigger heap-based buffer overflows. | 7% Низкий | больше 4 лет назад | ||
GHSA-4r9j-v95c-pgxw Cross-Site Request Forgery (CSRF) vulnerability in odihost Easy 301 Redirects allows Cross Site Request Forgery. This issue affects Easy 301 Redirects: from n/a through 1.33. | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
GHSA-4r9h-x77w-mffv collective.task Cross-site Scripting vulnerability | CVSS3: 6.1 | 1% Низкий | почти 4 года назад | |
GHSA-4r9h-gpvv-2xg3 The /dev/block/mmcblk0rpmb driver kernel module on Qiku 360 Phone N6 Pro 1801-A01 devices allows attackers to cause a denial of service (NULL pointer dereference and device crash) via a crafted 0xc0d8b300 ioctl call. | CVSS3: 7.5 | 1% Низкий | больше 4 лет назад | |
GHSA-4r9h-gm76-v6c4 The Facebook Facts (aka com.wFacebookFacts) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 0% Низкий | больше 4 лет назад | ||
GHSA-4r9g-w48q-8jwm HyperDown vulnerable to Cross-site Scripting | CVSS3: 6.1 | 0% Низкий | почти 4 года назад | |
GHSA-4r9g-c2fj-783p In the Linux kernel, the following vulnerability has been resolved: ice: Block switchdev mode when ADQ is active and vice versa ADQ and switchdev are not supported simultaneously. Enabling both at the same time can result in nullptr dereference. To prevent this, check if ADQ is active when changing devlink mode to switchdev mode, and check if switchdev is active when enabling ADQ. | CVSS3: 5.5 | 0% Низкий | около 1 года назад | |
GHSA-4r9f-wq7m-x6mw Integer overflow or wraparound in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | CVSS3: 7.8 | 0% Низкий | 12 дней назад | |
GHSA-4r9f-9cvp-xjm7 iManager Admin Console in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before 4.2.2 was vulnerable to iFrame manipulation attacks, which could allow remote users to gain access to authentication credentials. | CVSS3: 9.8 | 2% Низкий | больше 4 лет назад |
Уязвимостей на страницу