Количество 375 268
Количество 375 268
GHSA-4qqg-wwj3-fxwq
A flaw has been found in itsourcecode Fees Management System 1.0. The impacted element is an unknown function of the file /manage_fee.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used.
GHSA-4qqg-r6qm-rxgh
In getUiccCardsInfo of PhoneInterfaceManager.java, there is a possible permissions bypass due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-146570216
GHSA-4qqg-m5c4-9c3g
Integer underflow in the visual_read function in wiretap/visual.c in Wireshark 1.2.x before 1.2.17 and 1.4.x before 1.4.7 allows remote attackers to cause a denial of service (application crash) via a malformed Visual Networks file that triggers a heap-based buffer over-read.
GHSA-4qqg-523q-3vhc
A vulnerability classified as critical was found in SourceCodester Simple Membership System 1.0. Affected by this vulnerability is an unknown functionality of the file club_validator.php. The manipulation of the argument club leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-239869 was assigned to this vulnerability.
GHSA-4qqf-xjmf-3h2v
Use of password hash with insufficient computational effort vulnerability in QSAN Storage Manager, XEVO, SANOS allows remote attackers to recover the plain-text password by brute-forcing the MD5 hash.
GHSA-4qqf-vxv4-9698
Stack-based buffer overflow in the nestlex function in nestlex.c in Socat 1.5.0.0 through 1.7.1.2 and 2.0.0-b1 through 2.0.0-b3, when bidirectional data relay is enabled, allows context-dependent attackers to execute arbitrary code via long command-line arguments.
GHSA-4qqf-hmv6-r6wh
Use of a Broken or Risky Cryptographic Algorithm in Apache WSS4J
GHSA-4qqf-9m5c-w2c5
Weblate exposes personal IP address via e-mail
GHSA-4qqc-mp5f-ccv4
Command Injection in bestzip
GHSA-4qq9-rrq6-48ff
Cross site scripting in org.apache.nifi:nifi
GHSA-4qq9-qg7j-fcm9
Dolibarr Cross-Site Request Forgery (CSRF)
GHSA-4qq8-xmrv-9779
Out-of-bounds array access issue due to insufficient data verification in the kernel ambient light module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.
GHSA-4qq8-w9wg-4qw8
The tjLoadImage function in libjpeg-turbo 2.0.1 has an integer overflow with a resultant heap-based buffer overflow via a BMP image because multiplication of pitch and height is mishandled, as demonstrated by tjbench.
GHSA-4qq8-w3q5-56jf
Missing authorization vulnerability exists in Unifier and Unifier Cast Version.5.0 or later, and the patch "20240527" not applied. If this vulnerability is exploited, arbitrary code may be executed with LocalSystem privilege. As a result, a malicious program may be installed, data may be modified or deleted.
GHSA-4qq8-cxv5-977h
The Mozilla Maintenance Service updater in Mozilla Firefox before 46.0 on Windows allows user-assisted remote attackers to delete arbitrary files by leveraging certain local file execution.
GHSA-4qq8-38mm-j7jf
Stack-based buffer overflow in Pegasus Mail (PMail) 4.41 and possibly 4.51 allows remote POP3 servers to cause a denial of service (application crash) or possibly execute arbitrary code via a long error message.
GHSA-4qq7-wjm7-pqjr
Microsoft Word 2003 SP3, 2007 SP3, and 2010 SP1; Office Compatibility Pack SP3; and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability."
GHSA-4qq7-cgf7-vrf3
There is Sensitive Information in Cloudera Manager before 5.4.6 Diagnostic Support Bundles.
GHSA-4qq6-r634-f5m4
The HVMOP_set_mem_type control in Xen 4.1 through 4.4.x allows local guest HVM administrators to cause a denial of service (hypervisor crash) or possibly execute arbitrary code by leveraging a separate qemu-dm vulnerability to trigger invalid page table translations for unspecified memory page types.
GHSA-4qq6-2mx2-7x37
Open redirect vulnerability in ui/dynamic/unsecured.html in Linksys EA6500 with firmware 1.1.28.147876 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the target parameter.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4qqg-wwj3-fxwq A flaw has been found in itsourcecode Fees Management System 1.0. The impacted element is an unknown function of the file /manage_fee.php. Executing a manipulation of the argument ID can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used. | CVSS3: 6.3 | 0% Низкий | 4 месяца назад | |
GHSA-4qqg-r6qm-rxgh In getUiccCardsInfo of PhoneInterfaceManager.java, there is a possible permissions bypass due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-146570216 | 0% Низкий | больше 4 лет назад | ||
GHSA-4qqg-m5c4-9c3g Integer underflow in the visual_read function in wiretap/visual.c in Wireshark 1.2.x before 1.2.17 and 1.4.x before 1.4.7 allows remote attackers to cause a denial of service (application crash) via a malformed Visual Networks file that triggers a heap-based buffer over-read. | 2% Низкий | больше 4 лет назад | ||
GHSA-4qqg-523q-3vhc A vulnerability classified as critical was found in SourceCodester Simple Membership System 1.0. Affected by this vulnerability is an unknown functionality of the file club_validator.php. The manipulation of the argument club leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-239869 was assigned to this vulnerability. | CVSS3: 6.3 | 1% Низкий | около 3 лет назад | |
GHSA-4qqf-xjmf-3h2v Use of password hash with insufficient computational effort vulnerability in QSAN Storage Manager, XEVO, SANOS allows remote attackers to recover the plain-text password by brute-forcing the MD5 hash. | 1% Низкий | больше 4 лет назад | ||
GHSA-4qqf-vxv4-9698 Stack-based buffer overflow in the nestlex function in nestlex.c in Socat 1.5.0.0 through 1.7.1.2 and 2.0.0-b1 through 2.0.0-b3, when bidirectional data relay is enabled, allows context-dependent attackers to execute arbitrary code via long command-line arguments. | 3% Низкий | больше 4 лет назад | ||
GHSA-4qqf-hmv6-r6wh Use of a Broken or Risky Cryptographic Algorithm in Apache WSS4J | CVSS3: 5.9 | 2% Низкий | больше 4 лет назад | |
GHSA-4qqf-9m5c-w2c5 Weblate exposes personal IP address via e-mail | CVSS3: 5.3 | 0% Низкий | больше 1 года назад | |
GHSA-4qqc-mp5f-ccv4 Command Injection in bestzip | около 6 лет назад | |||
GHSA-4qq9-rrq6-48ff Cross site scripting in org.apache.nifi:nifi | CVSS3: 6.1 | 3% Низкий | больше 7 лет назад | |
GHSA-4qq9-qg7j-fcm9 Dolibarr Cross-Site Request Forgery (CSRF) | CVSS3: 8 | 1% Низкий | больше 4 лет назад | |
GHSA-4qq8-xmrv-9779 Out-of-bounds array access issue due to insufficient data verification in the kernel ambient light module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. | CVSS3: 6.6 | 0% Низкий | около 1 года назад | |
GHSA-4qq8-w9wg-4qw8 The tjLoadImage function in libjpeg-turbo 2.0.1 has an integer overflow with a resultant heap-based buffer overflow via a BMP image because multiplication of pitch and height is mishandled, as demonstrated by tjbench. | CVSS3: 8.8 | 2% Низкий | больше 4 лет назад | |
GHSA-4qq8-w3q5-56jf Missing authorization vulnerability exists in Unifier and Unifier Cast Version.5.0 or later, and the patch "20240527" not applied. If this vulnerability is exploited, arbitrary code may be executed with LocalSystem privilege. As a result, a malicious program may be installed, data may be modified or deleted. | CVSS3: 9.8 | 1% Низкий | больше 2 лет назад | |
GHSA-4qq8-cxv5-977h The Mozilla Maintenance Service updater in Mozilla Firefox before 46.0 on Windows allows user-assisted remote attackers to delete arbitrary files by leveraging certain local file execution. | CVSS3: 5.5 | 2% Низкий | больше 4 лет назад | |
GHSA-4qq8-38mm-j7jf Stack-based buffer overflow in Pegasus Mail (PMail) 4.41 and possibly 4.51 allows remote POP3 servers to cause a denial of service (application crash) or possibly execute arbitrary code via a long error message. | 6% Низкий | больше 4 лет назад | ||
GHSA-4qq7-wjm7-pqjr Microsoft Word 2003 SP3, 2007 SP3, and 2010 SP1; Office Compatibility Pack SP3; and Word Viewer allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted Office document, aka "Word Memory Corruption Vulnerability." | 20% Средний | больше 4 лет назад | ||
GHSA-4qq7-cgf7-vrf3 There is Sensitive Information in Cloudera Manager before 5.4.6 Diagnostic Support Bundles. | CVSS3: 7.5 | 1% Низкий | больше 4 лет назад | |
GHSA-4qq6-r634-f5m4 The HVMOP_set_mem_type control in Xen 4.1 through 4.4.x allows local guest HVM administrators to cause a denial of service (hypervisor crash) or possibly execute arbitrary code by leveraging a separate qemu-dm vulnerability to trigger invalid page table translations for unspecified memory page types. | 1% Низкий | больше 4 лет назад | ||
GHSA-4qq6-2mx2-7x37 Open redirect vulnerability in ui/dynamic/unsecured.html in Linksys EA6500 with firmware 1.1.28.147876 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the target parameter. | 1% Низкий | больше 4 лет назад |
Уязвимостей на страницу