Количество 375 268
Количество 375 268
GHSA-4qgp-9xhq-8w3j
Product: AndroidVersions: Android kernelAndroid ID: A-211162353References: N/A
GHSA-4qgp-72gr-jfg9
libxml2 through 2.9.1 does not properly handle external entities expansion unless an application developer uses the xmlSAX2ResolveEntity or xmlSetExternalEntityLoader function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, aka an XML External Entity (XXE) issue. NOTE: it could be argued that because libxml2 already provides the ability to disable external entity expansion, the responsibility for resolving this issue lies with application developers; according to this argument, this entry should be REJECTed and each affected application would need its own CVE.
GHSA-4qgm-jgjc-wjvj
Multiple cross-site scripting (XSS) vulnerabilities in ViewCVS 0.9.2 allow remote attackers to inject arbitrary HTML and web script via certain error messages.
GHSA-4qgj-c63p-26g3
The Vchasno Kasa plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the clear_all_log() function in all versions up to, and including, 1.0.3. This makes it possible for unauthenticated attackers to clear log files.
GHSA-4qgj-9mvg-3929
Special top object can be used to access Struts' internals
GHSA-4qgj-3gq9-2chf
RSA BSAFE Crypto-C Micro Edition, versions prior to 4.0.5.3 (in 4.0.x) and versions prior to 4.1.3.3 (in 4.1.x), and RSA Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) versions prior to 4.1.6.1 (in 4.1.x) and versions prior to 4.3.3 (4.2.x and 4.3.x) are vulnerable to an Information Exposure Through Timing Discrepancy. A malicious remote user could potentially exploit this vulnerability to extract information leaving data at risk of exposure.
GHSA-4qgh-qg2j-6vjw
Brickcom cameras ship with default credentials that allows any unauthenticated remote attacker to silently access camera feeds.
GHSA-4qgh-m9vp-48xp
MunkiReport Software Update module is vulnerable to SQL injection
GHSA-4qgh-f523-xm3p
An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. iTunes before 12.7 on Windows is affected. tvOS before 11 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.
GHSA-4qgh-57c7-qfq2
Buffer overflow in some Zoom Workplace Apps and SDK’s may allow an authenticated user to conduct a denial of service via network access.
GHSA-4qgg-qpcp-jx3h
SQL injection vulnerability in verify.asp in Asp-rider allows remote attackers to execute arbitrary SQL statements and bypass authentication via the username parameter.
GHSA-4qgf-3m3q-8xm4
In JetBrains IntelliJ IDEA before 2025.3 missing confirmation allowed opening of untrusted remote projects over SSH
GHSA-4qgc-r788-x389
Buffer overflow in the HTTP Plugin (xineplug_inp_http.so) for xine-lib 1.1.1 allows remote attackers to cause a denial of service (application crash) via a long reply from an HTTP server, as demonstrated using gxine 0.5.6.
GHSA-4qgc-qr9j-76rw
Kotaemon through 0.12.0 fails to properly validate conversation ownership in select_conv, delete_conv, rename_conv, and on_set_public_conversation functions in control.py. Attackers can read other users' chat histories, delete conversations, or rename conversations by supplying arbitrary conversation identifiers without proper authorization checks.
GHSA-4qgc-h55q-cm8r
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in gVectors Team wpForo Forum allows Code Injection.This issue affects wpForo Forum: from n/a through 2.2.5.
GHSA-4qg9-qqgj-hw85
spice-gtk 0.14, and possibly other versions, invokes the polkit authority using the insecure polkit_unix_process_new API function, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288.
GHSA-4qg9-fgqh-4wmj
Cybozu Office 10.0.0 to 10.8.3 allows remote authenticated attackers to bypass access restriction which may result in obtaining data without access privileges via the application 'Address'.
GHSA-4qg8-fj49-pxjh
Sigstore Timestamp Authority allocates excessive memory during request parsing
GHSA-4qg6-p4v4-grqc
Untrusted search path vulnerability in installer of ChatWork Desktop App for Windows 2.3.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
GHSA-4qg5-cxx4-g927
Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4qgp-9xhq-8w3j Product: AndroidVersions: Android kernelAndroid ID: A-211162353References: N/A | CVSS3: 7.5 | 0% Низкий | больше 4 лет назад | |
GHSA-4qgp-72gr-jfg9 libxml2 through 2.9.1 does not properly handle external entities expansion unless an application developer uses the xmlSAX2ResolveEntity or xmlSetExternalEntityLoader function, which allows remote attackers to cause a denial of service (resource consumption), send HTTP requests to intranet servers, or read arbitrary files via a crafted XML document, aka an XML External Entity (XXE) issue. NOTE: it could be argued that because libxml2 already provides the ability to disable external entity expansion, the responsibility for resolving this issue lies with application developers; according to this argument, this entry should be REJECTed and each affected application would need its own CVE. | 4% Низкий | больше 4 лет назад | ||
GHSA-4qgm-jgjc-wjvj Multiple cross-site scripting (XSS) vulnerabilities in ViewCVS 0.9.2 allow remote attackers to inject arbitrary HTML and web script via certain error messages. | 1% Низкий | больше 4 лет назад | ||
GHSA-4qgj-c63p-26g3 The Vchasno Kasa plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the clear_all_log() function in all versions up to, and including, 1.0.3. This makes it possible for unauthenticated attackers to clear log files. | CVSS3: 5.3 | 0% Низкий | около 1 года назад | |
GHSA-4qgj-9mvg-3929 Special top object can be used to access Struts' internals | CVSS3: 7.5 | 9% Низкий | больше 4 лет назад | |
GHSA-4qgj-3gq9-2chf RSA BSAFE Crypto-C Micro Edition, versions prior to 4.0.5.3 (in 4.0.x) and versions prior to 4.1.3.3 (in 4.1.x), and RSA Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) versions prior to 4.1.6.1 (in 4.1.x) and versions prior to 4.3.3 (4.2.x and 4.3.x) are vulnerable to an Information Exposure Through Timing Discrepancy. A malicious remote user could potentially exploit this vulnerability to extract information leaving data at risk of exposure. | CVSS3: 7.5 | 1% Низкий | больше 4 лет назад | |
GHSA-4qgh-qg2j-6vjw Brickcom cameras ship with default credentials that allows any unauthenticated remote attacker to silently access camera feeds. | CVSS3: 7.7 | 0% Низкий | 3 месяца назад | |
GHSA-4qgh-m9vp-48xp MunkiReport Software Update module is vulnerable to SQL injection | CVSS3: 8.8 | 1% Низкий | больше 4 лет назад | |
GHSA-4qgh-f523-xm3p An issue was discovered in certain Apple products. iOS before 11 is affected. Safari before 11 is affected. iCloud before 7.0 on Windows is affected. iTunes before 12.7 on Windows is affected. tvOS before 11 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. | CVSS3: 8.8 | 10% Средний | больше 4 лет назад | |
GHSA-4qgh-57c7-qfq2 Buffer overflow in some Zoom Workplace Apps and SDK’s may allow an authenticated user to conduct a denial of service via network access. | CVSS3: 6.5 | 0% Низкий | больше 2 лет назад | |
GHSA-4qgg-qpcp-jx3h SQL injection vulnerability in verify.asp in Asp-rider allows remote attackers to execute arbitrary SQL statements and bypass authentication via the username parameter. | 3% Низкий | больше 4 лет назад | ||
GHSA-4qgf-3m3q-8xm4 In JetBrains IntelliJ IDEA before 2025.3 missing confirmation allowed opening of untrusted remote projects over SSH | CVSS3: 5.4 | 0% Низкий | 9 месяцев назад | |
GHSA-4qgc-r788-x389 Buffer overflow in the HTTP Plugin (xineplug_inp_http.so) for xine-lib 1.1.1 allows remote attackers to cause a denial of service (application crash) via a long reply from an HTTP server, as demonstrated using gxine 0.5.6. | 11% Средний | больше 4 лет назад | ||
GHSA-4qgc-qr9j-76rw Kotaemon through 0.12.0 fails to properly validate conversation ownership in select_conv, delete_conv, rename_conv, and on_set_public_conversation functions in control.py. Attackers can read other users' chat histories, delete conversations, or rename conversations by supplying arbitrary conversation identifiers without proper authorization checks. | CVSS3: 7.4 | 0% Низкий | 22 дня назад | |
GHSA-4qgc-h55q-cm8r Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in gVectors Team wpForo Forum allows Code Injection.This issue affects wpForo Forum: from n/a through 2.2.5. | CVSS3: 4.3 | 0% Низкий | почти 2 года назад | |
GHSA-4qg9-qqgj-hw85 spice-gtk 0.14, and possibly other versions, invokes the polkit authority using the insecure polkit_unix_process_new API function, which allows local users to bypass intended access restrictions by leveraging a PolkitUnixProcess PolkitSubject race condition via a (1) setuid process or (2) pkexec process, a related issue to CVE-2013-4288. | 0% Низкий | больше 4 лет назад | ||
GHSA-4qg9-fgqh-4wmj Cybozu Office 10.0.0 to 10.8.3 allows remote authenticated attackers to bypass access restriction which may result in obtaining data without access privileges via the application 'Address'. | 1% Низкий | больше 4 лет назад | ||
GHSA-4qg8-fj49-pxjh Sigstore Timestamp Authority allocates excessive memory during request parsing | CVSS3: 7.5 | 0% Низкий | 10 месяцев назад | |
GHSA-4qg6-p4v4-grqc Untrusted search path vulnerability in installer of ChatWork Desktop App for Windows 2.3.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | CVSS3: 7.8 | 1% Низкий | больше 4 лет назад | |
GHSA-4qg5-cxx4-g927 Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchange | CVSS3: 6.5 | 0% Низкий | 9 дней назад |
Уязвимостей на страницу