Количество 374 825
Количество 374 825
GHSA-4ph9-3c4q-r2hh
Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.
GHSA-4ph8-r85v-ggp6
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphics Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-1010, CVE-2018-1013, CVE-2018-1015, CVE-2018-1016.
GHSA-4ph7-5c44-pppv
kajam allows local users to obtain sensitive information by listing the process
GHSA-4ph6-v858-6wh9
huft_build in archival/libarchive/decompress_gunzip.c in BusyBox before 1.27.2 misuses a pointer, causing segfaults and an application crash during an unzip operation on a specially crafted ZIP file.
GHSA-4ph6-mjv7-3fq6
netfoil vulnerable to improper handling of untrusted DoH response data
GHSA-4ph6-9589-22h5
Haakon Nilsen Simple Internet Publishing System (SIPS) 0.2.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain password and other user information via a direct request to a user-specific configuration directory.
GHSA-4ph5-83mw-vm42
A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow(). A client can trigger a use-after-free read after changing window attributes and forcing the screen saver, leading to information disclosure.
GHSA-4ph5-3333-xv3f
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier and 6 Update 35 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment.
GHSA-4ph4-q9r5-6wm6
Deserialization of Untrusted Data in Spring Batch
GHSA-4ph4-gqf8-q98f
Directory traversal vulnerability in shopsessionsubs.asp in Rocksalt International VP-ASP Shopping Cart 6.50 and earlier might allow remote attackers to determine the existence of arbitrary files via directory traversal sequences in the client's DNS hostname (aka the REMOTE_HOST variable), related to the CookielessGenerateFilename and CookielessReadFile functions.
GHSA-4ph4-7xqm-67v8
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CRUDLab Jazz Popups plugin <= 1.8.7 versions.
GHSA-4ph4-5rpm-wrw9
The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration request handler when password authentication has been disabled for the targeted account, allowing an unauthenticated attacker to obtain a valid authentication session as that account, including an administrator, by naming its login in a single registration request.
GHSA-4ph3-v6j7-j4pw
A weakness has been identified in PHPGurukul Online Shopping Portal Project 2.1. This issue affects some unknown processing of the file /sub-category.php of the component Parameter Handler. This manipulation of the argument pid causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.
GHSA-4ph3-7qqh-5h7g
In ss_SendCallBarringPwdRequiredIndMsg of ss_CallBarring.c, there is a possible null pointer deref due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
GHSA-4ph2-f6pf-79wv
PraisonAI Has Arbitrary File Write (Zip Slip) in Templates Extraction
GHSA-4ph2-c8x7-g842
D-Link DIR-601 B1 2.00NA devices are vulnerable to authentication bypass. They do not check for authentication at the server side and rely on client-side validation, which is bypassable. NOTE: this is an end-of-life product.
GHSA-4ph2-8337-hm62
Key Caching behavior in the DynamoDB Encryption Client.
GHSA-4pgx-8hjp-cmmq
openssl_encrypt (pip package openssl-encrypt) before 1.4.9 contains two weaknesses in the portable USB drive feature, whose threat model treats the removable drive as untrusted (attacker with physical write access). USBDriveCreator._verify_integrity_file only validates files listed in the manifest, so files added to the drive — including a root-level autorun payload — are not detected and integrity verification still passes. Additionally, a globally constant, source-embedded KDF salt (_LEGACY_FIXED_SALT) is used to derive the drive encryption key for any drive lacking a per-drive salt file, defeating precomputation resistance and enabling an offline rainbow-table attack.
GHSA-4pgv-p58j-ghpx
Apport argument parsing mishandles filename splitting on older kernels resulting in argument spoofing
GHSA-4pgr-wr6g-rxf6
When the ClickHouse plugin uses Native protocol (the default) with PDC or secure SOCKS, it asks for TLS but the connection library ignores that and talks to ClickHouse in the clear. Username, password, queries, and results can be read on the hop after the proxy. The server certificate is never checked, and a configured client certificate is not sent.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4ph9-3c4q-r2hh Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message. | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
GHSA-4ph8-r85v-ggp6 A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts, aka "Microsoft Graphics Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-1010, CVE-2018-1013, CVE-2018-1015, CVE-2018-1016. | CVSS3: 8.8 | 24% Средний | больше 4 лет назад | |
GHSA-4ph7-5c44-pppv kajam allows local users to obtain sensitive information by listing the process | CVSS3: 7.8 | 1% Низкий | больше 4 лет назад | |
GHSA-4ph6-v858-6wh9 huft_build in archival/libarchive/decompress_gunzip.c in BusyBox before 1.27.2 misuses a pointer, causing segfaults and an application crash during an unzip operation on a specially crafted ZIP file. | CVSS3: 5.5 | 2% Низкий | больше 4 лет назад | |
GHSA-4ph6-mjv7-3fq6 netfoil vulnerable to improper handling of untrusted DoH response data | 25 дней назад | |||
GHSA-4ph6-9589-22h5 Haakon Nilsen Simple Internet Publishing System (SIPS) 0.2.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain password and other user information via a direct request to a user-specific configuration directory. | 2% Низкий | больше 4 лет назад | ||
GHSA-4ph5-83mw-vm42 A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow(). A client can trigger a use-after-free read after changing window attributes and forcing the screen saver, leading to information disclosure. | CVSS3: 5.5 | 0% Низкий | 4 месяца назад | |
GHSA-4ph5-3333-xv3f Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier and 6 Update 35 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Deployment. | 6% Низкий | больше 4 лет назад | ||
GHSA-4ph4-q9r5-6wm6 Deserialization of Untrusted Data in Spring Batch | CVSS3: 8.1 | 2% Низкий | больше 4 лет назад | |
GHSA-4ph4-gqf8-q98f Directory traversal vulnerability in shopsessionsubs.asp in Rocksalt International VP-ASP Shopping Cart 6.50 and earlier might allow remote attackers to determine the existence of arbitrary files via directory traversal sequences in the client's DNS hostname (aka the REMOTE_HOST variable), related to the CookielessGenerateFilename and CookielessReadFile functions. | 2% Низкий | больше 4 лет назад | ||
GHSA-4ph4-7xqm-67v8 Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in CRUDLab Jazz Popups plugin <= 1.8.7 versions. | CVSS3: 7.1 | 0% Низкий | около 3 лет назад | |
GHSA-4ph4-5rpm-wrw9 The MainWP Child WordPress plugin before 6.1.2 does not verify the requester's identity in its site-registration request handler when password authentication has been disabled for the targeted account, allowing an unauthenticated attacker to obtain a valid authentication session as that account, including an administrator, by naming its login in a single registration request. | CVSS3: 8.1 | 0% Низкий | около 2 месяцев назад | |
GHSA-4ph3-v6j7-j4pw A weakness has been identified in PHPGurukul Online Shopping Portal Project 2.1. This issue affects some unknown processing of the file /sub-category.php of the component Parameter Handler. This manipulation of the argument pid causes sql injection. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks. | CVSS3: 6.3 | 0% Низкий | 6 месяцев назад | |
GHSA-4ph3-7qqh-5h7g In ss_SendCallBarringPwdRequiredIndMsg of ss_CallBarring.c, there is a possible null pointer deref due to a missing null check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. | CVSS3: 7.5 | 0% Низкий | больше 2 лет назад | |
GHSA-4ph2-f6pf-79wv PraisonAI Has Arbitrary File Write (Zip Slip) in Templates Extraction | CVSS3: 8.1 | 0% Низкий | 5 месяцев назад | |
GHSA-4ph2-c8x7-g842 D-Link DIR-601 B1 2.00NA devices are vulnerable to authentication bypass. They do not check for authentication at the server side and rely on client-side validation, which is bypassable. NOTE: this is an end-of-life product. | 2% Низкий | больше 4 лет назад | ||
GHSA-4ph2-8337-hm62 Key Caching behavior in the DynamoDB Encryption Client. | больше 5 лет назад | |||
GHSA-4pgx-8hjp-cmmq openssl_encrypt (pip package openssl-encrypt) before 1.4.9 contains two weaknesses in the portable USB drive feature, whose threat model treats the removable drive as untrusted (attacker with physical write access). USBDriveCreator._verify_integrity_file only validates files listed in the manifest, so files added to the drive — including a root-level autorun payload — are not detected and integrity verification still passes. Additionally, a globally constant, source-embedded KDF salt (_LEGACY_FIXED_SALT) is used to derive the drive encryption key for any drive lacking a per-drive salt file, defeating precomputation resistance and enabling an offline rainbow-table attack. | CVSS3: 3.5 | 0% Низкий | 22 дня назад | |
GHSA-4pgv-p58j-ghpx Apport argument parsing mishandles filename splitting on older kernels resulting in argument spoofing | CVSS3: 5.5 | 0% Низкий | больше 2 лет назад | |
GHSA-4pgr-wr6g-rxf6 When the ClickHouse plugin uses Native protocol (the default) with PDC or secure SOCKS, it asks for TLS but the connection library ignores that and talks to ClickHouse in the clear. Username, password, queries, and results can be read on the hop after the proxy. The server certificate is never checked, and a configured client certificate is not sent. | CVSS3: 6.1 | 0% Низкий | 22 дня назад |
Уязвимостей на страницу