Количество 374 825
Количество 374 825
GHSA-4pgf-p454-mf4w
The WC Vendors WordPress plugin before 2.7.2.1 does not verify that the vendor submitting a front-end order shipment status change owns the referenced order, allowing any authenticated vendor to mark another vendor's order as shipped, add an order note falsely attributed to the victim vendor, and trigger the customer shipment notification email.
GHSA-4pgf-fm4r-rmf9
ChatterBox 2.0 allows remote attackers to cause a denial of service (server crash) via a malformed request to the server, as demonstrated using "aaaaaa".
GHSA-4pgf-7qx2-4h3r
cgi-bin/sysconf.cgi on the Axesstel MV 410R allows remote attackers to cause a denial of service (configuration reset) via a RESTORE=RESTORE query string.
GHSA-4pgc-mf63-3x2r
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
GHSA-4pgc-gfrr-wcmg
Keycloak has Improper Access Control that allows attackers with valid credentials to bypass the allowRemoteResourceManagement=false
GHSA-4pgc-f487-53cr
Apport does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion, possibly gain root privileges, or escape from containers. The is_same_ns() function returns True when /proc/<global pid>/ does not exist in order to indicate that the crash should be handled in the global namespace rather than inside of a container. However, the portion of the data/apport code that decides whether or not to forward a crash to a container does not always replace sys.argv[1] with the value stored in the host_pid variable when /proc/<global pid>/ does not exist which results in the container pid being used in the global namespace. This flaw affects versions 2.20.8-0ubuntu4 through 2.20.9-0ubuntu7, 2.20.7-0ubuntu3.7, 2.20.7-0ubuntu3.8, 2.20.1-0ubuntu2.15 through 2.20.1-0ubuntu2.17, and 2.14.1-0ubuntu3.28.
GHSA-4pgc-4ghm-q2mf
The Waiting: One-click countdowns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown name in versions up to, and including, 0.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
GHSA-4pg8-p2gr-jw24
IOFireWireFamily in Apple OS X before 10.10.5 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-3769 and CVE-2015-3772.
GHSA-4pg8-m48c-w77f
elitecms v1.01 is vulnerable to Delete any file via /admin/delete_image.php?file=.
GHSA-4pg7-hw8j-rmpq
Tenda AC500 V2.0.1.9(1307) firmware has a stack overflow vulnerability via the timeZone parameter in the formSetTimeZone function.
GHSA-4pg7-2q5x-32w4
An issue in the parseGoosePayload() function (/goose/goose_receiver.c) of libiec61850 v1.6 allows attackers to bypass authentication via a captured GOOSE frame.
GHSA-4pg6-m7g3-m7hm
The States Map US plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'states_map' shortcode in all versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
GHSA-4pg5-xwrq-h998
Ovation FindMe 1.4-1083-1 is intended to support transmission of network traffic from covert video recorders but does not properly disrupt binary analysis for discovering the product's capabilities or purpose. This makes it easier for adversaries to detect the covert operation. Specifically, the product uses a compression technique to prevent the identification of certain libraries in the software by obfuscation. The software relies on a TLS callback and an additional executable file to enable these libraries and their access to certain websites. The unpacked software can be exploited by several different types of documented techniques.
GHSA-4pg5-rffm-vpmp
GE Healthcare Discovery 530C has a password of #bigguy1 for the (1) acqservice user and (2) wsservice user of the Xeleris System, which has unspecified impact and attack vectors. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires a fixed value.
GHSA-4pg5-q3hf-7698
MediaWiki before 1.9.2 allows remote attackers to obtain sensitive information via a direct request to (1) Simple.deps.php, (2) MonoBook.deps.php, (3) MySkin.deps.php, or (4) Chick.deps.php in wiki/skins, which shows the installation path in the resulting error message.
GHSA-4pg5-hx4c-34cx
Missing Authorization vulnerability in Tickera.This issue affects Tickera: from n/a through 3.5.2.6.
GHSA-4pg5-gw5q-8554
Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network.
GHSA-4pg5-c9wr-3p6w
Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over an adjacent network.
GHSA-4pg4-vjj9-4j5w
A vulnerability has been found in NousResearch hermes-agent up to 0.18.2. This affects the function HermesACPAgent.prompt of the file acp_adapter/session.py of the component ACP Prompt Workflow. Such manipulation leads to denial of service. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
GHSA-4pg4-qvpc-4q3h
Multer vulnerable to Denial of Service from maliciously crafted requests
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4pgf-p454-mf4w The WC Vendors WordPress plugin before 2.7.2.1 does not verify that the vendor submitting a front-end order shipment status change owns the referenced order, allowing any authenticated vendor to mark another vendor's order as shipped, add an order note falsely attributed to the victim vendor, and trigger the customer shipment notification email. | CVSS3: 4.3 | 0% Низкий | 17 дней назад | |
GHSA-4pgf-fm4r-rmf9 ChatterBox 2.0 allows remote attackers to cause a denial of service (server crash) via a malformed request to the server, as demonstrated using "aaaaaa". | 2% Низкий | больше 4 лет назад | ||
GHSA-4pgf-7qx2-4h3r cgi-bin/sysconf.cgi on the Axesstel MV 410R allows remote attackers to cause a denial of service (configuration reset) via a RESTORE=RESTORE query string. | 2% Низкий | больше 4 лет назад | ||
GHSA-4pgc-mf63-3x2r Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | CVSS3: 8.8 | 1% Низкий | больше 3 лет назад | |
GHSA-4pgc-gfrr-wcmg Keycloak has Improper Access Control that allows attackers with valid credentials to bypass the allowRemoteResourceManagement=false | CVSS3: 4.3 | 0% Низкий | 6 месяцев назад | |
GHSA-4pgc-f487-53cr Apport does not properly handle crashes originating from a PID namespace allowing local users to create certain files as root which an attacker could leverage to perform a denial of service via resource exhaustion, possibly gain root privileges, or escape from containers. The is_same_ns() function returns True when /proc/<global pid>/ does not exist in order to indicate that the crash should be handled in the global namespace rather than inside of a container. However, the portion of the data/apport code that decides whether or not to forward a crash to a container does not always replace sys.argv[1] with the value stored in the host_pid variable when /proc/<global pid>/ does not exist which results in the container pid being used in the global namespace. This flaw affects versions 2.20.8-0ubuntu4 through 2.20.9-0ubuntu7, 2.20.7-0ubuntu3.7, 2.20.7-0ubuntu3.8, 2.20.1-0ubuntu2.15 through 2.20.1-0ubuntu2.17, and 2.14.1-0ubuntu3.28. | CVSS3: 7.8 | 0% Низкий | больше 4 лет назад | |
GHSA-4pgc-4ghm-q2mf The Waiting: One-click countdowns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown name in versions up to, and including, 0.6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | CVSS3: 5.5 | 0% Низкий | почти 3 года назад | |
GHSA-4pg8-p2gr-jw24 IOFireWireFamily in Apple OS X before 10.10.5 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-3769 and CVE-2015-3772. | 0% Низкий | больше 4 лет назад | ||
GHSA-4pg8-m48c-w77f elitecms v1.01 is vulnerable to Delete any file via /admin/delete_image.php?file=. | CVSS3: 6.5 | 1% Низкий | больше 4 лет назад | |
GHSA-4pg7-hw8j-rmpq Tenda AC500 V2.0.1.9(1307) firmware has a stack overflow vulnerability via the timeZone parameter in the formSetTimeZone function. | CVSS3: 5.9 | 1% Низкий | больше 2 лет назад | |
GHSA-4pg7-2q5x-32w4 An issue in the parseGoosePayload() function (/goose/goose_receiver.c) of libiec61850 v1.6 allows attackers to bypass authentication via a captured GOOSE frame. | CVSS3: 9.8 | 1% Низкий | около 2 месяцев назад | |
GHSA-4pg6-m7g3-m7hm The States Map US plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'states_map' shortcode in all versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | CVSS3: 6.4 | 0% Низкий | почти 2 года назад | |
GHSA-4pg5-xwrq-h998 Ovation FindMe 1.4-1083-1 is intended to support transmission of network traffic from covert video recorders but does not properly disrupt binary analysis for discovering the product's capabilities or purpose. This makes it easier for adversaries to detect the covert operation. Specifically, the product uses a compression technique to prevent the identification of certain libraries in the software by obfuscation. The software relies on a TLS callback and an additional executable file to enable these libraries and their access to certain websites. The unpacked software can be exploited by several different types of documented techniques. | CVSS3: 7.5 | 1% Низкий | больше 4 лет назад | |
GHSA-4pg5-rffm-vpmp GE Healthcare Discovery 530C has a password of #bigguy1 for the (1) acqservice user and (2) wsservice user of the Xeleris System, which has unspecified impact and attack vectors. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires a fixed value. | 2% Низкий | больше 4 лет назад | ||
GHSA-4pg5-q3hf-7698 MediaWiki before 1.9.2 allows remote attackers to obtain sensitive information via a direct request to (1) Simple.deps.php, (2) MonoBook.deps.php, (3) MySkin.deps.php, or (4) Chick.deps.php in wiki/skins, which shows the installation path in the resulting error message. | 2% Низкий | больше 4 лет назад | ||
GHSA-4pg5-hx4c-34cx Missing Authorization vulnerability in Tickera.This issue affects Tickera: from n/a through 3.5.2.6. | CVSS3: 5.3 | 0% Низкий | больше 2 лет назад | |
GHSA-4pg5-gw5q-8554 Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to elevate privileges over a network. | CVSS3: 8.8 | 1% Низкий | около 1 месяца назад | |
GHSA-4pg5-c9wr-3p6w Heap-based buffer overflow in Windows Media allows an unauthorized attacker to execute code over an adjacent network. | CVSS3: 8 | 0% Низкий | около 1 года назад | |
GHSA-4pg4-vjj9-4j5w A vulnerability has been found in NousResearch hermes-agent up to 0.18.2. This affects the function HermesACPAgent.prompt of the file acp_adapter/session.py of the component ACP Prompt Workflow. Such manipulation leads to denial of service. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 4.3 | 0% Низкий | 17 дней назад | |
GHSA-4pg4-qvpc-4q3h Multer vulnerable to Denial of Service from maliciously crafted requests | CVSS3: 7.5 | 1% Низкий | больше 1 года назад |
Уязвимостей на страницу