Количество 374 825
Количество 374 825
GHSA-4pf2-37p5-x5fg
Photoshop Mobile is affected by a Session Fixation vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain access to sensitive resources. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must interact with a malicious webpage. Scope is changed.
GHSA-4pcx-rr5j-rxx3
IBC Solar ServeMaster TLP+ and Danfoss TLX Pro+ allow remote attackers to discover cleartext passwords by reading HTML source code.
GHSA-4pcx-m3hv-2jw5
Missing Authorization vulnerability in Stylemix Cost Calculator Builder cost-calculator-builder.This issue affects Cost Calculator Builder: from n/a through <= 3.5.32.
GHSA-4pcw-2chr-m4jj
Xen allows local OS guest users to cause a denial of service (crash) or possibly obtain sensitive information or gain privileges via vectors involving transitive grants.
GHSA-4pcv-mg8v-vrgf
PraisonAI: Server-Side Request Forgery (SSRF) in SearxNG / search_web tools via attacker-controlled searxng_url parameter
GHSA-4pcv-m5q3-f7q7
Microsoft InfoPath 2007 SP3, 2010 SP2, and 2013 SP1 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
GHSA-4pcr-226x-2w24
In memory management driver, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue ID: ALPS05336700.
GHSA-4pcq-7rw3-2jvx
In the autofill service, the package name that is provided by the app process is trusted inappropriately. This could lead to information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
GHSA-4pcp-h2jw-cp6p
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 could disclose sensitive database information to a privileged user.
GHSA-4pcp-9v53-4m7x
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
GHSA-4pcm-h7xx-qpcq
In valid_out_of_special_sec_dram_addr of drm_access_control.c, there is a possible EoP due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-238716781References: N/A
GHSA-4pcm-9qq9-65qc
IIS 4.0 and 5.0 allows remote attackers to obtain fragments of source code by appending a +.htr to the URL, a variant of the "File Fragment Reading via .HTR" vulnerability.
GHSA-4pcj-vr36-r5w4
In ImageMagick before 6.9.8-5 and 7.x before 7.0.5-6, there is a memory leak in the ReadMATImage function in coders/mat.c.
GHSA-4pcj-qpx3-mjmx
An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH does not honor revoked authorizer access. A URLAUTH URL minted while the authorizer had access continued to work after that access was revoked.
GHSA-4pcj-2vcf-4q8j
A security flaw has been discovered in SourceCodester Hotel Reservation System 1.0. This affects an unknown part of the file /admin/updateabout.php. The manipulation of the argument address results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be exploited.
GHSA-4pch-258r-x42r
Multiple SQL injection vulnerabilities in phpbb-Auction allow remote attackers to execute arbitrary SQL commands via the (1) u parameter to auction_rating.php or (2) ar parameter to action_offer.php.
GHSA-4pcg-wr6c-h9cq
fastify/websocket vulnerable to uncaught exception via crash on malformed packet
GHSA-4pcg-pjp5-3mc6
Concrete CMS vulnerable to Reflected Cross-Site Scripting (XSS) in Conversation Messages Dashboard Page
GHSA-4pcg-mhp2-2qh7
Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.
GHSA-4pcg-gfm2-cvg4
An improper access control flaw was found in Candlepin. An attacker can create data scoped under another customer/tenant, which can result in loss of confidentiality and availability for the affected customer/tenant.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4pf2-37p5-x5fg Photoshop Mobile is affected by a Session Fixation vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain access to sensitive resources. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must interact with a malicious webpage. Scope is changed. | CVSS3: 7.4 | 0% Низкий | 10 дней назад | |
GHSA-4pcx-rr5j-rxx3 IBC Solar ServeMaster TLP+ and Danfoss TLX Pro+ allow remote attackers to discover cleartext passwords by reading HTML source code. | 1% Низкий | больше 4 лет назад | ||
GHSA-4pcx-m3hv-2jw5 Missing Authorization vulnerability in Stylemix Cost Calculator Builder cost-calculator-builder.This issue affects Cost Calculator Builder: from n/a through <= 3.5.32. | CVSS3: 6.5 | 0% Низкий | 11 месяцев назад | |
GHSA-4pcw-2chr-m4jj Xen allows local OS guest users to cause a denial of service (crash) or possibly obtain sensitive information or gain privileges via vectors involving transitive grants. | CVSS3: 8.8 | 0% Низкий | больше 4 лет назад | |
GHSA-4pcv-mg8v-vrgf PraisonAI: Server-Side Request Forgery (SSRF) in SearxNG / search_web tools via attacker-controlled searxng_url parameter | CVSS3: 8.8 | 3 месяца назад | ||
GHSA-4pcv-m5q3-f7q7 Microsoft InfoPath 2007 SP3, 2010 SP2, and 2013 SP1 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability." | CVSS3: 7.8 | 24% Средний | больше 4 лет назад | |
GHSA-4pcr-226x-2w24 In memory management driver, there is a possible system crash due to improper input validation. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05403499; Issue ID: ALPS05336700. | 0% Низкий | больше 4 лет назад | ||
GHSA-4pcq-7rw3-2jvx In the autofill service, the package name that is provided by the app process is trusted inappropriately. This could lead to information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | CVSS3: 5.5 | 0% Низкий | почти 2 года назад | |
GHSA-4pcp-h2jw-cp6p IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.6 and 6.2.0.0 through 6.2.0.3 could disclose sensitive database information to a privileged user. | CVSS3: 2.7 | 0% Низкий | больше 1 года назад | |
GHSA-4pcp-9v53-4m7x Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | CVSS3: 8 | 2% Низкий | 10 месяцев назад | |
GHSA-4pcm-h7xx-qpcq In valid_out_of_special_sec_dram_addr of drm_access_control.c, there is a possible EoP due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-238716781References: N/A | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-4pcm-9qq9-65qc IIS 4.0 and 5.0 allows remote attackers to obtain fragments of source code by appending a +.htr to the URL, a variant of the "File Fragment Reading via .HTR" vulnerability. | 68% Средний | больше 4 лет назад | ||
GHSA-4pcj-vr36-r5w4 In ImageMagick before 6.9.8-5 and 7.x before 7.0.5-6, there is a memory leak in the ReadMATImage function in coders/mat.c. | CVSS3: 8.8 | 1% Низкий | больше 4 лет назад | |
GHSA-4pcj-qpx3-mjmx An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH does not honor revoked authorizer access. A URLAUTH URL minted while the authorizer had access continued to work after that access was revoked. | CVSS3: 3.5 | 0% Низкий | 2 месяца назад | |
GHSA-4pcj-2vcf-4q8j A security flaw has been discovered in SourceCodester Hotel Reservation System 1.0. This affects an unknown part of the file /admin/updateabout.php. The manipulation of the argument address results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be exploited. | CVSS3: 7.3 | 0% Низкий | около 1 года назад | |
GHSA-4pch-258r-x42r Multiple SQL injection vulnerabilities in phpbb-Auction allow remote attackers to execute arbitrary SQL commands via the (1) u parameter to auction_rating.php or (2) ar parameter to action_offer.php. | 2% Низкий | больше 4 лет назад | ||
GHSA-4pcg-wr6c-h9cq fastify/websocket vulnerable to uncaught exception via crash on malformed packet | CVSS3: 7.5 | 1% Низкий | почти 4 года назад | |
GHSA-4pcg-pjp5-3mc6 Concrete CMS vulnerable to Reflected Cross-Site Scripting (XSS) in Conversation Messages Dashboard Page | 0% Низкий | около 1 года назад | ||
GHSA-4pcg-mhp2-2qh7 Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure. | 9 месяцев назад | |||
GHSA-4pcg-gfm2-cvg4 An improper access control flaw was found in Candlepin. An attacker can create data scoped under another customer/tenant, which can result in loss of confidentiality and availability for the affected customer/tenant. | CVSS3: 6.8 | 1% Низкий | почти 3 года назад |
Уязвимостей на страницу