Количество 373 528
Количество 373 528
GHSA-4jpc-fv5p-mh98
Improper input validation of a large HTTP request in the Controller 6000 and Controller 7000 optional diagnostic web interface (Port 80) can be used to perform a Denial of Service of the diagnostic web interface. This issue affects: Gallagher Controller 6000 and 7000 8.90 prior to vCR8.90.231204a (distributed in 8.90.1620 (MR2)), 8.80 prior to vCR8.80.231204a (distributed in 8.80.1369 (MR3)), 8.70 prior to vCR8.70.231204a (distributed in 8.70.2375 (MR5)), 8.60 prior to vCR8.60.231116a (distributed in 8.60.2550 (MR7)), all versions of 8.50 and prior.
GHSA-4jp9-q9g7-48gr
When handling keypress events, an attacker may have been able to trick a user into bypassing the "Open Executable File?" confirmation dialog. This could have led to malicious code execution. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5.
GHSA-4jp9-m29w-rpw2
SQL injection vulnerability in usercp.php in MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL commands via the awayday parameter.
GHSA-4jp8-fm2m-q8mc
The AV1_DuplicateConfig function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command.
GHSA-4jp8-75fv-797w
Stack-based buffer overflow in the Read32s_64 function in src/lib/cdfread64.c in the NASA Goddard Space Flight Center Common Data Format (CDF) library before 3.2.1 allows context-dependent attackers to execute arbitrary code via a .cdf file with crafted length tags.
GHSA-4jp7-8p85-rpc6
WordPress plugin wp-cleanfix has Remote Code Execution
GHSA-4jp6-449x-6fgh
The SyncThru Web Service on Samsung SCX-6x55X printers allows an attacker to gain access to a list of SMB users and cleartext passwords by reading the HTML source code. Authentication is not required.
GHSA-4jp5-cwfh-cp99
Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. This is similar to, but not identical to CVE-2023-32532 through 32535.
GHSA-4jp4-vqwc-qh78
Multiple out-of-bounds read and write vulnerabilities exist in the ControlVault WBDI Driver Broadcom Storage Adapter functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted WinBioControlUnit call can lead to memory corruption. An attacker can issue an api call to trigger this vulnerability. This vulnerability is triggered when submitting a `WinBioControlUnit` call to the StorageAdapter with the ControlCode 3 (`WBIO_USH_CREATE_CHALLENGE`) and with `0 < ReceiveBuferSize < 4`. Up to three null-bytes will be written past the end of the `ReceiveBuffer`.
GHSA-4jp4-3xh6-74m2
Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N).
GHSA-4jp4-3c62-r8jv
OpenStack Glance Denial of service by creating a large number of images
GHSA-4jp3-q2qm-9fmw
Improper Restriction of Rendered UI Layers or Frames in Sylius
GHSA-4jp2-rjmj-344p
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Atarim Visual Website Collaboration, Feedback & Project Management – Atarim plugin <= 3.9.3 versions.
GHSA-4jmv-x65v-w43v
Dimension versions 4.1.4 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
GHSA-4jmv-jvrv-qcv7
Uncontrolled resource consumption in Zoom Team Chat for Zoom Desktop Client for Windows and Zoom VDI Client may allow an unauthenticated user to conduct a disclosure of information via network access.
GHSA-4jmv-9vjw-mj58
Dell PowerStore contains an Argument Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to gain unauthorized access to sensitive sensitive system information.
GHSA-4jmv-526x-2x7f
Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Collaboration before 8.7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka bugs 104552 and 104703.
GHSA-4jmv-3f44-7558
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
GHSA-4jmr-68h5-qq5j
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16663.
GHSA-4jmq-69hm-3jp3
Tanium addressed a use-after-free vulnerability in the Cloud Workloads Enforce client extension.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4jpc-fv5p-mh98 Improper input validation of a large HTTP request in the Controller 6000 and Controller 7000 optional diagnostic web interface (Port 80) can be used to perform a Denial of Service of the diagnostic web interface. This issue affects: Gallagher Controller 6000 and 7000 8.90 prior to vCR8.90.231204a (distributed in 8.90.1620 (MR2)), 8.80 prior to vCR8.80.231204a (distributed in 8.80.1369 (MR3)), 8.70 prior to vCR8.70.231204a (distributed in 8.70.2375 (MR5)), 8.60 prior to vCR8.60.231116a (distributed in 8.60.2550 (MR7)), all versions of 8.50 and prior. | CVSS3: 3.1 | 1% Низкий | больше 2 лет назад | |
GHSA-4jp9-q9g7-48gr When handling keypress events, an attacker may have been able to trick a user into bypassing the "Open Executable File?" confirmation dialog. This could have led to malicious code execution. This vulnerability affects Firefox < 133, Firefox ESR < 128.5, Thunderbird < 133, and Thunderbird < 128.5. | CVSS3: 8.8 | 1% Низкий | почти 2 года назад | |
GHSA-4jp9-m29w-rpw2 SQL injection vulnerability in usercp.php in MyBulletinBoard (MyBB) allows remote attackers to execute arbitrary SQL commands via the awayday parameter. | 2% Низкий | больше 4 лет назад | ||
GHSA-4jp8-fm2m-q8mc The AV1_DuplicateConfig function in GPAC 1.0.1 allows attackers to cause a denial of service (NULL pointer dereference) via a crafted file in the MP4Box command. | 1% Низкий | больше 4 лет назад | ||
GHSA-4jp8-75fv-797w Stack-based buffer overflow in the Read32s_64 function in src/lib/cdfread64.c in the NASA Goddard Space Flight Center Common Data Format (CDF) library before 3.2.1 allows context-dependent attackers to execute arbitrary code via a .cdf file with crafted length tags. | 4% Низкий | больше 4 лет назад | ||
GHSA-4jp7-8p85-rpc6 WordPress plugin wp-cleanfix has Remote Code Execution | 2% Низкий | больше 4 лет назад | ||
GHSA-4jp6-449x-6fgh The SyncThru Web Service on Samsung SCX-6x55X printers allows an attacker to gain access to a list of SMB users and cleartext passwords by reading the HTML source code. Authentication is not required. | CVSS3: 7.5 | 2% Низкий | больше 4 лет назад | |
GHSA-4jp5-cwfh-cp99 Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. This is similar to, but not identical to CVE-2023-32532 through 32535. | CVSS3: 6.1 | 2% Низкий | около 3 лет назад | |
GHSA-4jp4-vqwc-qh78 Multiple out-of-bounds read and write vulnerabilities exist in the ControlVault WBDI Driver Broadcom Storage Adapter functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted WinBioControlUnit call can lead to memory corruption. An attacker can issue an api call to trigger this vulnerability. This vulnerability is triggered when submitting a `WinBioControlUnit` call to the StorageAdapter with the ControlCode 3 (`WBIO_USH_CREATE_CHALLENGE`) and with `0 < ReceiveBuferSize < 4`. Up to three null-bytes will be written past the end of the `ReceiveBuffer`. | CVSS3: 7.3 | 0% Низкий | 10 месяцев назад | |
GHSA-4jp4-3xh6-74m2 Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Hyperion Financial Management. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Hyperion Financial Management accessible data. CVSS 3.1 Base Score 4.4 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N). | CVSS3: 4.4 | 0% Низкий | 30 дней назад | |
GHSA-4jp4-3c62-r8jv OpenStack Glance Denial of service by creating a large number of images | CVSS3: 7.5 | 2% Низкий | больше 4 лет назад | |
GHSA-4jp3-q2qm-9fmw Improper Restriction of Rendered UI Layers or Frames in Sylius | CVSS3: 6.1 | 1% Низкий | больше 4 лет назад | |
GHSA-4jp2-rjmj-344p Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Atarim Visual Website Collaboration, Feedback & Project Management – Atarim plugin <= 3.9.3 versions. | CVSS3: 7.1 | 0% Низкий | около 3 лет назад | |
GHSA-4jmv-x65v-w43v Dimension versions 4.1.4 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | CVSS3: 7.8 | 0% Низкий | 11 месяцев назад | |
GHSA-4jmv-jvrv-qcv7 Uncontrolled resource consumption in Zoom Team Chat for Zoom Desktop Client for Windows and Zoom VDI Client may allow an unauthenticated user to conduct a disclosure of information via network access. | CVSS3: 4.3 | 1% Низкий | почти 3 года назад | |
GHSA-4jmv-9vjw-mj58 Dell PowerStore contains an Argument Injection vulnerability. An authenticated user with limited privileges could potentially exploit this vulnerability to gain unauthorized access to sensitive sensitive system information. | CVSS3: 6.5 | 0% Низкий | 16 дней назад | |
GHSA-4jmv-526x-2x7f Multiple cross-site scripting (XSS) vulnerabilities in Zimbra Collaboration before 8.7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, aka bugs 104552 and 104703. | CVSS3: 6.1 | 1% Низкий | больше 4 лет назад | |
GHSA-4jmv-3f44-7558 Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability | CVSS3: 7.8 | 7% Низкий | около 2 лет назад | |
GHSA-4jmr-68h5-qq5j This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.2.1.53537. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16663. | CVSS3: 7.8 | 1% Низкий | около 4 лет назад | |
GHSA-4jmq-69hm-3jp3 Tanium addressed a use-after-free vulnerability in the Cloud Workloads Enforce client extension. | CVSS3: 4.7 | 0% Низкий | 7 месяцев назад |
Уязвимостей на страницу