Количество 371 326
Количество 371 326
GHSA-4g54-g63j-qr8v
An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. XSS can occur via a link on an error page.
GHSA-4g54-95xv-f353
http-proxy.js is malware
GHSA-4g53-vp7q-gfjv
constructEvent does not verify header
GHSA-4g53-844p-p879
In Raptor RDF Syntax Library through 2.0.16, there is a heap-based buffer over-read when parsing triples with the nquads parser in raptor_ntriples_parse_term_internal().
GHSA-4g52-qrp4-6j69
Cross-Site Request Forgery (CSRF) vulnerability in Ulf Benjaminsson WP-dTree plugin <= 4.4.5 versions.
GHSA-4g52-pqcj-phvh
BLS Signature "Malleability"
GHSA-4g52-pq8j-6qv5
TYPO3 Extension Manager Module vulnerable to Cross-Site Request Forgery
GHSA-4g52-pmx3-v5c4
The DNS packet parser in YADIFA before 2.2.6 does not check for the presence of infinite pointer loops, and thus it is possible to force it to enter an infinite loop. This can cause high CPU usage and makes the server unresponsive.
GHSA-4g4x-f7hr-8q9p
Persistent cross-site scripting (XSS) in Crime Reporting System 1.0 allows a remote attacker to introduce arbitary Javascript via manipulation of an unsanitized POST parameter
GHSA-4g4x-f3f9-gpq4
In the Linux kernel, the following vulnerability has been resolved: apparmor: fix race between freeing data and fs accessing it AppArmor was putting the reference to i_private data on its end after removing the original entry from the file system. However the inode can aand does live beyond that point and it is possible that some of the fs call back functions will be invoked after the reference has been put, which results in a race between freeing the data and accessing it through the fs. While the rawdata/loaddata is the most likely candidate to fail the race, as it has the fewest references. If properly crafted it might be possible to trigger a race for the other types stored in i_private. Fix this by moving the put of i_private referenced data to the correct place which is during inode eviction.
GHSA-4g4w-x2j6-rp8q
Honeywell Experion PKS Safety Manager 5.02 uses Hard-coded Credentials. According to FSCT-2022-0052, there is a Honeywell Experion PKS Safety Manager hardcoded credentials issue. The affected components are characterized as: POLO bootloader. The potential impact is: Manipulate firmware. The Honeywell Experion PKS Safety Manager utilizes the DCOM-232/485 serial interface for firmware management purposes. When booting, the Safety Manager exposes the Enea POLO bootloader via this interface. Access to the boot configuration is controlled by means of credentials hardcoded in the Safety Manager firmware. The credentials for the bootloader are hardcoded in the firmware. An attacker with access to the serial interface (either through physical access, a compromised EWS or an exposed serial-to-ethernet gateway) can utilize these credentials to control the boot process and manipulate the unauthenticated firmware image (see FSCT-2022-0054).
GHSA-4g4w-jrfj-2m5p
Boa web server - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
GHSA-4g4v-5cg8-c9g6
inventory in Atos Unify OpenScape 4000 Platform and OpenScape 4000 Manager Platform 10 R1 before 10 R1.34.4 allows an unauthenticated attacker to run arbitrary commands on the platform operating system and achieve administrative access, aka OSFOURK-23543.
GHSA-4g4r-m9qf-wf8m
An out-of-bounds read can be exploited in Autodesk TrueView 2022 may lead to an exposure of sensitive information or a crash through using a maliciously crafted DWG file as an Input. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
GHSA-4g4r-f763-vv8x
Memory safety bugs present in Firefox 124. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 125.
GHSA-4g4q-v35j-pfp4
NVIDIA Merlin Transformers4Rec for Linux contains a vulnerability in the Trainer component, where a user could cause a deserialization issue. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.
GHSA-4g4q-q7g9-8775
Multiple off-by-one errors in src/text.c in Vilistextum before 2.6.9 have unknown impact and attack vectors.
GHSA-4g4q-fph6-6vcc
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in omnipressteam Omnipress allows DOM-Based XSS. This issue affects Omnipress: from n/a through 1.6.3.
GHSA-4g4p-rr9c-6r55
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
GHSA-4g4p-chhg-9v66
A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The Gif_loader.dll library in affected applications lacks proper validation of user-supplied data when parsing GIF files. This could result in an out of bounds write past the end of an allocated structure. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-13340)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4g54-g63j-qr8v An issue was discovered in Mattermost Server before 3.8.2, 3.7.5, and 3.6.7. XSS can occur via a link on an error page. | 1% Низкий | больше 4 лет назад | ||
GHSA-4g54-95xv-f353 http-proxy.js is malware | CVSS3: 7.5 | 1% Низкий | около 8 лет назад | |
GHSA-4g53-vp7q-gfjv constructEvent does not verify header | больше 5 лет назад | |||
GHSA-4g53-844p-p879 In Raptor RDF Syntax Library through 2.0.16, there is a heap-based buffer over-read when parsing triples with the nquads parser in raptor_ntriples_parse_term_internal(). | CVSS3: 4 | 0% Низкий | больше 1 года назад | |
GHSA-4g52-qrp4-6j69 Cross-Site Request Forgery (CSRF) vulnerability in Ulf Benjaminsson WP-dTree plugin <= 4.4.5 versions. | CVSS3: 4.3 | 0% Низкий | почти 3 года назад | |
GHSA-4g52-pqcj-phvh BLS Signature "Malleability" | CVSS3: 5.9 | 1% Низкий | больше 5 лет назад | |
GHSA-4g52-pq8j-6qv5 TYPO3 Extension Manager Module vulnerable to Cross-Site Request Forgery | CVSS3: 7.5 | 0% Низкий | больше 1 года назад | |
GHSA-4g52-pmx3-v5c4 The DNS packet parser in YADIFA before 2.2.6 does not check for the presence of infinite pointer loops, and thus it is possible to force it to enter an infinite loop. This can cause high CPU usage and makes the server unresponsive. | CVSS3: 7.5 | 3% Низкий | больше 4 лет назад | |
GHSA-4g4x-f7hr-8q9p Persistent cross-site scripting (XSS) in Crime Reporting System 1.0 allows a remote attacker to introduce arbitary Javascript via manipulation of an unsanitized POST parameter | CVSS3: 5.4 | 1% Низкий | около 4 лет назад | |
GHSA-4g4x-f3f9-gpq4 In the Linux kernel, the following vulnerability has been resolved: apparmor: fix race between freeing data and fs accessing it AppArmor was putting the reference to i_private data on its end after removing the original entry from the file system. However the inode can aand does live beyond that point and it is possible that some of the fs call back functions will be invoked after the reference has been put, which results in a race between freeing the data and accessing it through the fs. While the rawdata/loaddata is the most likely candidate to fail the race, as it has the fewest references. If properly crafted it might be possible to trigger a race for the other types stored in i_private. Fix this by moving the put of i_private referenced data to the correct place which is during inode eviction. | CVSS3: 7.8 | 0% Низкий | 6 месяцев назад | |
GHSA-4g4w-x2j6-rp8q Honeywell Experion PKS Safety Manager 5.02 uses Hard-coded Credentials. According to FSCT-2022-0052, there is a Honeywell Experion PKS Safety Manager hardcoded credentials issue. The affected components are characterized as: POLO bootloader. The potential impact is: Manipulate firmware. The Honeywell Experion PKS Safety Manager utilizes the DCOM-232/485 serial interface for firmware management purposes. When booting, the Safety Manager exposes the Enea POLO bootloader via this interface. Access to the boot configuration is controlled by means of credentials hardcoded in the Safety Manager firmware. The credentials for the bootloader are hardcoded in the firmware. An attacker with access to the serial interface (either through physical access, a compromised EWS or an exposed serial-to-ethernet gateway) can utilize these credentials to control the boot process and manipulate the unauthenticated firmware image (see FSCT-2022-0054). | CVSS3: 4.6 | 0% Низкий | около 4 лет назад | |
GHSA-4g4w-jrfj-2m5p Boa web server - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | CVSS3: 7.5 | 1% Низкий | почти 2 года назад | |
GHSA-4g4v-5cg8-c9g6 inventory in Atos Unify OpenScape 4000 Platform and OpenScape 4000 Manager Platform 10 R1 before 10 R1.34.4 allows an unauthenticated attacker to run arbitrary commands on the platform operating system and achieve administrative access, aka OSFOURK-23543. | CVSS3: 9.8 | 1% Низкий | больше 3 лет назад | |
GHSA-4g4r-m9qf-wf8m An out-of-bounds read can be exploited in Autodesk TrueView 2022 may lead to an exposure of sensitive information or a crash through using a maliciously crafted DWG file as an Input. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process. | CVSS3: 7.1 | 1% Низкий | больше 4 лет назад | |
GHSA-4g4r-f763-vv8x Memory safety bugs present in Firefox 124. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox < 125. | CVSS3: 8.1 | 0% Низкий | больше 2 лет назад | |
GHSA-4g4q-v35j-pfp4 NVIDIA Merlin Transformers4Rec for Linux contains a vulnerability in the Trainer component, where a user could cause a deserialization issue. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering. | CVSS3: 8.8 | 1% Низкий | 9 месяцев назад | |
GHSA-4g4q-q7g9-8775 Multiple off-by-one errors in src/text.c in Vilistextum before 2.6.9 have unknown impact and attack vectors. | 2% Низкий | больше 4 лет назад | ||
GHSA-4g4q-fph6-6vcc Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in omnipressteam Omnipress allows DOM-Based XSS. This issue affects Omnipress: from n/a through 1.6.3. | CVSS3: 6.5 | 0% Низкий | около 1 года назад | |
GHSA-4g4p-rr9c-6r55 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | больше 1 года назад | |||
GHSA-4g4p-chhg-9v66 A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The Gif_loader.dll library in affected applications lacks proper validation of user-supplied data when parsing GIF files. This could result in an out of bounds write past the end of an allocated structure. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-13340) | 2% Низкий | больше 4 лет назад |
Уязвимостей на страницу