Количество 371 326
Количество 371 326
GHSA-4g42-h44f-r666
In bff_Scanner_addOutPos of Scanner.c, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege in an unprivileged app with no additional execution privileges needed. User interaction is needed for exploitation.
GHSA-4g42-gqrg-4633
Apache Struts vulnerable to memory exhaustion
GHSA-4g3x-rfq3-9rgr
Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
GHSA-4g3x-jprw-h46m
The read_request_line function in server/protocol.c in the Apache HTTP Server 2.4.12 does not initialize the protocol structure member, which allows remote attackers to cause a denial of service (NULL pointer dereference and process crash) by sending a request that lacks a method to an installation that enables the INCLUDES filter and has an ErrorDocument 400 directive specifying a local URI.
GHSA-4g3w-2657-gjq5
SmartRobot from INTUMIT has a Server-Side Request Forgery vulnerability, allowing unauthenticated remote attackers to probe internal network and even access arbitrary local files on the server.
GHSA-4g3v-8h47-v7g6
Astro: Reflected XSS via unescaped View Transition animation properties
GHSA-4g3q-mj64-82x3
In RPCMS v1.8 and below, the "nickname" variable is not properly sanitized before being displayed on page. Attacker can use "update password" function to inject XSS payloads into nickname variable, and achieve stored XSS. Users who view the articles published by the injected user will trigger the XSS.
GHSA-4g3q-363c-9m45
Actiontec WCB6200Q uh_tcp_recv_content Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Actiontec WCB6200Q routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the HTTP server. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length buffer. An attacker can leverage this vulnerability to execute code in the context of the HTTP server. Was ZDI-CAN-21410.
GHSA-4g3m-gr2j-r4mp
In the Linux kernel, the following vulnerability has been resolved: mtd: spi-nor: swp: Improve locking user experience In the case of the first block being locked (or the few first blocks), if the user want to fully unlock the device it has two possibilities: - either it asks to unlock the entire device, and this works; - or it asks to unlock just the block(s) that are currently locked, which fails. It fails because the conditions "can_be_top" and "can_be_bottom" are true. Indeed, in this case, we unlock everything, so the TB bit does not matter. However in the current implementation, use_top would be true (as this is the favourite option) and lock_len, which in practice should be reduced down to 0, is set to "nor->params->size - (ofs + len)" which is a positive number. This is wrong. An easy way is to simply add an extra condition. In the unlock() path, if we can achieve the same result from both sides, it means we unlock everything and lock_len must simply be 0. A comment is...
GHSA-4g3m-96xf-q484
The Yada Wiki WordPress plugin before 3.4.1 did not sanitise, validate or escape the anchor attribute of its shortcode, leading to a Stored Cross-Site Scripting issue
GHSA-4g3m-89jh-2mrf
A flaw was found in btrfs_get_root_ref in fs/btrfs/disk-io.c in the btrfs filesystem in the Linux Kernel due to a double decrement of the reference count. This issue may allow a local attacker with user privilege to crash the system or may lead to leaked internal kernel information.
GHSA-4g3j-c4wg-6j7x
Snowflake JDBC vulnerable to command injection via SSO URL authentication
GHSA-4g3h-v9fp-pgm4
A vulnerability was found in Avahi. A reachable assertion exists in the avahi_rdata_parse() function.
GHSA-4g3h-ffrc-5jpv
An issue was discovered in GitLab Omnibus 7.4 through 12.2.1. An unsafe interaction with logrotate could result in a privilege escalation
GHSA-4g3g-c4gj-wqr7
A vulnerability in the host input API daemon of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper certificate validation. An attacker could exploit this vulnerability by sending a crafted data stream to the host input daemon of the affected device. A successful exploit could allow the attacker to cause the host input daemon to restart. The attacker could use repeated attacks to cause the daemon to continuously reload, creating a DoS condition for the API.
GHSA-4g3g-9jv2-fhx5
The TCPUploader module in Progea Movicon 11.4 before 11.4.1150 allows remote attackers to obtain potentially sensitive version information via network traffic to TCP port 10651.
GHSA-4g3g-74f5-mm55
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HashThemes Easy Elementor Addons allows Stored XSS. This issue affects Easy Elementor Addons: from n/a through 2.1.6.
GHSA-4g3f-9mfg-xxgh
A Cross-site Scripting (XSS) vulnerability exists in the Settings page of parisneo/lollms-webui version 9.8. The vulnerability is due to the improper use of the 'v-html' directive, which inserts the content of the 'full_template' variable directly as HTML. This allows an attacker to execute malicious JavaScript code by injecting a payload into the 'System Template' input field under main configurations.
GHSA-4g3c-wg65-3h9j
Modex v2.11 was discovered to contain an Use-After-Free vulnerability via the component tcache.
GHSA-4g3c-4f22-rq5v
The social-login-bws plugin before 0.2 for WordPress has multiple XSS issues.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4g42-h44f-r666 In bff_Scanner_addOutPos of Scanner.c, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege in an unprivileged app with no additional execution privileges needed. User interaction is needed for exploitation. | CVSS3: 8.8 | 0% Низкий | почти 2 года назад | |
GHSA-4g42-gqrg-4633 Apache Struts vulnerable to memory exhaustion | CVSS3: 7.5 | 6% Низкий | больше 3 лет назад | |
GHSA-4g3x-rfq3-9rgr Adobe Experience Manager versions 6.5.18 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. | CVSS3: 5.4 | 1% Низкий | почти 3 года назад | |
GHSA-4g3x-jprw-h46m The read_request_line function in server/protocol.c in the Apache HTTP Server 2.4.12 does not initialize the protocol structure member, which allows remote attackers to cause a denial of service (NULL pointer dereference and process crash) by sending a request that lacks a method to an installation that enables the INCLUDES filter and has an ErrorDocument 400 directive specifying a local URI. | 13% Средний | больше 4 лет назад | ||
GHSA-4g3w-2657-gjq5 SmartRobot from INTUMIT has a Server-Side Request Forgery vulnerability, allowing unauthenticated remote attackers to probe internal network and even access arbitrary local files on the server. | CVSS3: 7.5 | 0% Низкий | больше 1 года назад | |
GHSA-4g3v-8h47-v7g6 Astro: Reflected XSS via unescaped View Transition animation properties | 0% Низкий | около 2 месяцев назад | ||
GHSA-4g3q-mj64-82x3 In RPCMS v1.8 and below, the "nickname" variable is not properly sanitized before being displayed on page. Attacker can use "update password" function to inject XSS payloads into nickname variable, and achieve stored XSS. Users who view the articles published by the injected user will trigger the XSS. | 1% Низкий | больше 4 лет назад | ||
GHSA-4g3q-363c-9m45 Actiontec WCB6200Q uh_tcp_recv_content Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Actiontec WCB6200Q routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the HTTP server. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length buffer. An attacker can leverage this vulnerability to execute code in the context of the HTTP server. Was ZDI-CAN-21410. | CVSS3: 8.8 | 1% Низкий | около 2 лет назад | |
GHSA-4g3m-gr2j-r4mp In the Linux kernel, the following vulnerability has been resolved: mtd: spi-nor: swp: Improve locking user experience In the case of the first block being locked (or the few first blocks), if the user want to fully unlock the device it has two possibilities: - either it asks to unlock the entire device, and this works; - or it asks to unlock just the block(s) that are currently locked, which fails. It fails because the conditions "can_be_top" and "can_be_bottom" are true. Indeed, in this case, we unlock everything, so the TB bit does not matter. However in the current implementation, use_top would be true (as this is the favourite option) and lock_len, which in practice should be reduced down to 0, is set to "nor->params->size - (ofs + len)" which is a positive number. This is wrong. An easy way is to simply add an extra condition. In the unlock() path, if we can achieve the same result from both sides, it means we unlock everything and lock_len must simply be 0. A comment is... | 0% Низкий | около 1 месяца назад | ||
GHSA-4g3m-96xf-q484 The Yada Wiki WordPress plugin before 3.4.1 did not sanitise, validate or escape the anchor attribute of its shortcode, leading to a Stored Cross-Site Scripting issue | 1% Низкий | больше 4 лет назад | ||
GHSA-4g3m-89jh-2mrf A flaw was found in btrfs_get_root_ref in fs/btrfs/disk-io.c in the btrfs filesystem in the Linux Kernel due to a double decrement of the reference count. This issue may allow a local attacker with user privilege to crash the system or may lead to leaked internal kernel information. | CVSS3: 7 | 0% Низкий | около 3 лет назад | |
GHSA-4g3j-c4wg-6j7x Snowflake JDBC vulnerable to command injection via SSO URL authentication | CVSS3: 7.3 | 2% Низкий | больше 3 лет назад | |
GHSA-4g3h-v9fp-pgm4 A vulnerability was found in Avahi. A reachable assertion exists in the avahi_rdata_parse() function. | CVSS3: 6.2 | 0% Низкий | почти 3 года назад | |
GHSA-4g3h-ffrc-5jpv An issue was discovered in GitLab Omnibus 7.4 through 12.2.1. An unsafe interaction with logrotate could result in a privilege escalation | CVSS3: 9.8 | 3% Низкий | больше 4 лет назад | |
GHSA-4g3g-c4gj-wqr7 A vulnerability in the host input API daemon of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to improper certificate validation. An attacker could exploit this vulnerability by sending a crafted data stream to the host input daemon of the affected device. A successful exploit could allow the attacker to cause the host input daemon to restart. The attacker could use repeated attacks to cause the daemon to continuously reload, creating a DoS condition for the API. | CVSS3: 5.3 | 1% Низкий | больше 4 лет назад | |
GHSA-4g3g-9jv2-fhx5 The TCPUploader module in Progea Movicon 11.4 before 11.4.1150 allows remote attackers to obtain potentially sensitive version information via network traffic to TCP port 10651. | 1% Низкий | больше 4 лет назад | ||
GHSA-4g3g-74f5-mm55 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HashThemes Easy Elementor Addons allows Stored XSS. This issue affects Easy Elementor Addons: from n/a through 2.1.6. | CVSS3: 6.5 | 0% Низкий | больше 1 года назад | |
GHSA-4g3f-9mfg-xxgh A Cross-site Scripting (XSS) vulnerability exists in the Settings page of parisneo/lollms-webui version 9.8. The vulnerability is due to the improper use of the 'v-html' directive, which inserts the content of the 'full_template' variable directly as HTML. This allows an attacker to execute malicious JavaScript code by injecting a payload into the 'System Template' input field under main configurations. | CVSS3: 5.5 | 0% Низкий | больше 1 года назад | |
GHSA-4g3c-wg65-3h9j Modex v2.11 was discovered to contain an Use-After-Free vulnerability via the component tcache. | 1% Низкий | больше 4 лет назад | ||
GHSA-4g3c-4f22-rq5v The social-login-bws plugin before 0.2 for WordPress has multiple XSS issues. | CVSS3: 6.1 | 1% Низкий | больше 4 лет назад |
Уязвимостей на страницу