Количество 371 326
Количество 371 326
GHSA-4g2g-8pcm-99w8
Improper Handling of Additional Special Element in GitHub repository squidex/squidex prior to 7.4.0.
GHSA-4g2g-3x54-996g
FlexHEX 2.71 contains a local buffer overflow vulnerability in the Stream Name field that allows local attackers to execute arbitrary code by triggering a structured exception handler (SEH) overflow. Attackers can craft a malicious text file with carefully aligned shellcode and SEH chain pointers, paste the contents into the Stream Name dialog, and execute arbitrary commands like calc.exe when the exception handler is triggered.
GHSA-4g2f-xcph-2335
ingress-nginx has Improper Check for Unusual or Exceptional Conditions
GHSA-4g2f-wf65-x5xp
The API in the WebKit Plug-ins component in Apple Safari before 9 does not provide notification of an HTTP Redirection (aka 3xx) status code to a plugin, which allows remote attackers to bypass intended request restrictions via a crafted web site.
GHSA-4g2f-q935-7ppv
PHP remote file inclusion vulnerability in end.php in ask_rave 0.9 PR, and other versions before 0.9b, allows remote attackers to execute arbitrary PHP code via a URL in the footfile parameter.
GHSA-4g2f-j53w-6jfc
The database access credentials configured during installation are stored in a special table, and are encrypted with a shared key, same among all Comarch ERP XL client installations. This could allow an attacker with access to that table to retrieve plain text passwords. This issue affects ERP XL: from 2020.2.2 through 2023.2.
GHSA-4g2c-wq22-f9v3
** DISPUTED ** Mozilla Firefox 1.0.7 and 1.5.0.1 allows remote attackers to cause a denial of service (crash) via an HTML tag with a large number of script action handlers such as onload and onmouseover, which triggers the crash when the user views the page source. NOTE: Red Hat has disputed this issue, suggesting that "It is likely the reporter was running the IE Tab extension," and Mozilla also confirmed that this is not an issue in Firefox itself.
GHSA-4g2c-w6c3-7ghw
Use-after-free vulnerability in the CPDF_Parser::IsLinearizedFile function in fpdfapi/fpdf_parser/fpdf_parser_parser.cpp in PDFium, as used in Google Chrome before 39.0.2171.65, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PDF document.
GHSA-4g2c-qjxv-9c24
LFENCE/JMP (mitigation V2-2) may not sufficiently mitigate CVE-2017-5715 on some AMD CPUs.
GHSA-4g2c-h3mq-5rv5
Centrinity First Class Internet Services 5.50 allows for the circumventing of the default 'spam' filters via the presence of '<@>' in the 'From:' field, which allows remote attackers to send spoofed email with the identity of local users.
GHSA-4g2c-9347-58ff
Cross-Site Request Forgery (CSRF) vulnerability in Wpmet Wp Ultimate Review plugin <= 2.0.3 versions.
GHSA-4g2c-8mg7-7g89
: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uploaditem.asp of Telos Automated Message Handling System allows a remote attacker to inject arbitrary script into an AMHS session. This issue affects: Telos Automated Message Handling System versions prior to 4.1.5.5.
GHSA-4g29-r7vj-2rpv
Jenkins Job Import Plugin allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins
GHSA-4g29-fccr-p59w
Reflected Cross-site Scripting in Shopware storefront
GHSA-4g29-9cr3-v367
MASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated Configuration Change, as demonstrated by the port number of the web server.
GHSA-4g28-wh72-jhwq
Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android. These could have led to potential user confusion and spoofing attacks. *This bug only affects Firefox and Focus for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox for Android < 112 and Focus for Android < 112.
GHSA-4g28-pqg3-vcxc
Improper Input Validation vulnerability in Samsung Open Source rLottie allows Overread Buffers.This issue affects rLottie: V0.2.
GHSA-4g28-pcv2-qj5h
wallabag 2 through 2.6.14 allows SSRF because a crafted title or content field is mishandled during PDF export.
GHSA-4g27-v2fc-m8fv
A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP.
GHSA-4g27-q2w9-m8m8
Magento affected by remote code execution vulnerability in the CMS page scheduled update feature
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4g2g-8pcm-99w8 Improper Handling of Additional Special Element in GitHub repository squidex/squidex prior to 7.4.0. | CVSS3: 6.1 | 1% Низкий | больше 3 лет назад | |
GHSA-4g2g-3x54-996g FlexHEX 2.71 contains a local buffer overflow vulnerability in the Stream Name field that allows local attackers to execute arbitrary code by triggering a structured exception handler (SEH) overflow. Attackers can craft a malicious text file with carefully aligned shellcode and SEH chain pointers, paste the contents into the Stream Name dialog, and execute arbitrary commands like calc.exe when the exception handler is triggered. | CVSS3: 8.4 | 0% Низкий | 6 месяцев назад | |
GHSA-4g2f-xcph-2335 ingress-nginx has Improper Check for Unusual or Exceptional Conditions | CVSS3: 3.1 | 0% Низкий | 7 месяцев назад | |
GHSA-4g2f-wf65-x5xp The API in the WebKit Plug-ins component in Apple Safari before 9 does not provide notification of an HTTP Redirection (aka 3xx) status code to a plugin, which allows remote attackers to bypass intended request restrictions via a crafted web site. | 2% Низкий | больше 4 лет назад | ||
GHSA-4g2f-q935-7ppv PHP remote file inclusion vulnerability in end.php in ask_rave 0.9 PR, and other versions before 0.9b, allows remote attackers to execute arbitrary PHP code via a URL in the footfile parameter. | 3% Низкий | больше 4 лет назад | ||
GHSA-4g2f-j53w-6jfc The database access credentials configured during installation are stored in a special table, and are encrypted with a shared key, same among all Comarch ERP XL client installations. This could allow an attacker with access to that table to retrieve plain text passwords. This issue affects ERP XL: from 2020.2.2 through 2023.2. | CVSS3: 6.2 | 0% Низкий | больше 2 лет назад | |
GHSA-4g2c-wq22-f9v3 ** DISPUTED ** Mozilla Firefox 1.0.7 and 1.5.0.1 allows remote attackers to cause a denial of service (crash) via an HTML tag with a large number of script action handlers such as onload and onmouseover, which triggers the crash when the user views the page source. NOTE: Red Hat has disputed this issue, suggesting that "It is likely the reporter was running the IE Tab extension," and Mozilla also confirmed that this is not an issue in Firefox itself. | 2% Низкий | больше 4 лет назад | ||
GHSA-4g2c-w6c3-7ghw Use-after-free vulnerability in the CPDF_Parser::IsLinearizedFile function in fpdfapi/fpdf_parser/fpdf_parser_parser.cpp in PDFium, as used in Google Chrome before 39.0.2171.65, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PDF document. | 1% Низкий | больше 4 лет назад | ||
GHSA-4g2c-qjxv-9c24 LFENCE/JMP (mitigation V2-2) may not sufficiently mitigate CVE-2017-5715 on some AMD CPUs. | CVSS3: 5.6 | 0% Низкий | больше 4 лет назад | |
GHSA-4g2c-h3mq-5rv5 Centrinity First Class Internet Services 5.50 allows for the circumventing of the default 'spam' filters via the presence of '<@>' in the 'From:' field, which allows remote attackers to send spoofed email with the identity of local users. | 1% Низкий | больше 4 лет назад | ||
GHSA-4g2c-9347-58ff Cross-Site Request Forgery (CSRF) vulnerability in Wpmet Wp Ultimate Review plugin <= 2.0.3 versions. | CVSS3: 4.3 | 0% Низкий | почти 3 года назад | |
GHSA-4g2c-8mg7-7g89 : Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in uploaditem.asp of Telos Automated Message Handling System allows a remote attacker to inject arbitrary script into an AMHS session. This issue affects: Telos Automated Message Handling System versions prior to 4.1.5.5. | 1% Низкий | больше 4 лет назад | ||
GHSA-4g29-r7vj-2rpv Jenkins Job Import Plugin allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins | CVSS3: 4.3 | 1% Низкий | почти 4 года назад | |
GHSA-4g29-fccr-p59w Reflected Cross-site Scripting in Shopware storefront | CVSS3: 5.4 | 1% Низкий | больше 4 лет назад | |
GHSA-4g29-9cr3-v367 MASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated Configuration Change, as demonstrated by the port number of the web server. | CVSS3: 7.5 | 5% Низкий | больше 4 лет назад | |
GHSA-4g28-wh72-jhwq Different techniques existed to obscure the fullscreen notification in Firefox and Focus for Android. These could have led to potential user confusion and spoofing attacks. *This bug only affects Firefox and Focus for Android. Other versions of Firefox are unaffected.* This vulnerability affects Firefox for Android < 112 and Focus for Android < 112. | CVSS3: 9.1 | 1% Низкий | около 3 лет назад | |
GHSA-4g28-pqg3-vcxc Improper Input Validation vulnerability in Samsung Open Source rLottie allows Overread Buffers.This issue affects rLottie: V0.2. | CVSS3: 9.8 | 0% Низкий | около 1 года назад | |
GHSA-4g28-pcv2-qj5h wallabag 2 through 2.6.14 allows SSRF because a crafted title or content field is mishandled during PDF export. | CVSS3: 6.4 | 0% Низкий | 18 дней назад | |
GHSA-4g27-v2fc-m8fv A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP. | CVSS3: 6.7 | 1% Низкий | больше 4 лет назад | |
GHSA-4g27-q2w9-m8m8 Magento affected by remote code execution vulnerability in the CMS page scheduled update feature | CVSS3: 9.1 | 2% Низкий | около 3 лет назад |
Уязвимостей на страницу