Количество 371 326
Количество 371 326
GHSA-4fvf-46cq-3pw2
Information leak in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
GHSA-4fvc-w7pw-48q6
Missing Authorization vulnerability in termel Bulk Fields Editor allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Bulk Fields Editor: from n/a through 1.8.0.
GHSA-4fvc-h857-qw9g
This vulnerability could allow an attacker to hijack a session while a user is logged in the configuration web page. This vulnerability was discovered by a security researcher in B426 and found during internal product tests in B426-CN/B429-CN, and B426-M and has been fixed already starting from version 3.08 on, which was released on June 2019.
GHSA-4fvc-83fv-pgq6
Unspecified vulnerability in HP StorageWorks Secure Path for Windows 4.0C-SP2 before 20060419 allows remote attackers to cause an unspecified denial of service via unknown vectors.
GHSA-4fv9-v5wm-569w
The Simple:Press Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.10.11. This is due to missing or incorrect nonce validation on the 'sp_save_edited_post' function. This makes it possible for unauthenticated attackers to modify a forum post via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
GHSA-4fv8-w65m-3932
efs-utils and aws-efs-csi-driver have race condition during concurrent TLS mounts
GHSA-4fv8-q23c-jh2m
Luocms v2.0 is affected by SQL Injection in /admin/link/link_mod.php.
GHSA-4fv8-h7r9-m88g
Process Monitor 1.22 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via unspecified kernel SSDT hooks for Windows Native API functions including (1) NtCreateKey, (2) NtDeleteValueKey, (3) NtLoadKey, (4) NtOpenKey, (5) NtQueryValueKey, (6) NtSetValueKey, and (7) NtUnloadKey.
GHSA-4fv8-fm6j-xc9r
An issue in the kiosk mode of Secure Lockdown Multi Application Edition v2.00.219 allows attackers to execute arbitrary code via running a ClickOnce application instance.
GHSA-4fv7-37f3-c5j6
In netdiag, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11; Patch ID: ALPS05442022.
GHSA-4fv6-38m4-qgqj
In DjVuLibre 3.5.27, DjVmDir.cpp in the DJVU reader component allows attackers to cause a denial-of-service (application crash in GStringRep::strdup in libdjvu/GString.cpp caused by a heap-based buffer over-read) by crafting a DJVU file.
GHSA-4fv6-2265-mqxm
An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Uncontrolled Resource Consumption.
GHSA-4fv5-wjqm-7f2r
Asset Management System v1.0 is vulnerable to an unauthenticated SQL Injection vulnerability on the 'email' parameter of index.php page, allowing an external attacker to dump all the contents of the database contents and bypass the login control.
GHSA-4fv5-g6r3-cjxh
Unspecified vulnerability in Mozilla Firefox allows remote attackers to execute arbitrary code via unspecified vectors involving Javascript errors. NOTE: this might be the same issue as CVE-2007-2175.
GHSA-4fv5-487x-c795
NVIDIA CUDA toolkit for all platforms contains a vulnerability in cuobjdump and nvdisasm where an attacker may cause a crash by tricking a user into reading a malformed ELF file. A successful exploit of this vulnerability may lead to a partial denial of service.
GHSA-4fv4-gh87-p496
The Pricing Table WordPress plugin before 3.6.1 fails to properly sanitize and escape user supplied POST data before it is being interpolated in an SQL statement and then executed via an AJAX action available to unauthenticated users
GHSA-4fv4-f7m5-w88w
The iTrack Easy mobile application stores the account password used to authenticate to the cloud API in base64-encoding in the cache.db file. The base64 encoding format is considered equivalent to cleartext.
GHSA-4fv4-cq5v-x45m
Improper Authentication in Apache MyFaces
GHSA-4fv4-55mw-p3v4
modules/loaders/loader_ico.c in imlib2 1.6.0 has an integer overflow (with resultant invalid memory allocations and out-of-bounds reads) via an icon with many colors in its color map.
GHSA-4fv3-v4jw-2q2p
A Reliance on Untrusted Inputs in a Security Decision vulnerability has been identified in the Lexmark Print Management Client.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4fvf-46cq-3pw2 Information leak in ServiceWorker in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium) | CVSS3: 4.3 | 0% Низкий | 20 дней назад | |
GHSA-4fvc-w7pw-48q6 Missing Authorization vulnerability in termel Bulk Fields Editor allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Bulk Fields Editor: from n/a through 1.8.0. | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
GHSA-4fvc-h857-qw9g This vulnerability could allow an attacker to hijack a session while a user is logged in the configuration web page. This vulnerability was discovered by a security researcher in B426 and found during internal product tests in B426-CN/B429-CN, and B426-M and has been fixed already starting from version 3.08 on, which was released on June 2019. | 1% Низкий | больше 4 лет назад | ||
GHSA-4fvc-83fv-pgq6 Unspecified vulnerability in HP StorageWorks Secure Path for Windows 4.0C-SP2 before 20060419 allows remote attackers to cause an unspecified denial of service via unknown vectors. | 3% Низкий | больше 4 лет назад | ||
GHSA-4fv9-v5wm-569w The Simple:Press Forum plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.10.11. This is due to missing or incorrect nonce validation on the 'sp_save_edited_post' function. This makes it possible for unauthenticated attackers to modify a forum post via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
GHSA-4fv8-w65m-3932 efs-utils and aws-efs-csi-driver have race condition during concurrent TLS mounts | CVSS3: 4.2 | 1% Низкий | больше 3 лет назад | |
GHSA-4fv8-q23c-jh2m Luocms v2.0 is affected by SQL Injection in /admin/link/link_mod.php. | CVSS3: 9.8 | 1% Низкий | больше 4 лет назад | |
GHSA-4fv8-h7r9-m88g Process Monitor 1.22 does not properly validate certain parameters to System Service Descriptor Table (SSDT) function handlers, which allows local users to cause a denial of service (crash) and possibly gain privileges via unspecified kernel SSDT hooks for Windows Native API functions including (1) NtCreateKey, (2) NtDeleteValueKey, (3) NtLoadKey, (4) NtOpenKey, (5) NtQueryValueKey, (6) NtSetValueKey, and (7) NtUnloadKey. | 0% Низкий | больше 4 лет назад | ||
GHSA-4fv8-fm6j-xc9r An issue in the kiosk mode of Secure Lockdown Multi Application Edition v2.00.219 allows attackers to execute arbitrary code via running a ClickOnce application instance. | CVSS3: 9.8 | 1% Низкий | больше 2 лет назад | |
GHSA-4fv7-37f3-c5j6 In netdiag, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11; Patch ID: ALPS05442022. | 0% Низкий | больше 4 лет назад | ||
GHSA-4fv6-38m4-qgqj In DjVuLibre 3.5.27, DjVmDir.cpp in the DJVU reader component allows attackers to cause a denial-of-service (application crash in GStringRep::strdup in libdjvu/GString.cpp caused by a heap-based buffer over-read) by crafting a DJVU file. | CVSS3: 5.5 | 2% Низкий | больше 4 лет назад | |
GHSA-4fv6-2265-mqxm An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Uncontrolled Resource Consumption. | CVSS3: 7.5 | 3% Низкий | больше 4 лет назад | |
GHSA-4fv5-wjqm-7f2r Asset Management System v1.0 is vulnerable to an unauthenticated SQL Injection vulnerability on the 'email' parameter of index.php page, allowing an external attacker to dump all the contents of the database contents and bypass the login control. | CVSS3: 9.8 | 1% Низкий | почти 3 года назад | |
GHSA-4fv5-g6r3-cjxh Unspecified vulnerability in Mozilla Firefox allows remote attackers to execute arbitrary code via unspecified vectors involving Javascript errors. NOTE: this might be the same issue as CVE-2007-2175. | 3% Низкий | больше 4 лет назад | ||
GHSA-4fv5-487x-c795 NVIDIA CUDA toolkit for all platforms contains a vulnerability in cuobjdump and nvdisasm where an attacker may cause a crash by tricking a user into reading a malformed ELF file. A successful exploit of this vulnerability may lead to a partial denial of service. | CVSS3: 3.3 | 0% Низкий | больше 2 лет назад | |
GHSA-4fv4-gh87-p496 The Pricing Table WordPress plugin before 3.6.1 fails to properly sanitize and escape user supplied POST data before it is being interpolated in an SQL statement and then executed via an AJAX action available to unauthenticated users | CVSS3: 9.8 | 13% Средний | больше 4 лет назад | |
GHSA-4fv4-f7m5-w88w The iTrack Easy mobile application stores the account password used to authenticate to the cloud API in base64-encoding in the cache.db file. The base64 encoding format is considered equivalent to cleartext. | CVSS3: 7.8 | 0% Низкий | больше 4 лет назад | |
GHSA-4fv4-cq5v-x45m Improper Authentication in Apache MyFaces | 3% Низкий | больше 4 лет назад | ||
GHSA-4fv4-55mw-p3v4 modules/loaders/loader_ico.c in imlib2 1.6.0 has an integer overflow (with resultant invalid memory allocations and out-of-bounds reads) via an icon with many colors in its color map. | 2% Низкий | больше 4 лет назад | ||
GHSA-4fv3-v4jw-2q2p A Reliance on Untrusted Inputs in a Security Decision vulnerability has been identified in the Lexmark Print Management Client. | CVSS3: 9.3 | 0% Низкий | больше 1 года назад |
Уязвимостей на страницу