Количество 370 914
Количество 370 914
GHSA-4cg3-gfhj-x3xm
Out of bounds memory access in developer tools in Google Chrome prior to 84.0.4147.89 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.
GHSA-4cg2-c6h6-v749
The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.0.18 via deserialization of untrusted input from the args[callback] parameter . This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to execute arbitrary functions, though it does not allow user supplied parameters only single functions can be called so the impact is limited.
GHSA-4cfx-p6p6-jpvw
Cross-site request forgery (CSRF) vulnerability in the account-creation panel in IBM InfoSphere Guardium 8.2 and earlier, when the CSRF filtering (aka csrf_status) feature is disabled, allows remote attackers to hijack the authentication of administrators for requests that create administrative accounts.
GHSA-4cfx-h9gq-xpx3
Heap overflow in COMMAND GETKEYS and ACL evaluation
GHSA-4cfw-gc9p-jwf4
Rejected reason: Not used
GHSA-4cfw-g6m2-82xj
** DISPUTED ** An issue was discovered in the org.telegram.messenger application 4.8.11 for Android. The FingerprintManager class for Biometric validation allows authentication bypass through the callback method from onAuthenticationFailed to onAuthenticationSucceeded with null, because the fingerprint API in conjunction with the Android keyGenerator class is not implemented. In other words, an attacker could authenticate with an arbitrary fingerprint. NOTE: the vendor indicates that this is not an attack of interest within the context of their threat model, which excludes Android devices on which rooting has occurred.
GHSA-4cfw-fmc2-h845
A vulnerability was found in aandrew-me ytDownloader up to 3.20.2. Affected by this issue is the function createTextNode of the component Error Details Panel. The manipulation results in cross site scripting. The attack may be performed from remote. The vendor was contacted early about this disclosure.
GHSA-4cfr-xp32-h9c9
IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
GHSA-4cfr-h84p-cp36
Multiple unspecified vulnerabilities in IBM Director before 5.10 allow remote attackers to cause a denial of service (crash) via unspecified vectors involving (1) malformed WMI CIM server requests and (2) malformed packets.
GHSA-4cfr-gjfx-fj3x
Cobbler before 3.3.0 allows arbitrary file write operations via upload_log_data.
GHSA-4cfr-8c5p-5jg6
Heap-based buffer overflow in the visit_old_format function in locate/locate.c in locate in GNU findutils before 4.2.31 might allow context-dependent attackers to execute arbitrary code via a long pathname in a locate database that has the old format, a different vulnerability than CVE-2001-1036.
GHSA-4cfq-849g-j9jx
I2P before 0.9.46 allows local users to gain privileges via a Trojan horse I2PSvc.exe file because of weak permissions on a certain %PROGRAMFILES% subdirectory.
GHSA-4cfp-g6j6-f76r
ScriptLogic 4.01, and possibly other versions before 4.14, uses insecure permissions for the LOGS$ share, which allows users to modify log records and possibly execute arbitrary code.
GHSA-4cfp-2523-96q2
The WP Social Widget WordPress plugin before 2.2.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
GHSA-4cfm-6q3x-wgvm
Cross-site scripting (XSS) vulnerability in Italtel S.p.A. i-MCS NFV v.12.1.0-20211215 allows unauthenticated remote attackers to inject arbitrary web script or HTML into HTTP/POST parameter
GHSA-4cfm-33p5-g53v
Improper Control of Generation of Code ('Code Injection') vulnerability in Qode Interactive Qode Essential Addons.This issue affects Qode Essential Addons: from n/a through 1.5.2.
GHSA-4cfj-pm5j-9qhf
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in cmsmasters CMSMasters Content Composer cmsmasters-content-composer allows PHP Local File Inclusion.This issue affects CMSMasters Content Composer: from n/a through <= 1.4.5.
GHSA-4cfj-fw6h-v7f4
Cross-site Scripting (XSS) in cPanel WebHost Manager (WHM) 11.34.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
GHSA-4cfj-cvw8-f4m2
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Nose Graze Novelist plugin <= 1.2.0 versions.
GHSA-4cfh-gw3m-q584
In a rare scenario, Check Point R80.30 Security Gateway before JHF Take 50 managed by Check Point R80.30 Management crashes with a unique configuration of enhanced logging.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4cg3-gfhj-x3xm Out of bounds memory access in developer tools in Google Chrome prior to 84.0.4147.89 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. | 1% Низкий | больше 4 лет назад | ||
GHSA-4cg2-c6h6-v749 The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.0.18 via deserialization of untrusted input from the args[callback] parameter . This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to execute arbitrary functions, though it does not allow user supplied parameters only single functions can be called so the impact is limited. | CVSS3: 5.6 | 0% Низкий | больше 1 года назад | |
GHSA-4cfx-p6p6-jpvw Cross-site request forgery (CSRF) vulnerability in the account-creation panel in IBM InfoSphere Guardium 8.2 and earlier, when the CSRF filtering (aka csrf_status) feature is disabled, allows remote attackers to hijack the authentication of administrators for requests that create administrative accounts. | 1% Низкий | больше 4 лет назад | ||
GHSA-4cfx-h9gq-xpx3 Heap overflow in COMMAND GETKEYS and ACL evaluation | CVSS3: 7.4 | 77% Высокий | около 3 лет назад | |
GHSA-4cfw-gc9p-jwf4 Rejected reason: Not used | около 1 года назад | |||
GHSA-4cfw-g6m2-82xj ** DISPUTED ** An issue was discovered in the org.telegram.messenger application 4.8.11 for Android. The FingerprintManager class for Biometric validation allows authentication bypass through the callback method from onAuthenticationFailed to onAuthenticationSucceeded with null, because the fingerprint API in conjunction with the Android keyGenerator class is not implemented. In other words, an attacker could authenticate with an arbitrary fingerprint. NOTE: the vendor indicates that this is not an attack of interest within the context of their threat model, which excludes Android devices on which rooting has occurred. | CVSS3: 6.8 | 0% Низкий | больше 4 лет назад | |
GHSA-4cfw-fmc2-h845 A vulnerability was found in aandrew-me ytDownloader up to 3.20.2. Affected by this issue is the function createTextNode of the component Error Details Panel. The manipulation results in cross site scripting. The attack may be performed from remote. The vendor was contacted early about this disclosure. | CVSS3: 4.3 | 0% Низкий | 5 месяцев назад | |
GHSA-4cfr-xp32-h9c9 IBM Aspera Faspex 5.0.0 through 5.0.10 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. | CVSS3: 5.9 | 0% Низкий | больше 1 года назад | |
GHSA-4cfr-h84p-cp36 Multiple unspecified vulnerabilities in IBM Director before 5.10 allow remote attackers to cause a denial of service (crash) via unspecified vectors involving (1) malformed WMI CIM server requests and (2) malformed packets. | 2% Низкий | больше 4 лет назад | ||
GHSA-4cfr-gjfx-fj3x Cobbler before 3.3.0 allows arbitrary file write operations via upload_log_data. | CVSS3: 7.5 | 69% Средний | почти 5 лет назад | |
GHSA-4cfr-8c5p-5jg6 Heap-based buffer overflow in the visit_old_format function in locate/locate.c in locate in GNU findutils before 4.2.31 might allow context-dependent attackers to execute arbitrary code via a long pathname in a locate database that has the old format, a different vulnerability than CVE-2001-1036. | 2% Низкий | больше 4 лет назад | ||
GHSA-4cfq-849g-j9jx I2P before 0.9.46 allows local users to gain privileges via a Trojan horse I2PSvc.exe file because of weak permissions on a certain %PROGRAMFILES% subdirectory. | 0% Низкий | больше 4 лет назад | ||
GHSA-4cfp-g6j6-f76r ScriptLogic 4.01, and possibly other versions before 4.14, uses insecure permissions for the LOGS$ share, which allows users to modify log records and possibly execute arbitrary code. | 1% Низкий | больше 4 лет назад | ||
GHSA-4cfp-2523-96q2 The WP Social Widget WordPress plugin before 2.2.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | CVSS3: 5.4 | 1% Низкий | больше 3 лет назад | |
GHSA-4cfm-6q3x-wgvm Cross-site scripting (XSS) vulnerability in Italtel S.p.A. i-MCS NFV v.12.1.0-20211215 allows unauthenticated remote attackers to inject arbitrary web script or HTML into HTTP/POST parameter | CVSS3: 6.1 | 0% Низкий | больше 1 года назад | |
GHSA-4cfm-33p5-g53v Improper Control of Generation of Code ('Code Injection') vulnerability in Qode Interactive Qode Essential Addons.This issue affects Qode Essential Addons: from n/a through 1.5.2. | CVSS3: 9.9 | 1% Низкий | больше 2 лет назад | |
GHSA-4cfj-pm5j-9qhf Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in cmsmasters CMSMasters Content Composer cmsmasters-content-composer allows PHP Local File Inclusion.This issue affects CMSMasters Content Composer: from n/a through <= 1.4.5. | CVSS3: 7.5 | 0% Низкий | 7 месяцев назад | |
GHSA-4cfj-fw6h-v7f4 Cross-site Scripting (XSS) in cPanel WebHost Manager (WHM) 11.34.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | CVSS3: 6.1 | 2% Низкий | больше 4 лет назад | |
GHSA-4cfj-cvw8-f4m2 Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Nose Graze Novelist plugin <= 1.2.0 versions. | CVSS3: 5.9 | 0% Низкий | около 3 лет назад | |
GHSA-4cfh-gw3m-q584 In a rare scenario, Check Point R80.30 Security Gateway before JHF Take 50 managed by Check Point R80.30 Management crashes with a unique configuration of enhanced logging. | CVSS3: 7.5 | 1% Низкий | больше 4 лет назад |
Уязвимостей на страницу