Количество 342 247
Количество 342 247
GHSA-2w8m-f4xv-fpww
jhead through 3.04 has a heap-based buffer over-read in process_DQT in jpgqguess.c.
GHSA-2w8j-h6jx-gc5q
Gee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has identified an issue with a specific file that the server is using. A non-admin user can modify this file to either create files or change the content of files in an admin-protected location. Axis has released a patched version for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.
GHSA-2w8j-8xc6-4wcx
SQL Injection vulnerability in Simple Laboratory Management System using PHP and MySQL v.1.0 allows a remote attacker to cause a denial of service via the delete_users function in the Useres.php
GHSA-2w8h-mqc4-qvfp
Cross-site scripting (XSS) vulnerability in IBM ENOVIA 6 allows remote attackers to inject arbitrary web script or HTML via vectors related to the emxFramework.FilterParameterPattern property.
GHSA-2w8h-hch2-v23h
mudler/LocalAI version 2.17.1 allows for arbitrary file write due to improper handling of automatic archive extraction. When model configurations specify additional files as archives (e.g., .tar), these archives are automatically extracted after downloading. This behavior can be exploited to perform a 'tarslip' attack, allowing files to be written to arbitrary locations on the server, bypassing checks that normally restrict files to the models directory. This vulnerability can lead to remote code execution (RCE) by overwriting backend assets used by the server.
GHSA-2w8h-77mr-j4fw
Microsoft PowerShell Spoofing Vulnerability
GHSA-2w8g-v9pc-7jpq
Belkin N900 router (F9K1104v1) contains an Authentication Bypass using "Javascript debugging".
GHSA-2w8g-m5j8-7m87
Zalgo-like output that crashes the server
GHSA-2w8f-9fpf-qq4v
sound/core/hrtimer.c in the Linux kernel before 4.4.1 does not prevent recursive callback access, which allows local users to cause a denial of service (deadlock) via a crafted ioctl call.
GHSA-2w8f-25gq-9g77
The Wp-Adv-Quiz WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
GHSA-2w8c-hj6v-28vw
A maliciously crafted pskernel.dll file in Autodesk products is used to trigger integer overflow vulnerabilities. Exploitation of these vulnerabilities may lead to code execution.
GHSA-2w89-g5fw-9c76
PHP remote file inclusion vulnerability in tools/packages/import.php in ATutor 1.6.1 pl1 and earlier allows remote authenticated administrators to execute arbitrary PHP code via a URL in the type parameter.
GHSA-2w89-7wx5-gppj
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.63 and earlier, and 5.5.25 and earlier, allows remote authenticated users to affect availability via unknown vectors related to InnoDB Plugin.
GHSA-2w89-5px3-fvx6
iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function.
GHSA-2w88-9jch-6jfv
omx/SimpleSoftOMXComponent.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 does not prevent input-port changes, which allows attackers to gain privileges via a crafted application, aka internal bug 29421804.
GHSA-2w88-4wpv-5768
A vulnerability classified as critical was found in CodeAstro Membership Management System 1.0. This vulnerability affects unknown code of the file renew.php?id=6. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
GHSA-2w87-fjj9-j39h
A component for parsing OXMF templates could be abused to execute arbitrary system commands that would be executed as the non-privileged runtime user. Users and attackers could run system commands with limited privilege to gain unauthorized access to confidential information and potentially violate integrity by modifying resources. The template engine has been reconfigured to deny execution of harmful commands on a system level. No publicly available exploits are known.
GHSA-2w87-6hh6-mqrj
On Windows a directory returned by tempfile.mkdtemp() would not always have permissions set to restrict reading and writing to the temporary directory by other users, instead usually inheriting the correct permissions from the default location. Alternate configurations or users without a profile directory may not have the intended permissions. If you’re not using Windows or haven’t changed the temporary directory location then you aren’t affected by this vulnerability. On other platforms the returned directory is consistently readable and writable only by the current user. This issue was caused by Python not supporting Unix permissions on Windows. The fix adds support for Unix “700” for the mkdir function on Windows which is used by mkdtemp() to ensure the newly created directory has the proper permissions.
GHSA-2w87-5qcj-j6gx
OpenStack Compute (Nova) Denial of service due to improper validation of virtual size of QCOW2 image
GHSA-2w86-wv37-w7h5
A spoofing attack in ujcms v.8.0.2 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted script to the X-Forwarded-For function in the header.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2w8m-f4xv-fpww jhead through 3.04 has a heap-based buffer over-read in process_DQT in jpgqguess.c. | CVSS3: 7.1 | 1% Низкий | больше 4 лет назад | |
GHSA-2w8j-h6jx-gc5q Gee-netics, member of AXIS Camera Station Pro Bug Bounty Program, has identified an issue with a specific file that the server is using. A non-admin user can modify this file to either create files or change the content of files in an admin-protected location. Axis has released a patched version for the highlighted flaw. Please refer to the Axis security advisory for more information and solution. | CVSS3: 6.1 | 0% Низкий | больше 1 года назад | |
GHSA-2w8j-8xc6-4wcx SQL Injection vulnerability in Simple Laboratory Management System using PHP and MySQL v.1.0 allows a remote attacker to cause a denial of service via the delete_users function in the Useres.php | CVSS3: 4.3 | 1% Низкий | почти 2 года назад | |
GHSA-2w8h-mqc4-qvfp Cross-site scripting (XSS) vulnerability in IBM ENOVIA 6 allows remote attackers to inject arbitrary web script or HTML via vectors related to the emxFramework.FilterParameterPattern property. | 1% Низкий | больше 4 лет назад | ||
GHSA-2w8h-hch2-v23h mudler/LocalAI version 2.17.1 allows for arbitrary file write due to improper handling of automatic archive extraction. When model configurations specify additional files as archives (e.g., .tar), these archives are automatically extracted after downloading. This behavior can be exploited to perform a 'tarslip' attack, allowing files to be written to arbitrary locations on the server, bypassing checks that normally restrict files to the models directory. This vulnerability can lead to remote code execution (RCE) by overwriting backend assets used by the server. | CVSS3: 8.1 | 2% Низкий | почти 2 года назад | |
GHSA-2w8h-77mr-j4fw Microsoft PowerShell Spoofing Vulnerability | CVSS3: 5.5 | 2% Низкий | больше 4 лет назад | |
GHSA-2w8g-v9pc-7jpq Belkin N900 router (F9K1104v1) contains an Authentication Bypass using "Javascript debugging". | CVSS3: 9.8 | 2% Низкий | больше 4 лет назад | |
GHSA-2w8g-m5j8-7m87 Zalgo-like output that crashes the server | больше 4 лет назад | |||
GHSA-2w8f-9fpf-qq4v sound/core/hrtimer.c in the Linux kernel before 4.4.1 does not prevent recursive callback access, which allows local users to cause a denial of service (deadlock) via a crafted ioctl call. | CVSS3: 6.2 | 0% Низкий | больше 4 лет назад | |
GHSA-2w8f-25gq-9g77 The Wp-Adv-Quiz WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | CVSS3: 4.8 | 0% Низкий | больше 2 лет назад | |
GHSA-2w8c-hj6v-28vw A maliciously crafted pskernel.dll file in Autodesk products is used to trigger integer overflow vulnerabilities. Exploitation of these vulnerabilities may lead to code execution. | CVSS3: 7.8 | 0% Низкий | около 3 лет назад | |
GHSA-2w89-g5fw-9c76 PHP remote file inclusion vulnerability in tools/packages/import.php in ATutor 1.6.1 pl1 and earlier allows remote authenticated administrators to execute arbitrary PHP code via a URL in the type parameter. | 3% Низкий | больше 4 лет назад | ||
GHSA-2w89-7wx5-gppj Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.63 and earlier, and 5.5.25 and earlier, allows remote authenticated users to affect availability via unknown vectors related to InnoDB Plugin. | 3% Низкий | больше 4 лет назад | ||
GHSA-2w89-5px3-fvx6 iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function. | 1% Низкий | больше 1 года назад | ||
GHSA-2w88-9jch-6jfv omx/SimpleSoftOMXComponent.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016-09-01 does not prevent input-port changes, which allows attackers to gain privileges via a crafted application, aka internal bug 29421804. | CVSS3: 7.8 | 1% Низкий | больше 4 лет назад | |
GHSA-2w88-4wpv-5768 A vulnerability classified as critical was found in CodeAstro Membership Management System 1.0. This vulnerability affects unknown code of the file renew.php?id=6. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 7.3 | 0% Низкий | больше 1 года назад | |
GHSA-2w87-fjj9-j39h A component for parsing OXMF templates could be abused to execute arbitrary system commands that would be executed as the non-privileged runtime user. Users and attackers could run system commands with limited privilege to gain unauthorized access to confidential information and potentially violate integrity by modifying resources. The template engine has been reconfigured to deny execution of harmful commands on a system level. No publicly available exploits are known. | CVSS3: 8.8 | 1% Низкий | больше 2 лет назад | |
GHSA-2w87-6hh6-mqrj On Windows a directory returned by tempfile.mkdtemp() would not always have permissions set to restrict reading and writing to the temporary directory by other users, instead usually inheriting the correct permissions from the default location. Alternate configurations or users without a profile directory may not have the intended permissions. If you’re not using Windows or haven’t changed the temporary directory location then you aren’t affected by this vulnerability. On other platforms the returned directory is consistently readable and writable only by the current user. This issue was caused by Python not supporting Unix permissions on Windows. The fix adds support for Unix “700” for the mkdir function on Windows which is used by mkdtemp() to ensure the newly created directory has the proper permissions. | CVSS3: 7.1 | 0% Низкий | больше 2 лет назад | |
GHSA-2w87-5qcj-j6gx OpenStack Compute (Nova) Denial of service due to improper validation of virtual size of QCOW2 image | 0% Низкий | больше 4 лет назад | ||
GHSA-2w86-wv37-w7h5 A spoofing attack in ujcms v.8.0.2 allows a remote attacker to obtain sensitive information and execute arbitrary code via a crafted script to the X-Forwarded-For function in the header. | CVSS3: 9.8 | 1% Низкий | больше 2 лет назад |
Уязвимостей на страницу