Количество 366 653
Количество 366 653
GHSA-4444-8mhw-c9m5
There is a heap-buffer-overflow at jmem-poolman.c:165 in jmem_pools_collect_empty in JerryScript 2.2.0.
GHSA-4444-267r-x82x
The HTTP client in Cisco IOS 12.4 and 15.0 allows user-assisted remote attackers to cause a denial of service (device crash) via a malformed HTTP response to a request for service installation, aka Bug ID CSCts12249.
GHSA-4443-73qg-vxgj
showme.php in CelerBB 0.0.2 allows remote attackers to obtain "reserved information" via the user parameter.
GHSA-4443-6wcq-ghrh
Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4257, CVE-2016-4258, CVE-2016-4259, CVE-2016-4260, CVE-2016-4261, and CVE-2016-4262.
GHSA-4442-gqg3-5qvm
In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: fix memory corruption on open The probe session-duplication overflow check incremented the session count also when there were no more available sessions so that memory beyond the fixed-size slab-allocated session array could be corrupted in fastrpc_session_alloc() on open().
GHSA-4442-448q-43m4
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Hostel allows Reflected XSS. This issue affects Hostel: from n/a through 1.1.5.5.
GHSA-443x-fg59-93h7
A vulnerability was identified in Campcodes Online Apartment Visitor Management System 1.0. Impacted is an unknown function of the file /search-visitor.php. The manipulation of the argument searchdata leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used.
GHSA-443w-gf2f-8h6x
Untrusted pointer dereference in Windows Kernel Memory allows an authorized attacker to elevate privileges locally.
GHSA-443w-3rq3-5m5h
AWS SDK for Java 2.0: Improper Handling of Special Characters in CloudFront Signing Utilities
GHSA-443r-v97h-37x3
Microarchitectural Store Buffer Data Sampling (MSBDS): Store buffers on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impacted products can be found here: https://www.intel.com/content/dam/www/public/us/en/documents/corporate-information/SA00233-microcode-update-guidance_05132019.pdf
GHSA-443r-2qp2-x75x
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0093, CVE-2016-0094, and CVE-2016-0096.
GHSA-443p-ggjw-7w6x
Missing Authorization vulnerability in reputeinfosystems ARForms.This issue affects ARForms: from n/a through 6.4.
GHSA-443p-64xr-9cq7
A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/add_postlogin.php. The manipulation of the argument SingleLoginId leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259711.
GHSA-443m-f58x-jx9j
Capgo before 12.128.2 contains an information disclosure vulnerability in the public.invite_user_to_org RPC function that allows unauthenticated attackers to enumerate organization existence by observing distinct error responses. Attackers can call the SECURITY DEFINER function with a publishable API key to determine if an organization ID exists based on NO_ORG versus NO_RIGHTS responses, enabling tenant enumeration attacks.
GHSA-443m-3fr6-w8wj
PowerJob incorrect access control vulnerability
GHSA-443j-grxv-2pgv
Apache ActiveMQ Artemis: Authenticated users could perform RCE via Jolokia MBeans
GHSA-443j-8jp8-4xch
Web-accessible extension pages (pages with a moz-extension:// scheme) were not correctly enforcing the frame-ancestors directive when it was used in the Web Extension's Content Security Policy. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6.
GHSA-443j-7m97-75j3
This vulnerability allows remote attackers to overwrite files on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the org.apache.jsp.u.jsp.reports.templates.network.traffic_005freport_jsp servlet, which listens on TCP port 8081 by default. When parsing the filename parameter, the process does not properly validate a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to overwrite any files accessible to the Administrator. Was ZDI-CAN-5191.
GHSA-443j-6p7g-6v4w
OpenStack Mistral DoS
GHSA-443h-2c59-36vf
pam_wheel in Linux-PAM 0.78, with the trust option enabled and the use_uid option disabled, allows local users to spoof log entries and gain privileges by causing getlogin() to return a spoofed user name.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4444-8mhw-c9m5 There is a heap-buffer-overflow at jmem-poolman.c:165 in jmem_pools_collect_empty in JerryScript 2.2.0. | 1% Низкий | больше 4 лет назад | ||
GHSA-4444-267r-x82x The HTTP client in Cisco IOS 12.4 and 15.0 allows user-assisted remote attackers to cause a denial of service (device crash) via a malformed HTTP response to a request for service installation, aka Bug ID CSCts12249. | 1% Низкий | больше 4 лет назад | ||
GHSA-4443-73qg-vxgj showme.php in CelerBB 0.0.2 allows remote attackers to obtain "reserved information" via the user parameter. | 3% Низкий | больше 4 лет назад | ||
GHSA-4443-6wcq-ghrh Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-4257, CVE-2016-4258, CVE-2016-4259, CVE-2016-4260, CVE-2016-4261, and CVE-2016-4262. | CVSS3: 9.8 | 5% Низкий | больше 4 лет назад | |
GHSA-4442-gqg3-5qvm In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: fix memory corruption on open The probe session-duplication overflow check incremented the session count also when there were no more available sessions so that memory beyond the fixed-size slab-allocated session array could be corrupted in fastrpc_session_alloc() on open(). | CVSS3: 7.8 | 0% Низкий | около 1 года назад | |
GHSA-4442-448q-43m4 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bob Hostel allows Reflected XSS. This issue affects Hostel: from n/a through 1.1.5.5. | CVSS3: 7.1 | 0% Низкий | больше 1 года назад | |
GHSA-443x-fg59-93h7 A vulnerability was identified in Campcodes Online Apartment Visitor Management System 1.0. Impacted is an unknown function of the file /search-visitor.php. The manipulation of the argument searchdata leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used. | CVSS3: 7.3 | 0% Низкий | 11 месяцев назад | |
GHSA-443w-gf2f-8h6x Untrusted pointer dereference in Windows Kernel Memory allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 1% Низкий | больше 1 года назад | |
GHSA-443w-3rq3-5m5h AWS SDK for Java 2.0: Improper Handling of Special Characters in CloudFront Signing Utilities | 5 месяцев назад | |||
GHSA-443r-v97h-37x3 Microarchitectural Store Buffer Data Sampling (MSBDS): Store buffers on some microprocessors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. A list of impacted products can be found here: https://www.intel.com/content/dam/www/public/us/en/documents/corporate-information/SA00233-microcode-update-guidance_05132019.pdf | CVSS3: 5.6 | 2% Низкий | больше 4 лет назад | |
GHSA-443r-2qp2-x75x The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted application, aka "Win32k Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0093, CVE-2016-0094, and CVE-2016-0096. | CVSS3: 7.8 | 4% Низкий | больше 4 лет назад | |
GHSA-443p-ggjw-7w6x Missing Authorization vulnerability in reputeinfosystems ARForms.This issue affects ARForms: from n/a through 6.4. | CVSS3: 7.1 | 0% Низкий | около 2 лет назад | |
GHSA-443p-64xr-9cq7 A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/add_postlogin.php. The manipulation of the argument SingleLoginId leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259711. | CVSS3: 6.3 | 1% Низкий | больше 2 лет назад | |
GHSA-443m-f58x-jx9j Capgo before 12.128.2 contains an information disclosure vulnerability in the public.invite_user_to_org RPC function that allows unauthenticated attackers to enumerate organization existence by observing distinct error responses. Attackers can call the SECURITY DEFINER function with a publishable API key to determine if an organization ID exists based on NO_ORG versus NO_RIGHTS responses, enabling tenant enumeration attacks. | CVSS3: 5.3 | 0% Низкий | 2 месяца назад | |
GHSA-443m-3fr6-w8wj PowerJob incorrect access control vulnerability | CVSS3: 7.5 | 1% Низкий | около 3 лет назад | |
GHSA-443j-grxv-2pgv Apache ActiveMQ Artemis: Authenticated users could perform RCE via Jolokia MBeans | CVSS3: 8.8 | 17% Средний | почти 2 года назад | |
GHSA-443j-8jp8-4xch Web-accessible extension pages (pages with a moz-extension:// scheme) were not correctly enforcing the frame-ancestors directive when it was used in the Web Extension's Content Security Policy. This vulnerability affects Firefox < 97, Thunderbird < 91.6, and Firefox ESR < 91.6. | CVSS3: 8.8 | 1% Низкий | больше 3 лет назад | |
GHSA-443j-7m97-75j3 This vulnerability allows remote attackers to overwrite files on vulnerable installations of NetGain Systems Enterprise Manager 7.2.730 build 1034. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the org.apache.jsp.u.jsp.reports.templates.network.traffic_005freport_jsp servlet, which listens on TCP port 8081 by default. When parsing the filename parameter, the process does not properly validate a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to overwrite any files accessible to the Administrator. Was ZDI-CAN-5191. | CVSS3: 6.5 | 2% Низкий | больше 4 лет назад | |
GHSA-443j-6p7g-6v4w OpenStack Mistral DoS | CVSS3: 6.5 | 1% Низкий | больше 4 лет назад | |
GHSA-443h-2c59-36vf pam_wheel in Linux-PAM 0.78, with the trust option enabled and the use_uid option disabled, allows local users to spoof log entries and gain privileges by causing getlogin() to return a spoofed user name. | 1% Низкий | больше 4 лет назад |
Уязвимостей на страницу