Количество 366 653
Количество 366 653
GHSA-43gm-x67w-cjp4
The ffingerd 1.19 allows remote attackers to identify users on the target system based on its responses.
GHSA-43gm-9rr3-cx7g
Froxlor: Stored XSS in DNS TXT Record Content Allows Customer-to-Admin Account Takeover
GHSA-43gj-mj95-qp4h
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the dumpSyslog function.
GHSA-43gj-mj2w-wh46
Cross-Site Scripting in TYPO3 CMS Form Engine
GHSA-43gj-jf28-cm95
A vulnerability was found in SourceCodester AC Repair and Services System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/bookings/manage_booking.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-227707.
GHSA-43gh-2c4j-x343
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Charsets). Supported versions that are affected are 5.5.53 and earlier. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS v3.0 Base Score 4.4 (Availability impacts).
GHSA-43gg-m8j9-xmqj
A vulnerability, which was classified as critical, was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. Affected is an unknown function of the file /control/activate_case.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-260274 is the identifier assigned to this vulnerability.
GHSA-43gg-3jq2-xwfh
PayMoney 3.3 is vulnerable to Stored Cross-Site Scripting (XSS) during replying the ticket. The XSS can be obtain from injecting under "Message" field with "description" parameter with the specially crafted payload to gain Stored XSS. The XSS then will prompt after that or can be access from the view ticket function.
GHSA-43gf-9mf8-44g5
IBM MQ Appliance 9.1.4.CD could allow a local attacker to obtain highly sensitive information by inclusion of sensitive data within trace. IBM X-Force ID: 172616.
GHSA-43gf-2x57-fwxf
In the Linux kernel, the following vulnerability has been resolved: drm/virtio: Fix missed dmabuf unpinning in error path of prepare_fb() Correct error handling in prepare_fb() to fix leaking resources when error happens.
GHSA-43gc-mjxg-gvrq
XStream is vulnerable to an Arbitrary Code Execution attack
GHSA-43g9-xc7g-7r65
In the Linux kernel, the following vulnerability has been resolved: erofs: fix incorrect early exits for invalid metabox-enabled images Crafted EROFS images with metadata compression enabled can trigger incorrect early returns, leading to folio reference leaks. However, this does not cause system crashes or other severe issues.
GHSA-43g9-qgw6-3pfp
Process lifetime issue in Chrome in Google Chrome on Android prior to 74.0.3729.108 allowed a remote attacker to potentially persist an exploited process via a crafted HTML page.
GHSA-43g9-fmq9-jjpm
Products with Unified Automation .NET based OPC UA Client/Server SDK Bundle: Versions V3.0.7 and prior (.NET 4.5, 4.0, and 3.5 Framework versions only) are vulnerable to an uncontrolled recursion, which may allow an attacker to trigger a stack overflow.
GHSA-43g9-956r-vq78
readelf in GNU Binutils 2.28 is vulnerable to a heap-based buffer over-read while processing corrupt RL78 binaries. The vulnerability can trigger program crashes. It may lead to an information leak as well.
GHSA-43g8-79x3-j898
Unrestricted access to predictable file paths in hov/jobfair
GHSA-43g8-4r39-vq2f
In the Linux kernel, the following vulnerability has been resolved: parisc: Try to fix random segmentation faults in package builds PA-RISC systems with PA8800 and PA8900 processors have had problems with random segmentation faults for many years. Systems with earlier processors are much more stable. Systems with PA8800 and PA8900 processors have a large L2 cache which needs per page flushing for decent performance when a large range is flushed. The combined cache in these systems is also more sensitive to non-equivalent aliases than the caches in earlier systems. The majority of random segmentation faults that I have looked at appear to be memory corruption in memory allocated using mmap and malloc. My first attempt at fixing the random faults didn't work. On reviewing the cache code, I realized that there were two issues which the existing code didn't handle correctly. Both relate to cache move-in. Another issue is that the present bit in PTEs is racy. 1) PA-RISC caches hav...
GHSA-43g7-vrh8-pwwx
The cforms2 plugin before 14.13 for WordPress has SQL injection in the tracking DB GUI via Delete Entries or Download Entries.
GHSA-43g7-f6j3-j7xf
A vulnerability was found in Campcodes Online Recruitment Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/ajax.php?action=delete_recruitment_status. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
GHSA-43g7-cwr8-q3jh
OpenTelemetry eBPF Instrumentation: Memcached payload length overflow can crash OBI
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-43gm-x67w-cjp4 The ffingerd 1.19 allows remote attackers to identify users on the target system based on its responses. | 9% Низкий | больше 4 лет назад | ||
GHSA-43gm-9rr3-cx7g Froxlor: Stored XSS in DNS TXT Record Content Allows Customer-to-Admin Account Takeover | CVSS3: 8.7 | 0% Низкий | 19 дней назад | |
GHSA-43gj-mj95-qp4h In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the dumpSyslog function. | CVSS3: 8.8 | 1% Низкий | почти 2 года назад | |
GHSA-43gj-mj2w-wh46 Cross-Site Scripting in TYPO3 CMS Form Engine | CVSS3: 5.4 | 1% Низкий | больше 6 лет назад | |
GHSA-43gj-jf28-cm95 A vulnerability was found in SourceCodester AC Repair and Services System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/bookings/manage_booking.php. The manipulation of the argument id leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-227707. | CVSS3: 6.3 | 1% Низкий | больше 3 лет назад | |
GHSA-43gh-2c4j-x343 Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Charsets). Supported versions that are affected are 5.5.53 and earlier. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS v3.0 Base Score 4.4 (Availability impacts). | CVSS3: 4.4 | 4% Низкий | больше 4 лет назад | |
GHSA-43gg-m8j9-xmqj A vulnerability, which was classified as critical, was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. Affected is an unknown function of the file /control/activate_case.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-260274 is the identifier assigned to this vulnerability. | CVSS3: 4.7 | 1% Низкий | больше 2 лет назад | |
GHSA-43gg-3jq2-xwfh PayMoney 3.3 is vulnerable to Stored Cross-Site Scripting (XSS) during replying the ticket. The XSS can be obtain from injecting under "Message" field with "description" parameter with the specially crafted payload to gain Stored XSS. The XSS then will prompt after that or can be access from the view ticket function. | CVSS3: 5.4 | 1% Низкий | почти 4 года назад | |
GHSA-43gf-9mf8-44g5 IBM MQ Appliance 9.1.4.CD could allow a local attacker to obtain highly sensitive information by inclusion of sensitive data within trace. IBM X-Force ID: 172616. | 0% Низкий | больше 4 лет назад | ||
GHSA-43gf-2x57-fwxf In the Linux kernel, the following vulnerability has been resolved: drm/virtio: Fix missed dmabuf unpinning in error path of prepare_fb() Correct error handling in prepare_fb() to fix leaking resources when error happens. | CVSS3: 5.5 | 0% Низкий | больше 1 года назад | |
GHSA-43gc-mjxg-gvrq XStream is vulnerable to an Arbitrary Code Execution attack | CVSS3: 5.3 | 15% Средний | больше 5 лет назад | |
GHSA-43g9-xc7g-7r65 In the Linux kernel, the following vulnerability has been resolved: erofs: fix incorrect early exits for invalid metabox-enabled images Crafted EROFS images with metadata compression enabled can trigger incorrect early returns, leading to folio reference leaks. However, this does not cause system crashes or other severe issues. | CVSS3: 5.5 | 0% Низкий | 4 месяца назад | |
GHSA-43g9-qgw6-3pfp Process lifetime issue in Chrome in Google Chrome on Android prior to 74.0.3729.108 allowed a remote attacker to potentially persist an exploited process via a crafted HTML page. | CVSS3: 8.8 | 2% Низкий | больше 4 лет назад | |
GHSA-43g9-fmq9-jjpm Products with Unified Automation .NET based OPC UA Client/Server SDK Bundle: Versions V3.0.7 and prior (.NET 4.5, 4.0, and 3.5 Framework versions only) are vulnerable to an uncontrolled recursion, which may allow an attacker to trigger a stack overflow. | CVSS3: 7.5 | 2% Низкий | больше 4 лет назад | |
GHSA-43g9-956r-vq78 readelf in GNU Binutils 2.28 is vulnerable to a heap-based buffer over-read while processing corrupt RL78 binaries. The vulnerability can trigger program crashes. It may lead to an information leak as well. | CVSS3: 9.1 | 4% Низкий | больше 4 лет назад | |
GHSA-43g8-79x3-j898 Unrestricted access to predictable file paths in hov/jobfair | CVSS3: 7.5 | 1% Низкий | почти 5 лет назад | |
GHSA-43g8-4r39-vq2f In the Linux kernel, the following vulnerability has been resolved: parisc: Try to fix random segmentation faults in package builds PA-RISC systems with PA8800 and PA8900 processors have had problems with random segmentation faults for many years. Systems with earlier processors are much more stable. Systems with PA8800 and PA8900 processors have a large L2 cache which needs per page flushing for decent performance when a large range is flushed. The combined cache in these systems is also more sensitive to non-equivalent aliases than the caches in earlier systems. The majority of random segmentation faults that I have looked at appear to be memory corruption in memory allocated using mmap and malloc. My first attempt at fixing the random faults didn't work. On reviewing the cache code, I realized that there were two issues which the existing code didn't handle correctly. Both relate to cache move-in. Another issue is that the present bit in PTEs is racy. 1) PA-RISC caches hav... | CVSS3: 6.3 | 0% Низкий | около 2 лет назад | |
GHSA-43g7-vrh8-pwwx The cforms2 plugin before 14.13 for WordPress has SQL injection in the tracking DB GUI via Delete Entries or Download Entries. | CVSS3: 9.8 | 2% Низкий | больше 4 лет назад | |
GHSA-43g7-f6j3-j7xf A vulnerability was found in Campcodes Online Recruitment Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/ajax.php?action=delete_recruitment_status. The manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 7.3 | 0% Низкий | около 1 года назад | |
GHSA-43g7-cwr8-q3jh OpenTelemetry eBPF Instrumentation: Memcached payload length overflow can crash OBI | CVSS3: 7.5 | 0% Низкий | 4 месяца назад |
Уязвимостей на страницу