Количество 366 653
Количество 366 653
GHSA-42m7-x4gf-gj25
A maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
GHSA-42m7-jqh7-g85c
Joomla Extension - j2commerce.com - Stored XSS in Guest checkout in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - J2Commerce 4.1.5 is vulnerable to Stored Cross-Site Scripting (XSS) through the guest checkout billing address fields. An unauthenticated attacker exploits a filter bypass in Joomla's Input::getArray() combined with PHP's variables_order=EGPCS (Cookie overrides POST in $_REQUEST ) to store unsanitized HTML in fields such as billing_first_name.
GHSA-42m7-8557-x95x
Windows Mobile Broadband Driver Denial of Service Vulnerability
GHSA-42m7-33x8-mvrh
OPW Fuel Management Systems SiteSentinel could allow an attacker to bypass authentication to the server and obtain full admin privileges.
GHSA-42m6-xh7c-6xm4
CodexBar before 0.33.0 contains a credential forwarding vulnerability that allows network-adjacent attackers to intercept sensitive credentials by issuing cross-origin or HTTP-downgrade redirects to the shared ProviderHTTPClient transport. Attackers can redirect credentialed provider requests carrying browser cookies, bearer tokens, or API keys to an unintended host, port, or plaintext HTTP destination to capture those credentials.
GHSA-42m6-v976-v7cf
A Null Pointer dereference vulnerability exists in GPAC 2.1-DEV-revUNKNOWN-master via the function gf_filter_pid_set_property_full () at filter_core/filter_pid.c:5250,which causes a Denial of Service (DoS). This vulnerability was fixed in commit b43f9d1.
GHSA-42m6-mm85-f999
SQL Injection exists in the AllVideos Reloaded 1.2.x component for Joomla! via the divid parameter.
GHSA-42m6-m8gm-pwp9
Microsoft Internet Explorer 6 and 7 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "HTML Object Memory Corruption Vulnerability."
GHSA-42m6-m7p8-vqwv
An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. A remote code execution vulnerability exists in the network configuration functionality, stemming from insufficient input validation when processing network configuration parameters through administrative endpoints. The application allows administrators to modify the server's network configuration through the Django application. This configuration is processed by Bash scripts (TSsetnoproxy and TSsetproxy) that write user-controlled data directly to environment variables without proper sanitization. After updating environment variables, the scripts execute a source command on /etc/environment; if an attacker injects malicious data into environment variables, this command can enable arbitrary command execution. The vulnerability begins with the /admin/network endpoint, which passes user-supplied form data as arguments to subprocess.Popen calls. The user-supplied input is then used to update environme...
GHSA-42m6-g935-5vmq
@ianwalter/merge Prototype Pollution via `merge` function
GHSA-42m6-9p28-3cfp
Directory traversal vulnerability in Flatnuke 2.5.6 allows remote attackers to access arbitrary files via a .. (dot dot) and null byte (%00) in the id parameter of the read module.
GHSA-42m6-7xff-9v9m
Improper Neutralization of Input During Web Page Generation in Jenkins
GHSA-42m6-6jcq-4m5x
Use-after-free vulnerability in Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to SVG layout.
GHSA-42m6-5vm7-fjv2
Mattermost Confluence Plugin has Missing Authorization vulnerability
GHSA-42m5-rf78-8h9x
Potential Cross-Site Scripting in ArcSight Logger versions prior to 7.3.0
GHSA-42m5-g3g4-g4j9
The mintToken function of a smart contract implementation for Carrot, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
GHSA-42m5-3r2p-wr92
Monsta FTP versions 2.11 and earlier contain a vulnerability that allows unauthenticated arbitrary file uploads. This flaw enables attackers to execute arbitrary code by uploading a specially crafted file from a malicious (S)FTP server.
GHSA-42m5-34mg-qrv6
cPanel before 60.0.25 allows file-overwrite operations during preparation for MySQL upgrades (SEC-161).
GHSA-42m4-q6r2-jh92
An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displaying an incorrect diff in a re-opened Pull Request. To do so, an attacker would need write access to the repository. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in versions 3.6.17, 3.7.15, 3.8.8, 3.9.3, and 3.10.1. This vulnerability was reported via the GitHub Bug Bounty program.
GHSA-42m4-gw8j-vjvg
A cross-site scripting (XSS) vulnerability in the component /managers/multiple_freeleech.php of Gazelle commit 63b3370 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the torrents parameter.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-42m7-x4gf-gj25 A maliciously crafted X_B file when parsed through Autodesk® AutoCAD® 2023 could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process. | CVSS3: 7.8 | 0% Низкий | около 3 лет назад | |
GHSA-42m7-jqh7-g85c Joomla Extension - j2commerce.com - Stored XSS in Guest checkout in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - J2Commerce 4.1.5 is vulnerable to Stored Cross-Site Scripting (XSS) through the guest checkout billing address fields. An unauthenticated attacker exploits a filter bypass in Joomla's Input::getArray() combined with PHP's variables_order=EGPCS (Cookie overrides POST in $_REQUEST ) to store unsanitized HTML in fields such as billing_first_name. | 0% Низкий | 14 дней назад | ||
GHSA-42m7-8557-x95x Windows Mobile Broadband Driver Denial of Service Vulnerability | CVSS3: 6.5 | 1% Низкий | почти 2 года назад | |
GHSA-42m7-33x8-mvrh OPW Fuel Management Systems SiteSentinel could allow an attacker to bypass authentication to the server and obtain full admin privileges. | CVSS3: 9.8 | 1% Низкий | почти 2 года назад | |
GHSA-42m6-xh7c-6xm4 CodexBar before 0.33.0 contains a credential forwarding vulnerability that allows network-adjacent attackers to intercept sensitive credentials by issuing cross-origin or HTTP-downgrade redirects to the shared ProviderHTTPClient transport. Attackers can redirect credentialed provider requests carrying browser cookies, bearer tokens, or API keys to an unintended host, port, or plaintext HTTP destination to capture those credentials. | CVSS3: 5.3 | 0% Низкий | 3 месяца назад | |
GHSA-42m6-v976-v7cf A Null Pointer dereference vulnerability exists in GPAC 2.1-DEV-revUNKNOWN-master via the function gf_filter_pid_set_property_full () at filter_core/filter_pid.c:5250,which causes a Denial of Service (DoS). This vulnerability was fixed in commit b43f9d1. | CVSS3: 7.5 | 1% Низкий | около 4 лет назад | |
GHSA-42m6-mm85-f999 SQL Injection exists in the AllVideos Reloaded 1.2.x component for Joomla! via the divid parameter. | CVSS3: 9.8 | 3% Низкий | больше 4 лет назад | |
GHSA-42m6-m8gm-pwp9 Microsoft Internet Explorer 6 and 7 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "HTML Object Memory Corruption Vulnerability." | 25% Средний | больше 4 лет назад | ||
GHSA-42m6-m7p8-vqwv An issue was discovered in the Thermo Fisher Torrent Suite Django application 5.18.1. A remote code execution vulnerability exists in the network configuration functionality, stemming from insufficient input validation when processing network configuration parameters through administrative endpoints. The application allows administrators to modify the server's network configuration through the Django application. This configuration is processed by Bash scripts (TSsetnoproxy and TSsetproxy) that write user-controlled data directly to environment variables without proper sanitization. After updating environment variables, the scripts execute a source command on /etc/environment; if an attacker injects malicious data into environment variables, this command can enable arbitrary command execution. The vulnerability begins with the /admin/network endpoint, which passes user-supplied form data as arguments to subprocess.Popen calls. The user-supplied input is then used to update environme... | CVSS3: 7.2 | 1% Низкий | 9 месяцев назад | |
GHSA-42m6-g935-5vmq @ianwalter/merge Prototype Pollution via `merge` function | CVSS3: 5.6 | 1% Низкий | около 4 лет назад | |
GHSA-42m6-9p28-3cfp Directory traversal vulnerability in Flatnuke 2.5.6 allows remote attackers to access arbitrary files via a .. (dot dot) and null byte (%00) in the id parameter of the read module. | 8% Низкий | больше 4 лет назад | ||
GHSA-42m6-7xff-9v9m Improper Neutralization of Input During Web Page Generation in Jenkins | CVSS3: 5.4 | 1% Низкий | больше 4 лет назад | |
GHSA-42m6-6jcq-4m5x Use-after-free vulnerability in Google Chrome before 24.0.1312.52 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to SVG layout. | 1% Низкий | больше 4 лет назад | ||
GHSA-42m6-5vm7-fjv2 Mattermost Confluence Plugin has Missing Authorization vulnerability | CVSS3: 3.7 | 0% Низкий | около 1 года назад | |
GHSA-42m5-rf78-8h9x Potential Cross-Site Scripting in ArcSight Logger versions prior to 7.3.0 | CVSS3: 6.1 | 0% Низкий | около 3 лет назад | |
GHSA-42m5-g3g4-g4j9 The mintToken function of a smart contract implementation for Carrot, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | CVSS3: 7.5 | 1% Низкий | больше 4 лет назад | |
GHSA-42m5-3r2p-wr92 Monsta FTP versions 2.11 and earlier contain a vulnerability that allows unauthenticated arbitrary file uploads. This flaw enables attackers to execute arbitrary code by uploading a specially crafted file from a malicious (S)FTP server. | 73% Высокий | 10 месяцев назад | ||
GHSA-42m5-34mg-qrv6 cPanel before 60.0.25 allows file-overwrite operations during preparation for MySQL upgrades (SEC-161). | CVSS3: 6.5 | 1% Низкий | больше 4 лет назад | |
GHSA-42m4-q6r2-jh92 An incorrect comparison vulnerability was identified in GitHub Enterprise Server that allowed commit smuggling by displaying an incorrect diff in a re-opened Pull Request. To do so, an attacker would need write access to the repository. This vulnerability affected all versions of GitHub Enterprise Server and was fixed in versions 3.6.17, 3.7.15, 3.8.8, 3.9.3, and 3.10.1. This vulnerability was reported via the GitHub Bug Bounty program. | CVSS3: 4.5 | 1% Низкий | почти 3 года назад | |
GHSA-42m4-gw8j-vjvg A cross-site scripting (XSS) vulnerability in the component /managers/multiple_freeleech.php of Gazelle commit 63b3370 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the torrents parameter. | CVSS3: 6.1 | 0% Низкий | около 2 лет назад |
Уязвимостей на страницу