Количество 366 087
Количество 366 087
GHSA-3xxr-vfgj-3gw3
In updateState of LocationServicesWifiScanningPreferenceController.java, there is a possible admin restriction bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-228315529
GHSA-3xxr-729f-x6v9
IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to server-side request forgery, caused by improper input of application server registration function. A remote attacker could exploit this vulnerability using the host address and port fields of the application server registration form in the portal UI to enumerate and attack services that are running on those hosts. IBM X-Force ID: 214441.
GHSA-3xxp-88xx-wwq3
Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.
GHSA-3xxp-73wf-27cp
DotNetNuke (DNN) 9.9.1 CMS is vulnerable to a Stored Cross-Site Scripting vulnerability in the user profile biography section which allows remote authenticated users to inject arbitrary code via a crafted payload.
GHSA-3xxm-pww7-gf82
In nfa_hci_handle_admin_gate_rsp of nfa_hci_act.cc, there is a possible out of bound write due to missing bounds checks. This could lead to local escalation of privilege with system execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-124524315
GHSA-3xxm-cx7p-m4p6
joyplus-cms 1.6.0 has CSRF, as demonstrated by adding an administrator account via a manager/admin_ajax.php?action=save&tab={pre}manager request.
GHSA-3xxm-3g3c-w579
Moodle Code Injection vulnerability
GHSA-3xxj-wpwj-gxhm
An Improper Check for Unusual or Exceptional Conditions (CWE-754) vulnerability exists in Modicon Quantum 140 NOE771x1 version 6.9 and earlier, which could cause denial of service when the module receives an IP fragmented packet with a length greater than 65535 bytes. The module then requires a power cycle to recover.
GHSA-3xxj-rv47-9w5r
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Chroma chroma allows PHP Local File Inclusion.This issue affects Chroma: from n/a through <= 1.11.
GHSA-3xxj-rfjr-w6h5
Cross-Site Request Forgery (CSRF) vulnerability in plainware.Com ShiftController Employee Shift Scheduling plugin <= 4.9.23 versions.
GHSA-3xxj-pcr2-rvh7
NULL Pointer Dereference in Homebrew mruby prior to 3.2.
GHSA-3xxh-w577-324m
The Spectra WordPress plugin before 1.15.0 does not sanitize user input as it reaches its style HTML attribute, allowing contributors to conduct stored XSS attacks via the plugin's Gutenberg blocks.
GHSA-3xxh-hm67-x74r
Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled 'GO' and 'index' parameters into a 64-byte stack buffer without length restriction, leading to stack overflow.
GHSA-3xxh-2rc7-7mx7
SQL injection vulnerability in the WebAdmin application 6.0.5, 6.0.8, and 7.0 before P2 in IBM Netezza allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
GHSA-3xxg-cfxh-f9rh
** DISPUTED ** Cross-site scripting (XSS) vulnerability in index.php in NZ Ecommerce allows remote attackers to inject arbitrary web script or HTML via the action parameter. NOTE: the vendor has disputed this issue in a comment on the researcher's blog, but research by CVE suggests that this might be a legitimate problem.
GHSA-3xxg-9vrr-9g96
Buffer overflow in some Zoom Workplace Apps and Rooms Clients may allow an authenticated user to conduct an escalation of privilege via network access.
GHSA-3xxf-f9pw-rwm5
In the Linux kernel, the following vulnerability has been resolved: net/tcp-ao: Fix MAC comparison to be constant-time To prevent timing attacks, MACs need to be compared in constant time. Use the appropriate helper function for this.
GHSA-3xxf-776r-vvm4
In executeSetClientTarget of ComposerCommandEngine.h, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-252764410
GHSA-3xxc-v62h-9qfv
run.cgi in Webmin 0.80 and 0.88 creates temporary files with world-writable permissions, which allows local users to execute arbitrary commands.
GHSA-3xxc-pwj6-jgrj
rfc3161-client Has Improper Certificate Validation
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3xxr-vfgj-3gw3 In updateState of LocationServicesWifiScanningPreferenceController.java, there is a possible admin restriction bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-228315529 | CVSS3: 7.8 | 0% Низкий | около 4 лет назад | |
GHSA-3xxr-729f-x6v9 IBM Spectrum Copy Data Management 2.2.0.0 through 2.2.14.3 is vulnerable to server-side request forgery, caused by improper input of application server registration function. A remote attacker could exploit this vulnerability using the host address and port fields of the application server registration form in the portal UI to enumerate and attack services that are running on those hosts. IBM X-Force ID: 214441. | CVSS3: 6.5 | 1% Низкий | больше 4 лет назад | |
GHSA-3xxp-88xx-wwq3 Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network. | CVSS3: 6.5 | 1% Низкий | 24 дня назад | |
GHSA-3xxp-73wf-27cp DotNetNuke (DNN) 9.9.1 CMS is vulnerable to a Stored Cross-Site Scripting vulnerability in the user profile biography section which allows remote authenticated users to inject arbitrary code via a crafted payload. | CVSS3: 5.4 | 1% Низкий | около 4 лет назад | |
GHSA-3xxm-pww7-gf82 In nfa_hci_handle_admin_gate_rsp of nfa_hci_act.cc, there is a possible out of bound write due to missing bounds checks. This could lead to local escalation of privilege with system execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0 Android-8.1 Android-9 Android-10Android ID: A-124524315 | 0% Низкий | больше 4 лет назад | ||
GHSA-3xxm-cx7p-m4p6 joyplus-cms 1.6.0 has CSRF, as demonstrated by adding an administrator account via a manager/admin_ajax.php?action=save&tab={pre}manager request. | CVSS3: 8.8 | 1% Низкий | больше 4 лет назад | |
GHSA-3xxm-3g3c-w579 Moodle Code Injection vulnerability | CVSS3: 4.7 | 2% Низкий | почти 3 года назад | |
GHSA-3xxj-wpwj-gxhm An Improper Check for Unusual or Exceptional Conditions (CWE-754) vulnerability exists in Modicon Quantum 140 NOE771x1 version 6.9 and earlier, which could cause denial of service when the module receives an IP fragmented packet with a length greater than 65535 bytes. The module then requires a power cycle to recover. | CVSS3: 7.5 | 1% Низкий | больше 4 лет назад | |
GHSA-3xxj-rv47-9w5r Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Chroma chroma allows PHP Local File Inclusion.This issue affects Chroma: from n/a through <= 1.11. | CVSS3: 8.1 | 0% Низкий | 6 месяцев назад | |
GHSA-3xxj-rfjr-w6h5 Cross-Site Request Forgery (CSRF) vulnerability in plainware.Com ShiftController Employee Shift Scheduling plugin <= 4.9.23 versions. | CVSS3: 5.4 | 0% Низкий | почти 3 года назад | |
GHSA-3xxj-pcr2-rvh7 NULL Pointer Dereference in Homebrew mruby prior to 3.2. | 1% Низкий | больше 4 лет назад | ||
GHSA-3xxh-w577-324m The Spectra WordPress plugin before 1.15.0 does not sanitize user input as it reaches its style HTML attribute, allowing contributors to conduct stored XSS attacks via the plugin's Gutenberg blocks. | CVSS3: 5.4 | 1% Низкий | больше 3 лет назад | |
GHSA-3xxh-hm67-x74r Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sprintf to copy user-controlled 'GO' and 'index' parameters into a 64-byte stack buffer without length restriction, leading to stack overflow. | CVSS3: 9.8 | 0% Низкий | около 1 месяца назад | |
GHSA-3xxh-2rc7-7mx7 SQL injection vulnerability in the WebAdmin application 6.0.5, 6.0.8, and 7.0 before P2 in IBM Netezza allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. | 1% Низкий | больше 4 лет назад | ||
GHSA-3xxg-cfxh-f9rh ** DISPUTED ** Cross-site scripting (XSS) vulnerability in index.php in NZ Ecommerce allows remote attackers to inject arbitrary web script or HTML via the action parameter. NOTE: the vendor has disputed this issue in a comment on the researcher's blog, but research by CVE suggests that this might be a legitimate problem. | 1% Низкий | больше 4 лет назад | ||
GHSA-3xxg-9vrr-9g96 Buffer overflow in some Zoom Workplace Apps and Rooms Clients may allow an authenticated user to conduct an escalation of privilege via network access. | CVSS3: 8.5 | 1% Низкий | около 2 лет назад | |
GHSA-3xxf-f9pw-rwm5 In the Linux kernel, the following vulnerability has been resolved: net/tcp-ao: Fix MAC comparison to be constant-time To prevent timing attacks, MACs need to be compared in constant time. Use the appropriate helper function for this. | CVSS3: 9.8 | 0% Низкий | 4 месяца назад | |
GHSA-3xxf-776r-vvm4 In executeSetClientTarget of ComposerCommandEngine.h, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-13Android ID: A-252764410 | CVSS3: 4.4 | 0% Низкий | около 3 лет назад | |
GHSA-3xxc-v62h-9qfv run.cgi in Webmin 0.80 and 0.88 creates temporary files with world-writable permissions, which allows local users to execute arbitrary commands. | 0% Низкий | больше 4 лет назад | ||
GHSA-3xxc-pwj6-jgrj rfc3161-client Has Improper Certificate Validation | CVSS3: 6.2 | 0% Низкий | 5 месяцев назад |
Уязвимостей на страницу