Количество 342 247
Количество 342 247
GHSA-2pj3-3r8x-phjq
A vulnerability, which was classified as critical, was found in Tenda FH1202 1.2.0.14(408). This affects an unknown part of the file /goform/qossetting of the component Web Management Interface. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
GHSA-2pj2-w39h-8vvq
Untrusted search path vulnerability in the installer in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, and Thunderbird ESR 10.x before 10.0.7 on Windows allows local users to gain privileges via a Trojan horse executable file in a root directory.
GHSA-2pj2-gchf-wmw7
Zip4j Origin Validation Error
GHSA-2pj2-82cm-7r39
PicoC 2.1 has a heap-based buffer overflow in StringStrcpy in cstdlib/string.c when called from ExpressionParseFunctionCall in expression.c.
GHSA-2phx-w35g-x9vm
Moodle Weak Password Recovery Mechanism for Forgotten Password
GHSA-2phx-jm8v-c5v7
A vulnerability in the Guest Shell of Cisco IOS XE Software could allow an authenticated, local attacker to perform directory traversal on the base Linux operating system of Cisco IOS XE Software. The vulnerability is due to incomplete validation of certain commands. An attacker could exploit this vulnerability by first accessing the Guest Shell and then entering specific commands. A successful exploit could allow the attacker to execute arbitrary code on the base Linux operating system.
GHSA-2phx-frhf-xr55
Mattermost Plugin Zoom allows any logged-in user to change Zoom meeting restrictions for arbitrary channels
GHSA-2phw-rgr7-5pvh
Information Cards Module vulnerable to Cross-site Scripting
GHSA-2phw-mm8g-9jp8
OPNsense before 23.7 was discovered to contain insecure permissions in the directory /tmp.
GHSA-2phw-fwxh-2fw8
Multiple cross-site scripting (XSS) vulnerabilities in index.php in NewsPHP 2006 PRO allow remote attackers to inject arbitrary web script or HTML via the (1) words, (2) id, (3) cat_id, and (4) tim parameters, which are not sanitized before being returned in an error page. NOTE: it is possible that some of these vectors are resultant from an SQL injection issue.
GHSA-2phv-qp8w-5cv7
Directory traversal vulnerability in Enceladus Server Suite 3.9 allows remote attackers to list arbitrary directories and possibly cause a denial of service via "@" (at) characters in a CD (CWD) command, such as (1) "@/....\", (2) "@@@/..c:\", or (3) "@/..@/..".
GHSA-2phv-j68v-wwqx
pnpm vulnerable to Command Injection via environment variable substitution
GHSA-2phr-4qpj-wc46
Multiple unspecified vulnerabilities in SPIP before 1.9.2.o, 2.0.x before 2.0.18, and 2.1.x before 2.1.13 have unknown impact and attack vectors that are not related to cross-site scripting (XSS), different vulnerabilities than CVE-2012-2151.
GHSA-2phr-482w-4ppv
Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the startIp parameter in the formSetPPTPServer function.
GHSA-2phq-x5jx-m4c3
A flaw was found in ImageMagick in MagickCore/resample.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.
GHSA-2phq-jg7h-ghf4
Stack-based buffer overflow in the DCE/RPC preprocessor in Snort before 2.6.1.3, and 2.7 before beta 2; and Sourcefire Intrusion Sensor; allows remote attackers to execute arbitrary code via crafted SMB traffic.
GHSA-2phq-ghf8-6586
Jenkins Snow Commander Plugin prior to 2.0 vulnerable to Missing Authorization
GHSA-2php-v593-f386
Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTTP requests can lead to stack-based buffer overflow. An attacker can send a series of HTTP requests to trigger these vulnerabilities.This buffer overflow is related to the `ipaddr` request parameter for composing the `"ping -c <counts> <ipaddr> 2>&1 > %s &"` string.
GHSA-2php-rv2v-c3w8
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Michael Gangolf Custom post type templates for Elementor allows Stored XSS.This issue affects Custom post type templates for Elementor: from n/a through 1.10.1.
GHSA-2php-mg3p-mcqg
The GigPress WordPress plugin through 2.3.28 does not validate and escape some of its shortcode attributes before using them in SQL statement/s, which could allow any authenticated users, such as subscriber to perform SQL Injection attacks
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2pj3-3r8x-phjq A vulnerability, which was classified as critical, was found in Tenda FH1202 1.2.0.14(408). This affects an unknown part of the file /goform/qossetting of the component Web Management Interface. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 5.3 | 1% Низкий | больше 1 года назад | |
GHSA-2pj2-w39h-8vvq Untrusted search path vulnerability in the installer in Mozilla Firefox before 15.0, Firefox ESR 10.x before 10.0.7, Thunderbird before 15.0, and Thunderbird ESR 10.x before 10.0.7 on Windows allows local users to gain privileges via a Trojan horse executable file in a root directory. | 0% Низкий | больше 4 лет назад | ||
GHSA-2pj2-gchf-wmw7 Zip4j Origin Validation Error | CVSS3: 5.9 | 1% Низкий | больше 3 лет назад | |
GHSA-2pj2-82cm-7r39 PicoC 2.1 has a heap-based buffer overflow in StringStrcpy in cstdlib/string.c when called from ExpressionParseFunctionCall in expression.c. | 1% Низкий | больше 4 лет назад | ||
GHSA-2phx-w35g-x9vm Moodle Weak Password Recovery Mechanism for Forgotten Password | CVSS3: 7.3 | 1% Низкий | больше 4 лет назад | |
GHSA-2phx-jm8v-c5v7 A vulnerability in the Guest Shell of Cisco IOS XE Software could allow an authenticated, local attacker to perform directory traversal on the base Linux operating system of Cisco IOS XE Software. The vulnerability is due to incomplete validation of certain commands. An attacker could exploit this vulnerability by first accessing the Guest Shell and then entering specific commands. A successful exploit could allow the attacker to execute arbitrary code on the base Linux operating system. | CVSS3: 6.7 | 1% Низкий | больше 4 лет назад | |
GHSA-2phx-frhf-xr55 Mattermost Plugin Zoom allows any logged-in user to change Zoom meeting restrictions for arbitrary channels | CVSS3: 4.3 | 0% Низкий | 7 месяцев назад | |
GHSA-2phw-rgr7-5pvh Information Cards Module vulnerable to Cross-site Scripting | CVSS3: 6.1 | 1% Низкий | больше 3 лет назад | |
GHSA-2phw-mm8g-9jp8 OPNsense before 23.7 was discovered to contain insecure permissions in the directory /tmp. | CVSS3: 7.5 | 1% Низкий | около 3 лет назад | |
GHSA-2phw-fwxh-2fw8 Multiple cross-site scripting (XSS) vulnerabilities in index.php in NewsPHP 2006 PRO allow remote attackers to inject arbitrary web script or HTML via the (1) words, (2) id, (3) cat_id, and (4) tim parameters, which are not sanitized before being returned in an error page. NOTE: it is possible that some of these vectors are resultant from an SQL injection issue. | 2% Низкий | больше 4 лет назад | ||
GHSA-2phv-qp8w-5cv7 Directory traversal vulnerability in Enceladus Server Suite 3.9 allows remote attackers to list arbitrary directories and possibly cause a denial of service via "@" (at) characters in a CD (CWD) command, such as (1) "@/....\", (2) "@@@/..c:\", or (3) "@/..@/..". | 2% Низкий | больше 4 лет назад | ||
GHSA-2phv-j68v-wwqx pnpm vulnerable to Command Injection via environment variable substitution | CVSS3: 7.5 | 1% Низкий | 8 месяцев назад | |
GHSA-2phr-4qpj-wc46 Multiple unspecified vulnerabilities in SPIP before 1.9.2.o, 2.0.x before 2.0.18, and 2.1.x before 2.1.13 have unknown impact and attack vectors that are not related to cross-site scripting (XSS), different vulnerabilities than CVE-2012-2151. | 1% Низкий | больше 4 лет назад | ||
GHSA-2phr-482w-4ppv Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the startIp parameter in the formSetPPTPServer function. | CVSS3: 7.5 | 1% Низкий | почти 4 года назад | |
GHSA-2phq-x5jx-m4c3 A flaw was found in ImageMagick in MagickCore/resample.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability. | CVSS3: 5.5 | 1% Низкий | больше 4 лет назад | |
GHSA-2phq-jg7h-ghf4 Stack-based buffer overflow in the DCE/RPC preprocessor in Snort before 2.6.1.3, and 2.7 before beta 2; and Sourcefire Intrusion Sensor; allows remote attackers to execute arbitrary code via crafted SMB traffic. | 79% Высокий | больше 4 лет назад | ||
GHSA-2phq-ghf8-6586 Jenkins Snow Commander Plugin prior to 2.0 vulnerable to Missing Authorization | CVSS3: 5.4 | 1% Низкий | больше 4 лет назад | |
GHSA-2php-v593-f386 Multiple stack-based buffer overflow vulnerabilities exist in the formPingCmd functionality of Planet WGR-500 v1.3411b190912. A specially crafted series of HTTP requests can lead to stack-based buffer overflow. An attacker can send a series of HTTP requests to trigger these vulnerabilities.This buffer overflow is related to the `ipaddr` request parameter for composing the `"ping -c <counts> <ipaddr> 2>&1 > %s &"` string. | CVSS3: 8.8 | 1% Низкий | 11 месяцев назад | |
GHSA-2php-rv2v-c3w8 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Michael Gangolf Custom post type templates for Elementor allows Stored XSS.This issue affects Custom post type templates for Elementor: from n/a through 1.10.1. | CVSS3: 6.5 | 0% Низкий | почти 2 года назад | |
GHSA-2php-mg3p-mcqg The GigPress WordPress plugin through 2.3.28 does not validate and escape some of its shortcode attributes before using them in SQL statement/s, which could allow any authenticated users, such as subscriber to perform SQL Injection attacks | CVSS3: 8.8 | 1% Низкий | больше 3 лет назад |
Уязвимостей на страницу