Количество 365 324
Количество 365 324
GHSA-3w95-9p64-7q7q
FlatNuke 2.5.3 allows remote attackers to obtain sensitive information via invalid parameters to certain scripts, which leaks the web document root in an error message.
GHSA-3w95-9g93-92fj
In vcu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07645149; Issue ID: ALPS07645178.
GHSA-3w95-95fc-gjxf
SQL injection vulnerability in philboard_forum.asp in Husrev BlackBoard 2.0.2 allows remote attackers to execute arbitrary SQL commands via the forumid parameter.
GHSA-3w95-3q7c-6v47
services/go.php in Horde Application Framework 3.0.0 through 3.0.10 and 3.1.0 through 3.1.1 does not properly restrict its image proxy capability, which allows remote attackers to perform "Web tunneling" attacks and use the server as a proxy via (1) http, (2) https, and (3) ftp URL in the url parameter, which is requested from the server.
GHSA-3w94-w3gc-69pw
SQL injection vulnerability in sorter.php in the phpManufaktur kitForm extension 0.43 and earlier for the KeepInTouch (KIT) module allows remote attackers to execute arbitrary SQL commands via the sorter_value parameter.
GHSA-3w94-vq2x-v5wr
ethereum does not check transaction malleability for EIP-2930, EIP-1559 and EIP-7702 transactions
GHSA-3w94-4jxf-2v59
SQL injection vulnerability in gallery.php in MyCard 1.0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.
GHSA-3w93-xggv-pqrq
IBM Jazz Foundation (IBM Rational Engineering Lifecycle Manager 5.0 through 6.0.6) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152740.
GHSA-3w93-f425-v54j
Unauthenticated Broken Access Control in Classified Listing <= 5.3.8 versions.
GHSA-3w8x-qf95-v2x7
Stack-based buffer overflow in Novell iPrint Client before 5.90 allows remote attackers to execute arbitrary code via unspecified vectors.
GHSA-3w8x-p539-469j
In query of DownloadManager.java, there is a possible read/write of arbitrary files due to a permissions bypass. This could lead to local information disclosure and file rewriting with no additional execution privileges needed. User interaction is not needed for exploitation.
GHSA-3w8x-76pc-54fp
The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the gd-rating-system-information page.
GHSA-3w8w-mhj7-j5rc
systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace. This occurs in parse_elf_object in shared/elf-util.c. The exploitation methodology is to crash a binary calling the same function recursively, and put it in a deeply nested directory to make its backtrace large enough to cause the deadlock. This must be done 16 times when MaxConnections=16 is set for the systemd/units/systemd-coredump.socket file.
GHSA-3w8w-875g-xvfg
Foxit PDF Reader before 12.0.1 and PDF Editor before 12.0.1 allow a NULL pointer dereference when this.Span is used for oState of Collab.addStateModel, because this.Span.text can be NULL.
GHSA-3w8r-3jh9-89v9
xxl-job-admin vulnerable to Insecure Permissions
GHSA-3w8r-2x8f-g5jx
It was reported that watchman in openshift node-utils creates /var/run/watchman.pid and /var/log/watchman.ouput with world writable permission.
GHSA-3w8q-xq97-5j7x
Rhino has high CPU usage and potential DoS when passing specific numbers to `toFixed()` function
GHSA-3w8q-xg7c-33gv
syslogd in the syslog subsystem in Apple iOS before 8 and Apple TV before 7 allows local users to change the permissions of arbitrary files via a symlink attack on an unspecified file.
GHSA-3w8q-vg6g-cg46
In the Linux kernel, the following vulnerability has been resolved: crypto: lib/mpi - avoid null pointer deref in mpi_cmp_ui() During NVMeTCP Authentication a controller can trigger a kernel oops by specifying the 8192 bit Diffie Hellman group and passing a correctly sized, but zeroed Diffie Hellamn value. mpi_cmp_ui() was detecting this if the second parameter was 0, but 1 is passed from dh_is_pubkey_valid(). This causes the null pointer u->d to be dereferenced towards the end of mpi_cmp_ui()
GHSA-3w8q-3783-r4v7
A vulnerability classified as problematic was found in LitmusChaos Litmus up to 3.19.0. Affected by this vulnerability is an unknown functionality. The manipulation of the argument projectID leads to improper control of resource identifiers. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3w95-9p64-7q7q FlatNuke 2.5.3 allows remote attackers to obtain sensitive information via invalid parameters to certain scripts, which leaks the web document root in an error message. | 3% Низкий | больше 4 лет назад | ||
GHSA-3w95-9g93-92fj In vcu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07645149; Issue ID: ALPS07645178. | CVSS3: 6.7 | 0% Низкий | около 3 лет назад | |
GHSA-3w95-95fc-gjxf SQL injection vulnerability in philboard_forum.asp in Husrev BlackBoard 2.0.2 allows remote attackers to execute arbitrary SQL commands via the forumid parameter. | 1% Низкий | больше 4 лет назад | ||
GHSA-3w95-3q7c-6v47 services/go.php in Horde Application Framework 3.0.0 through 3.0.10 and 3.1.0 through 3.1.1 does not properly restrict its image proxy capability, which allows remote attackers to perform "Web tunneling" attacks and use the server as a proxy via (1) http, (2) https, and (3) ftp URL in the url parameter, which is requested from the server. | 2% Низкий | больше 4 лет назад | ||
GHSA-3w94-w3gc-69pw SQL injection vulnerability in sorter.php in the phpManufaktur kitForm extension 0.43 and earlier for the KeepInTouch (KIT) module allows remote attackers to execute arbitrary SQL commands via the sorter_value parameter. | 1% Низкий | больше 4 лет назад | ||
GHSA-3w94-vq2x-v5wr ethereum does not check transaction malleability for EIP-2930, EIP-1559 and EIP-7702 transactions | 0% Низкий | около 1 года назад | ||
GHSA-3w94-4jxf-2v59 SQL injection vulnerability in gallery.php in MyCard 1.0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter. | 1% Низкий | больше 4 лет назад | ||
GHSA-3w93-xggv-pqrq IBM Jazz Foundation (IBM Rational Engineering Lifecycle Manager 5.0 through 6.0.6) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 152740. | CVSS3: 5.4 | 1% Низкий | больше 4 лет назад | |
GHSA-3w93-f425-v54j Unauthenticated Broken Access Control in Classified Listing <= 5.3.8 versions. | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
GHSA-3w8x-qf95-v2x7 Stack-based buffer overflow in Novell iPrint Client before 5.90 allows remote attackers to execute arbitrary code via unspecified vectors. | 6% Низкий | больше 4 лет назад | ||
GHSA-3w8x-p539-469j In query of DownloadManager.java, there is a possible read/write of arbitrary files due to a permissions bypass. This could lead to local information disclosure and file rewriting with no additional execution privileges needed. User interaction is not needed for exploitation. | CVSS3: 7.7 | 0% Низкий | почти 2 года назад | |
GHSA-3w8x-76pc-54fp The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the gd-rating-system-information page. | CVSS3: 7.5 | 4% Низкий | больше 4 лет назад | |
GHSA-3w8w-mhj7-j5rc systemd 250 and 251 allows local users to achieve a systemd-coredump deadlock by triggering a crash that has a long backtrace. This occurs in parse_elf_object in shared/elf-util.c. The exploitation methodology is to crash a binary calling the same function recursively, and put it in a deeply nested directory to make its backtrace large enough to cause the deadlock. This must be done 16 times when MaxConnections=16 is set for the systemd/units/systemd-coredump.socket file. | CVSS3: 5.5 | 0% Низкий | почти 4 года назад | |
GHSA-3w8w-875g-xvfg Foxit PDF Reader before 12.0.1 and PDF Editor before 12.0.1 allow a NULL pointer dereference when this.Span is used for oState of Collab.addStateModel, because this.Span.text can be NULL. | CVSS3: 7.5 | 1% Низкий | около 4 лет назад | |
GHSA-3w8r-3jh9-89v9 xxl-job-admin vulnerable to Insecure Permissions | CVSS3: 5.4 | 0% Низкий | почти 3 года назад | |
GHSA-3w8r-2x8f-g5jx It was reported that watchman in openshift node-utils creates /var/run/watchman.pid and /var/log/watchman.ouput with world writable permission. | CVSS3: 5.5 | 0% Низкий | около 4 лет назад | |
GHSA-3w8q-xq97-5j7x Rhino has high CPU usage and potential DoS when passing specific numbers to `toFixed()` function | 0% Низкий | 9 месяцев назад | ||
GHSA-3w8q-xg7c-33gv syslogd in the syslog subsystem in Apple iOS before 8 and Apple TV before 7 allows local users to change the permissions of arbitrary files via a symlink attack on an unspecified file. | 0% Низкий | больше 4 лет назад | ||
GHSA-3w8q-vg6g-cg46 In the Linux kernel, the following vulnerability has been resolved: crypto: lib/mpi - avoid null pointer deref in mpi_cmp_ui() During NVMeTCP Authentication a controller can trigger a kernel oops by specifying the 8192 bit Diffie Hellman group and passing a correctly sized, but zeroed Diffie Hellamn value. mpi_cmp_ui() was detecting this if the second parameter was 0, but 1 is passed from dh_is_pubkey_valid(). This causes the null pointer u->d to be dereferenced towards the end of mpi_cmp_ui() | CVSS3: 7.5 | 1% Низкий | 9 месяцев назад | |
GHSA-3w8q-3783-r4v7 A vulnerability classified as problematic was found in LitmusChaos Litmus up to 3.19.0. Affected by this vulnerability is an unknown functionality. The manipulation of the argument projectID leads to improper control of resource identifiers. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 4.3 | 0% Низкий | около 1 года назад |
Уязвимостей на страницу