Количество 365 324
Количество 365 324
GHSA-3w37-5p3p-jv92
Apache CXF vulnerable to Exposure of Sensitive Information
GHSA-3w36-wf5x-rjfv
Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute arbitrary code.
GHSA-3w36-ppm5-2f9j
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
GHSA-3w34-xv7m-phqr
Insufficient validation of untrusted input in Blink in Google Chrome prior to 79.0.3945.79 allowed a local attacker to bypass same origin policy via crafted clipboard content.
GHSA-3w33-h749-fgfr
Inappropriate implementation in cryptohome in Google Chrome on ChromeOS prior to 87.0.4280.66 allowed a remote attacker who had compromised the browser process to bypass discretionary access control via a malicious file.
GHSA-3w32-vr93-jm7m
An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The sort_by and start parameter can be used to perform an SQL injection attack. An attacker can use a browser to trigger these vulnerabilities, and no special tools are required.
GHSA-3w32-23wj-rxg3
Craft CMS Vulnerable to Unauthorized Deletion of Destination Folders During Forced Moves
GHSA-3w2x-jhm7-3gw3
Y.SAK allows remote attackers to execute arbitrary commands via shell metacharacters in the $no variable to (1) w_s3mbfm.cgi, (2) w_s3adix.cgi, or (3) w_s3sbfm.cgi.
GHSA-3w2x-9vcq-46w8
The IsPixelGray function in MagickCore/pixel-accessor.h in ImageMagick 7.0.3-8 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted image file.
GHSA-3w2w-p865-v7xr
Missing Authorization vulnerability in Elementor Image Optimizer by Elementor image-optimization allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Optimizer by Elementor: from n/a through <= 1.7.1.
GHSA-3w2w-73h7-hq3v
Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the NodeName2 parameter.
GHSA-3w2w-5pxh-222c
dirapi.dll in Adobe Shockwave Player before 11.5.9.615 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-2581, CVE-2010-4085, CVE-2010-4086, and CVE-2010-4088.
GHSA-3w2w-4v6h-c6q9
The xfs_fs_geometry function in fs/xfs/xfs_fsops.c in the Linux kernel before 2.6.38-rc6-git3 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via an FSGEOMETRY_V1 ioctl call.
GHSA-3w2v-v5mv-qqrj
A command injection vulnerability exists in the download and convert report feature of the ScienceLogic SL1 that takes unsanitized user?controlled input and passes it directly to a shell command. This allows for the injection of arbitrary commands to the underlying operating system.
GHSA-3w2v-f8x7-qc92
Missing Authorization vulnerability in rtCamp rtMedia for WordPress, BuddyPress and bbPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects rtMedia for WordPress, BuddyPress and bbPress: from n/a through 4.6.14.
GHSA-3w2r-c4w7-whmh
Incorrect access control in the getDiagnosisCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain diagnostic configuration and ping log contents via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
GHSA-3w2m-22gp-wc5v
phpProfiles before 2.1.1 uses world writable permissions for certain profile files and directories, which allows local users to modify or delete files, related to (1) users/include/do_makeprofile.inc.php and (2) users/include/copy.inc.php.
GHSA-3w2j-qqf9-7gjm
Elasticsearch does not apply its configurable input length restriction to a user-supplied pattern accepted by an intervals query. Compiling a deeply nested pattern drives unbounded recursion that exhausts the thread stack and raises a fatal error, terminating the Elasticsearch node process and causing a denial of service for that node. An authenticated user holding only read-only privileges on a single searchable index can trigger the condition with one small search request.
GHSA-3w2j-mvmp-4vx3
Transient DOS while processing DL NAS Transport message, as specified in 3GPP 24.501 v16.
GHSA-3w2j-jf2v-w2v3
The vivid_fb_ioctl function in drivers/media/platform/vivid/vivid-osd.c in the Linux kernel through 4.3.3 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel memory via a crafted application.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3w37-5p3p-jv92 Apache CXF vulnerable to Exposure of Sensitive Information | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | |
GHSA-3w36-wf5x-rjfv Remote Code Execution in PAN-OS 7.1.18 and earlier, PAN-OS 8.0.11 and earlier, and PAN-OS 8.1.2 and earlier with GlobalProtect Portal or GlobalProtect Gateway Interface enabled may allow an unauthenticated remote attacker to execute arbitrary code. | CVSS3: 8.1 | 46% Средний | больше 4 лет назад | |
GHSA-3w36-ppm5-2f9j Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability | CVSS3: 8.8 | 1% Низкий | больше 3 лет назад | |
GHSA-3w34-xv7m-phqr Insufficient validation of untrusted input in Blink in Google Chrome prior to 79.0.3945.79 allowed a local attacker to bypass same origin policy via crafted clipboard content. | CVSS3: 8.8 | 1% Низкий | больше 4 лет назад | |
GHSA-3w33-h749-fgfr Inappropriate implementation in cryptohome in Google Chrome on ChromeOS prior to 87.0.4280.66 allowed a remote attacker who had compromised the browser process to bypass discretionary access control via a malicious file. | 1% Низкий | больше 4 лет назад | ||
GHSA-3w32-vr93-jm7m An exploitable SQL injection vulnerability exists in the authenticated part of ERPNext v10.1.6. Specially crafted web requests can cause SQL injections resulting in data compromise. The sort_by and start parameter can be used to perform an SQL injection attack. An attacker can use a browser to trigger these vulnerabilities, and no special tools are required. | CVSS3: 8.8 | 1% Низкий | больше 4 лет назад | |
GHSA-3w32-23wj-rxg3 Craft CMS Vulnerable to Unauthorized Deletion of Destination Folders During Forced Moves | 0% Низкий | 2 месяца назад | ||
GHSA-3w2x-jhm7-3gw3 Y.SAK allows remote attackers to execute arbitrary commands via shell metacharacters in the $no variable to (1) w_s3mbfm.cgi, (2) w_s3adix.cgi, or (3) w_s3sbfm.cgi. | 3% Низкий | больше 4 лет назад | ||
GHSA-3w2x-9vcq-46w8 The IsPixelGray function in MagickCore/pixel-accessor.h in ImageMagick 7.0.3-8 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted image file. | CVSS3: 5.5 | 2% Низкий | больше 4 лет назад | |
GHSA-3w2w-p865-v7xr Missing Authorization vulnerability in Elementor Image Optimizer by Elementor image-optimization allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Optimizer by Elementor: from n/a through <= 1.7.1. | CVSS3: 4.3 | 0% Низкий | 6 месяцев назад | |
GHSA-3w2w-73h7-hq3v Stack-based buffer overflow in Advantech WebAccess (formerly BroadWin WebAccess) 7.2 allows remote attackers to execute arbitrary code via the NodeName2 parameter. | 3% Низкий | больше 4 лет назад | ||
GHSA-3w2w-5pxh-222c dirapi.dll in Adobe Shockwave Player before 11.5.9.615 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2010-2581, CVE-2010-4085, CVE-2010-4086, and CVE-2010-4088. | 4% Низкий | больше 4 лет назад | ||
GHSA-3w2w-4v6h-c6q9 The xfs_fs_geometry function in fs/xfs/xfs_fsops.c in the Linux kernel before 2.6.38-rc6-git3 does not initialize a certain structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via an FSGEOMETRY_V1 ioctl call. | 0% Низкий | больше 4 лет назад | ||
GHSA-3w2v-v5mv-qqrj A command injection vulnerability exists in the download and convert report feature of the ScienceLogic SL1 that takes unsanitized user?controlled input and passes it directly to a shell command. This allows for the injection of arbitrary commands to the underlying operating system. | CVSS3: 8.8 | 2% Низкий | около 3 лет назад | |
GHSA-3w2v-f8x7-qc92 Missing Authorization vulnerability in rtCamp rtMedia for WordPress, BuddyPress and bbPress allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects rtMedia for WordPress, BuddyPress and bbPress: from n/a through 4.6.14. | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
GHSA-3w2r-c4w7-whmh Incorrect access control in the getDiagnosisCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to obtain diagnostic configuration and ping log contents via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | 0% Низкий | 4 дня назад | ||
GHSA-3w2m-22gp-wc5v phpProfiles before 2.1.1 uses world writable permissions for certain profile files and directories, which allows local users to modify or delete files, related to (1) users/include/do_makeprofile.inc.php and (2) users/include/copy.inc.php. | 0% Низкий | больше 4 лет назад | ||
GHSA-3w2j-qqf9-7gjm Elasticsearch does not apply its configurable input length restriction to a user-supplied pattern accepted by an intervals query. Compiling a deeply nested pattern drives unbounded recursion that exhausts the thread stack and raises a fatal error, terminating the Elasticsearch node process and causing a denial of service for that node. An authenticated user holding only read-only privileges on a single searchable index can trigger the condition with one small search request. | CVSS3: 6.5 | 0% Низкий | 19 дней назад | |
GHSA-3w2j-mvmp-4vx3 Transient DOS while processing DL NAS Transport message, as specified in 3GPP 24.501 v16. | CVSS3: 7.5 | 0% Низкий | больше 2 лет назад | |
GHSA-3w2j-jf2v-w2v3 The vivid_fb_ioctl function in drivers/media/platform/vivid/vivid-osd.c in the Linux kernel through 4.3.3 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel memory via a crafted application. | CVSS3: 2.3 | 0% Низкий | больше 4 лет назад |
Уязвимостей на страницу