Количество 364 543
Количество 364 543
GHSA-3qcr-p3xq-5c4r
RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users to achieve a pool overflow (leading to Escalation of Privileges, Denial of Service, and Code Execution) via a crafted Device IO Control packet to a device.
GHSA-3qcq-w2m6-vwwx
An interaction between the AS/400 shared folders feature and Microsoft SNA Server 3.0 and earlier allows users to view each other's folders when the users share the same Local APPC LU.
GHSA-3qcq-p3m2-3c4p
Missing Authorization vulnerability in Select-Themes Don Peppe donpeppe allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Don Peppe: from n/a through <= 1.3.
GHSA-3qcq-28jc-g3f4
The Download Manager WordPress plugin before 3.2.83 does not protect file download's passwords, leaking it upon receiving an invalid one.
GHSA-3qcp-g78m-7jv9
A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.
GHSA-3qcp-9v8c-6jp7
Piranha CMS vulnerable to stored cross-site scripting (XSS)
GHSA-3qcm-pj6q-w4c5
Nodcms contains a cross-site request forgery vulnerability
GHSA-3qcj-r6mr-vw7f
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer allows DOM-Based XSS.This issue affects tagDiv Composer: from n/a through <= 5.4.2.
GHSA-3qch-fgcw-x72h
In phNxpNciHal_ext_process_nfc_init_rsp of phNxpNciHal_ext.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the NFC server with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-169258455
GHSA-3qcg-h4xg-5jrg
The All-in-One WP Migration Unlimited Extension plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.83. This is due to the 'Ai1wmve_Schedules_Controller::save' handler for 'admin_post_ai1wm_schedule_event_save' not verifying user capabilities before saving schedule data. This makes it possible for authenticated attackers, with subscriber-level access and above, to create scheduled export jobs and send backup notifications to attacker-controlled email addresses. Because such notifications include the random backup filename, full site backups can subsequently be downloaded from the target site, resulting in sensitive information exposure.
GHSA-3qcg-4hp6-rx66
IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 has an improper account-lockout setting, which makes it easier for remote attackers to obtain access via a brute-force attack.
GHSA-3qcf-jc2v-r99h
Directory traversal vulnerability in the third party tool from Powertech, as used to secure the iSeries AS/400 FTP server, allows remote attackers to access arbitrary files, including those from qsys.lib, via ".." sequences in a GET request.
GHSA-3qcf-hphp-2m63
In imgsys, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation Patch ID: ALPS08518692; Issue ID: MSV-1012.
GHSA-3qcf-857g-5p4x
IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by a CSV injection vulnerability. By persuading a victim to open a specially crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system.
GHSA-3qcc-hgxf-jmc5
IBM Tivoli Monitoring (ITM) 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, 6.2.3 through FP05, and 6.3.0 before FP04 allows remote authenticated users to bypass intended access restrictions and execute arbitrary commands by leveraging Take Action view authority to modify in-progress commands.
GHSA-3qcc-7w94-cc7w
SQL injection vulnerability in DWdirectory 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the search parameter to the /search URI.
GHSA-3qc9-35qv-7xpj
To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
GHSA-3qc8-c2c9-9pgw
Out-of-bounds read in subsystem for Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow an unauthenticated user to potentially enable information disclosure and/or denial of service via network access.
GHSA-3qc8-39jf-7268
libtiff up to 3.7.0 allows remote attackers to cause a denial of service (application crash) via a TIFF image header with a zero "YCbCr subsampling" value, which causes a divide-by-zero error in (1) tif_strip.c and (2) tif_tile.c, a different vulnerability than CVE-2004-0804.
GHSA-3qc6-x7mq-579v
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Roberto Alicata ra_qrcode allows Stored XSS.This issue affects ra_qrcode: from n/a through 2.1.0.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3qcr-p3xq-5c4r RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users to achieve a pool overflow (leading to Escalation of Privileges, Denial of Service, and Code Execution) via a crafted Device IO Control packet to a device. | CVSS3: 7.8 | 0% Низкий | больше 4 лет назад | |
GHSA-3qcq-w2m6-vwwx An interaction between the AS/400 shared folders feature and Microsoft SNA Server 3.0 and earlier allows users to view each other's folders when the users share the same Local APPC LU. | 6% Низкий | больше 4 лет назад | ||
GHSA-3qcq-p3m2-3c4p Missing Authorization vulnerability in Select-Themes Don Peppe donpeppe allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Don Peppe: from n/a through <= 1.3. | CVSS3: 4.3 | 0% Низкий | 7 месяцев назад | |
GHSA-3qcq-28jc-g3f4 The Download Manager WordPress plugin before 3.2.83 does not protect file download's passwords, leaking it upon receiving an invalid one. | CVSS3: 7.5 | 2% Низкий | больше 2 лет назад | |
GHSA-3qcp-g78m-7jv9 A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux. | CVSS3: 8.8 | 66% Средний | больше 4 лет назад | |
GHSA-3qcp-9v8c-6jp7 Piranha CMS vulnerable to stored cross-site scripting (XSS) | 0% Низкий | 10 месяцев назад | ||
GHSA-3qcm-pj6q-w4c5 Nodcms contains a cross-site request forgery vulnerability | CVSS3: 4.3 | 0% Низкий | 5 месяцев назад | |
GHSA-3qcj-r6mr-vw7f Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer allows DOM-Based XSS.This issue affects tagDiv Composer: from n/a through <= 5.4.2. | CVSS3: 6.1 | 0% Низкий | 7 месяцев назад | |
GHSA-3qch-fgcw-x72h In phNxpNciHal_ext_process_nfc_init_rsp of phNxpNciHal_ext.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the NFC server with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-169258455 | 0% Низкий | больше 4 лет назад | ||
GHSA-3qcg-h4xg-5jrg The All-in-One WP Migration Unlimited Extension plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.83. This is due to the 'Ai1wmve_Schedules_Controller::save' handler for 'admin_post_ai1wm_schedule_event_save' not verifying user capabilities before saving schedule data. This makes it possible for authenticated attackers, with subscriber-level access and above, to create scheduled export jobs and send backup notifications to attacker-controlled email addresses. Because such notifications include the random backup filename, full site backups can subsequently be downloaded from the target site, resulting in sensitive information exposure. | CVSS3: 6.5 | 0% Низкий | 4 месяца назад | |
GHSA-3qcg-4hp6-rx66 IBM WebSphere eXtreme Scale 7.1.0 before 7.1.0.3 and 7.1.1 before 7.1.1.1 has an improper account-lockout setting, which makes it easier for remote attackers to obtain access via a brute-force attack. | 1% Низкий | больше 4 лет назад | ||
GHSA-3qcf-jc2v-r99h Directory traversal vulnerability in the third party tool from Powertech, as used to secure the iSeries AS/400 FTP server, allows remote attackers to access arbitrary files, including those from qsys.lib, via ".." sequences in a GET request. | 2% Низкий | больше 4 лет назад | ||
GHSA-3qcf-hphp-2m63 In imgsys, there is a possible information disclosure due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is needed for exploitation Patch ID: ALPS08518692; Issue ID: MSV-1012. | CVSS3: 6.3 | 0% Низкий | больше 2 лет назад | |
GHSA-3qcf-857g-5p4x IBM Aspera Console 3.4.0 through 3.4.4 could allow a remote authenticated attacker to execute arbitrary code on the system, caused by a CSV injection vulnerability. By persuading a victim to open a specially crafted file, an attacker could exploit this vulnerability to execute arbitrary code on the system. | CVSS3: 8 | 1% Низкий | почти 2 года назад | |
GHSA-3qcc-hgxf-jmc5 IBM Tivoli Monitoring (ITM) 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, 6.2.3 through FP05, and 6.3.0 before FP04 allows remote authenticated users to bypass intended access restrictions and execute arbitrary commands by leveraging Take Action view authority to modify in-progress commands. | 2% Низкий | больше 4 лет назад | ||
GHSA-3qcc-7w94-cc7w SQL injection vulnerability in DWdirectory 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the search parameter to the /search URI. | 1% Низкий | больше 4 лет назад | ||
GHSA-3qc9-35qv-7xpj To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used. | больше 3 лет назад | |||
GHSA-3qc8-c2c9-9pgw Out-of-bounds read in subsystem for Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow an unauthenticated user to potentially enable information disclosure and/or denial of service via network access. | CVSS3: 9.1 | 2% Низкий | больше 4 лет назад | |
GHSA-3qc8-39jf-7268 libtiff up to 3.7.0 allows remote attackers to cause a denial of service (application crash) via a TIFF image header with a zero "YCbCr subsampling" value, which causes a divide-by-zero error in (1) tif_strip.c and (2) tif_tile.c, a different vulnerability than CVE-2004-0804. | 2% Низкий | больше 4 лет назад | ||
GHSA-3qc6-x7mq-579v Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Roberto Alicata ra_qrcode allows Stored XSS.This issue affects ra_qrcode: from n/a through 2.1.0. | CVSS3: 6.5 | 0% Низкий | почти 2 года назад |
Уязвимостей на страницу