Количество 364 463
Количество 364 463
GHSA-3q2v-fjjf-4p2w
An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when processing a malicious terraform file. This issue impacts Checkov 2.0 versions earlier than Checkov 2.0.139. Checkov 1.0 versions are not impacted.
GHSA-3q2v-922f-6rc3
In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Fix sysfs leak in alloc_iommu() iommu_device_sysfs_add() is called before, so is has to be cleaned on subsequent errors.
GHSA-3q2r-98pg-wrxg
An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE-2020-0625, CVE-2020-0626, CVE-2020-0627, CVE-2020-0628, CVE-2020-0630, CVE-2020-0631, CVE-2020-0632, CVE-2020-0633.
GHSA-3q2r-55v2-9hwf
Multiple unknown vulnjerabilities HP OpenView Event Correlation Services (OV ECS) 3.32 and 3.33 allow attackers to cause a denial of service or execute arbitrary code.
GHSA-3q2q-j727-g75q
NetBSD on a multi-homed host allows ARP packets on one network to modify ARP entries on another connected network.
GHSA-3q2q-8m5p-gc7q
The 'name' parameter of the process_registration.php resource does not validate the characters received and they are sent unfiltered to the database.
GHSA-3q2p-xj33-xm8j
Insufficient escaping in the “Copy as cURL” feature could potentially be used to trick a user into executing unexpected code. This vulnerability affects Firefox < 141, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1.
GHSA-3q2p-72cj-682c
File Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existent Path
GHSA-3q2m-pwgp-2xph
Dell OS Recovery Tool, versions 2.2.4013, 2.3.7012.0, and 2.3.7515.0 contain an Improper Access Control Vulnerability. A local authenticated non-administrator user could potentially exploit this vulnerability, leading to the elevation of privilege on the system.
GHSA-3q2j-jxjj-f39g
NVIDIA Windows GPU Display Driver for Windows, all versions, contains a vulnerability in the kernel driver (nvlddmkm.sys) where a NULL pointer dereference may lead to system crash.
GHSA-3q2j-hghg-2fv5
An out-of-bounds read vulnerability exists in the EMF functionality of PDF-XChange Editor version 10.5.2.395. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information.
GHSA-3q2j-hfh6-wm75
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to evade behind-the-firewall protection of app-linked resources via a Broken Authentication vulnerability in the `makeRequest` gadget resource. The affected versions are before version 8.13.3, and from version 8.14.0 before 8.14.1.
GHSA-3q2j-29qj-crmr
The Login Security, FireWall, Malware removal by CleanTalk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the page URL in all versions up to, and including, 2.168 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
GHSA-3q2h-7599-7r76
TLS ECH decryptor crash in Wireshark 4.6.0 to 4.6.6 allows denial of service
GHSA-3q2g-r99g-8h69
The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle errors from TIFFReadRGBAImageOriented(), leading to uninitialized memory use when processing certain TIFF image files.
GHSA-3q2g-h6qw-ffgj
SQL injection vulnerability in modules.php in the Okul 1.0 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the okulid parameter in an okullar action.
GHSA-3q2g-h5vg-gwqf
smcboot in Sun SMC (Sun Management Center) 2.0 in Solaris 8 allows local users to delete arbitrary files via a symlink attack on /tmp/smc$SMC_PORT.
GHSA-3q2g-cq44-pjqq
The The Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.7.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.
GHSA-3q2g-2xmv-33rc
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0840.
GHSA-3q2f-wr5w-xp3w
Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to inject arbitary code via the X-Forwarded-Host Header.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3q2v-fjjf-4p2w An unsafe deserialization vulnerability in Bridgecrew Checkov by Prisma Cloud allows arbitrary code execution when processing a malicious terraform file. This issue impacts Checkov 2.0 versions earlier than Checkov 2.0.139. Checkov 1.0 versions are not impacted. | 1% Низкий | больше 4 лет назад | ||
GHSA-3q2v-922f-6rc3 In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Fix sysfs leak in alloc_iommu() iommu_device_sysfs_add() is called before, so is has to be cleaned on subsequent errors. | CVSS3: 5.5 | 0% Низкий | больше 2 лет назад | |
GHSA-3q2r-98pg-wrxg An elevation of privilege vulnerability exists in the way that the Windows Search Indexer handles objects in memory, aka 'Windows Search Indexer Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0613, CVE-2020-0614, CVE-2020-0623, CVE-2020-0625, CVE-2020-0626, CVE-2020-0627, CVE-2020-0628, CVE-2020-0630, CVE-2020-0631, CVE-2020-0632, CVE-2020-0633. | 1% Низкий | больше 4 лет назад | ||
GHSA-3q2r-55v2-9hwf Multiple unknown vulnjerabilities HP OpenView Event Correlation Services (OV ECS) 3.32 and 3.33 allow attackers to cause a denial of service or execute arbitrary code. | 1% Низкий | больше 4 лет назад | ||
GHSA-3q2q-j727-g75q NetBSD on a multi-homed host allows ARP packets on one network to modify ARP entries on another connected network. | 1% Низкий | больше 4 лет назад | ||
GHSA-3q2q-8m5p-gc7q The 'name' parameter of the process_registration.php resource does not validate the characters received and they are sent unfiltered to the database. | CVSS3: 9.8 | почти 3 года назад | ||
GHSA-3q2p-xj33-xm8j Insufficient escaping in the “Copy as cURL” feature could potentially be used to trick a user into executing unexpected code. This vulnerability affects Firefox < 141, Firefox ESR < 128.13, Firefox ESR < 140.1, Thunderbird < 141, Thunderbird < 128.13, and Thunderbird < 140.1. | CVSS3: 8.1 | 0% Низкий | около 1 года назад | |
GHSA-3q2p-72cj-682c File Browser: Improper Access Control Occurs via Pre-Created Public Share for a Non-existent Path | CVSS3: 8.4 | 0% Низкий | 3 месяца назад | |
GHSA-3q2m-pwgp-2xph Dell OS Recovery Tool, versions 2.2.4013, 2.3.7012.0, and 2.3.7515.0 contain an Improper Access Control Vulnerability. A local authenticated non-administrator user could potentially exploit this vulnerability, leading to the elevation of privilege on the system. | CVSS3: 7.3 | 0% Низкий | почти 3 года назад | |
GHSA-3q2j-jxjj-f39g NVIDIA Windows GPU Display Driver for Windows, all versions, contains a vulnerability in the kernel driver (nvlddmkm.sys) where a NULL pointer dereference may lead to system crash. | 0% Низкий | больше 4 лет назад | ||
GHSA-3q2j-hghg-2fv5 An out-of-bounds read vulnerability exists in the EMF functionality of PDF-XChange Editor version 10.5.2.395. By using a specially crafted EMF file, an attacker could exploit this vulnerability to perform an out-of-bounds read, potentially leading to the disclosure of sensitive information. | CVSS3: 6.5 | 1% Низкий | около 1 года назад | |
GHSA-3q2j-hfh6-wm75 Affected versions of Atlassian Jira Server and Data Center allow remote attackers to evade behind-the-firewall protection of app-linked resources via a Broken Authentication vulnerability in the `makeRequest` gadget resource. The affected versions are before version 8.13.3, and from version 8.14.0 before 8.14.1. | CVSS3: 7.2 | 2% Низкий | больше 4 лет назад | |
GHSA-3q2j-29qj-crmr The Login Security, FireWall, Malware removal by CleanTalk plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the page URL in all versions up to, and including, 2.168 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | CVSS3: 7.2 | 0% Низкий | 9 месяцев назад | |
GHSA-3q2h-7599-7r76 TLS ECH decryptor crash in Wireshark 4.6.0 to 4.6.6 allows denial of service | CVSS3: 5.5 | 0% Низкий | около 2 месяцев назад | |
GHSA-3q2g-r99g-8h69 The tiff_document_render() and tiff_document_get_thumbnail() functions in the TIFF document backend in GNOME Evince through 3.32.0 did not handle errors from TIFFReadRGBAImageOriented(), leading to uninitialized memory use when processing certain TIFF image files. | CVSS3: 5.5 | 1% Низкий | больше 4 лет назад | |
GHSA-3q2g-h6qw-ffgj SQL injection vulnerability in modules.php in the Okul 1.0 module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via the okulid parameter in an okullar action. | 1% Низкий | больше 4 лет назад | ||
GHSA-3q2g-h5vg-gwqf smcboot in Sun SMC (Sun Management Center) 2.0 in Solaris 8 allows local users to delete arbitrary files via a symlink attack on /tmp/smc$SMC_PORT. | 0% Низкий | больше 4 лет назад | ||
GHSA-3q2g-cq44-pjqq The The Logo Slider – Logo Showcase, Logo Carousel, Logo Gallery and Client Logo Presentation plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.7.3. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes. | CVSS3: 7.3 | 0% Низкий | больше 1 года назад | |
GHSA-3q2g-2xmv-33rc An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Windows Kernel Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0840. | CVSS3: 5.5 | 2% Низкий | больше 4 лет назад | |
GHSA-3q2f-wr5w-xp3w Cross-site scripting (XSS) via Host Header injection in PKP Open Journals System 2.4.8 >= 3.3 allows remote attackers to inject arbitary code via the X-Forwarded-Host Header. | CVSS3: 6.1 | 6% Низкий | больше 4 лет назад |
Уязвимостей на страницу