Количество 364 463
Количество 364 463
GHSA-3pvm-rcw8-28wj
An unhandled memory allocation failure in Core/AP4IkmsAtom.cpp of Bento 1.5.1-628 causes a NULL pointer dereference, leading to a denial of service (DOS).
GHSA-3pvm-hf79-jr5w
Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. Cisco Bug IDs: CSCvg70904.
GHSA-3pvm-h88r-3692
cPanel before 60.0.25 allows attackers to discover file contents during file copy operations (SEC-185).
GHSA-3pvj-q7qj-89fg
A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL library. If an attacker manages to exhaust the heap space, this error is not detected and may lead to libssh using a partially initialized cipher context. This occurs because the OpenSSL error code returned aliases with the SSH_OK code, resulting in libssh not properly detecting the error returned by the OpenSSL library. This issue can lead to undefined behavior, including compromised data confidentiality and integrity or crashes.
GHSA-3pvj-jv98-qhjq
Chrome DevTools for agents: daemon.pid write follows symlinks in /tmp fallback runtime directory
GHSA-3pvj-gf5m-rhhf
MapUrlToZone Security Feature Bypass Vulnerability
GHSA-3pvh-h2xv-4jw7
PDF-XChange Editor PNG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PNG files. Crafted data in a PNG file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18663.
GHSA-3pvh-8v83-x7v2
Allowing long password leads to denial of service in polonel/trudesk in GitHub repository polonel/trudesk prior to 1.2.2. This vulnerability can be abused by doing a DDoS attack for which genuine users will not able to access resources/applications.
GHSA-3pvh-63gf-j9mw
LangBot: Authenticated RCE Via MCP Configuration
GHSA-3pvh-4h3w-f294
There is an invalid free in ReadImage in input-bmp.ci that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecified other impact.
GHSA-3pvh-38hr-8x7c
The Trend Controls IC protocol through 2022-05-06 allows Cleartext Transmission of Sensitive Information. According to FSCT-2022-0050, there is a Trend Controls Inter-Controller (IC) protocol cleartext transmission of credentials issue. The affected components are characterized as: Inter-Controller (IC) protocol (57612/UDP). The potential impact is: Compromise of credentials. Several Trend Controls building automation controllers utilize the Inter-Controller (IC) protocol in for information exchange and automation purposes. This protocol offers authentication in the form of a 4-digit PIN in order to protect access to sensitive operations like strategy uploads and downloads as well as optional 0-30 character username and password protection for web page access protection. Both the PIN and usernames and passwords are transmitted in cleartext, allowing an attacker with passive interception capabilities to obtain these credentials. Credentials are transmitted in cleartext. An attacker w...
GHSA-3pvg-8h3w-fc9m
Various Lexmark products have stored XSS in the embedded web server used in older generation Lexmark devices. Affected products are available in http://support.lexmark.com/index?page=content&id=TE935&locale=en&userlocale=EN_US.
GHSA-3pvf-vxrv-hh9c
Craft CMS: Low-privilege users could read private asset contents when editing an asset (IDOR)
GHSA-3pvf-vxc3-wr36
Cross-site request forgery (CSRF) vulnerability in news/admin.php in N-13 News 3.4, 3.7, and 4.0 allows remote attackers to hijack the authentication of administrators for requests that create new users via the options action. NOTE: some of these details are obtained from third party information.
GHSA-3pvf-9jm4-6vxf
An issue in urban_project mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
GHSA-3pvf-92c7-q7p5
Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability
GHSA-3pvf-8762-r99w
The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate an argument to an unspecified system call, which allows local users to gain privileges via a crafted application, aka "Windows Driver Class Registration Vulnerability."
GHSA-3pvc-h22x-rq5v
The Sleuth Kit through 4.14.0 contains an out-of-bounds read vulnerability in the ISO9660 filesystem parser where the parse_susp() function trusts len_id, len_des, and len_src fields from the disk image to memcpy data into a stack buffer without verifying that the source data falls within the parsed SUSP block. An attacker can craft a malicious ISO image that causes reads past the end of the SUSP data buffer, and a zero-length SUSP entry can trigger an infinite parsing loop.
GHSA-3pvc-g892-vvj8
SQL injection vulnerability in news.php in DGNews 2.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter in a newslist action. NOTE: this issue can produce resultant cross-site scripting (XSS).
GHSA-3pv8-6f4r-ffg2
tar has a PAX header desynchronization issue
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3pvm-rcw8-28wj An unhandled memory allocation failure in Core/AP4IkmsAtom.cpp of Bento 1.5.1-628 causes a NULL pointer dereference, leading to a denial of service (DOS). | 1% Низкий | больше 4 лет назад | ||
GHSA-3pvm-hf79-jr5w Multiple vulnerabilities in the web-based management interface of Cisco Unified Contact Center Express (Unified CCX) could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. Cisco Bug IDs: CSCvg70904. | CVSS3: 6.1 | 1% Низкий | больше 4 лет назад | |
GHSA-3pvm-h88r-3692 cPanel before 60.0.25 allows attackers to discover file contents during file copy operations (SEC-185). | CVSS3: 6.5 | 1% Низкий | больше 4 лет назад | |
GHSA-3pvj-q7qj-89fg A flaw was found in libssh when using the ChaCha20 cipher with the OpenSSL library. If an attacker manages to exhaust the heap space, this error is not detected and may lead to libssh using a partially initialized cipher context. This occurs because the OpenSSL error code returned aliases with the SSH_OK code, resulting in libssh not properly detecting the error returned by the OpenSSL library. This issue can lead to undefined behavior, including compromised data confidentiality and integrity or crashes. | CVSS3: 5 | 1% Низкий | около 1 года назад | |
GHSA-3pvj-jv98-qhjq Chrome DevTools for agents: daemon.pid write follows symlinks in /tmp fallback runtime directory | CVSS3: 6.1 | 0% Низкий | 2 месяца назад | |
GHSA-3pvj-gf5m-rhhf MapUrlToZone Security Feature Bypass Vulnerability | CVSS3: 4.3 | 1% Низкий | больше 1 года назад | |
GHSA-3pvh-h2xv-4jw7 PDF-XChange Editor PNG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PDF-XChange Editor. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PNG files. Crafted data in a PNG file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18663. | CVSS3: 7.8 | 1% Низкий | больше 2 лет назад | |
GHSA-3pvh-8v83-x7v2 Allowing long password leads to denial of service in polonel/trudesk in GitHub repository polonel/trudesk prior to 1.2.2. This vulnerability can be abused by doing a DDoS attack for which genuine users will not able to access resources/applications. | CVSS3: 6.5 | 1% Низкий | больше 4 лет назад | |
GHSA-3pvh-63gf-j9mw LangBot: Authenticated RCE Via MCP Configuration | CVSS3: 8.8 | 0% Низкий | около 1 месяца назад | |
GHSA-3pvh-4h3w-f294 There is an invalid free in ReadImage in input-bmp.ci that leads to a Segmentation fault in sam2p 0.49.4. A crafted input will lead to a denial of service or possibly unspecified other impact. | CVSS3: 9.8 | 2% Низкий | больше 4 лет назад | |
GHSA-3pvh-38hr-8x7c The Trend Controls IC protocol through 2022-05-06 allows Cleartext Transmission of Sensitive Information. According to FSCT-2022-0050, there is a Trend Controls Inter-Controller (IC) protocol cleartext transmission of credentials issue. The affected components are characterized as: Inter-Controller (IC) protocol (57612/UDP). The potential impact is: Compromise of credentials. Several Trend Controls building automation controllers utilize the Inter-Controller (IC) protocol in for information exchange and automation purposes. This protocol offers authentication in the form of a 4-digit PIN in order to protect access to sensitive operations like strategy uploads and downloads as well as optional 0-30 character username and password protection for web page access protection. Both the PIN and usernames and passwords are transmitted in cleartext, allowing an attacker with passive interception capabilities to obtain these credentials. Credentials are transmitted in cleartext. An attacker w... | CVSS3: 6.5 | 0% Низкий | почти 4 года назад | |
GHSA-3pvg-8h3w-fc9m Various Lexmark products have stored XSS in the embedded web server used in older generation Lexmark devices. Affected products are available in http://support.lexmark.com/index?page=content&id=TE935&locale=en&userlocale=EN_US. | 1% Низкий | больше 4 лет назад | ||
GHSA-3pvf-vxrv-hh9c Craft CMS: Low-privilege users could read private asset contents when editing an asset (IDOR) | 0% Низкий | 5 месяцев назад | ||
GHSA-3pvf-vxc3-wr36 Cross-site request forgery (CSRF) vulnerability in news/admin.php in N-13 News 3.4, 3.7, and 4.0 allows remote attackers to hijack the authentication of administrators for requests that create new users via the options action. NOTE: some of these details are obtained from third party information. | 1% Низкий | больше 4 лет назад | ||
GHSA-3pvf-9jm4-6vxf An issue in urban_project mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | CVSS3: 5.3 | 1% Низкий | больше 2 лет назад | |
GHSA-3pvf-92c7-q7p5 Windows Cloud Files Mini Filter Driver Information Disclosure Vulnerability | CVSS3: 5.5 | 7% Низкий | больше 2 лет назад | |
GHSA-3pvf-8762-r99w The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly validate an argument to an unspecified system call, which allows local users to gain privileges via a crafted application, aka "Windows Driver Class Registration Vulnerability." | 1% Низкий | больше 4 лет назад | ||
GHSA-3pvc-h22x-rq5v The Sleuth Kit through 4.14.0 contains an out-of-bounds read vulnerability in the ISO9660 filesystem parser where the parse_susp() function trusts len_id, len_des, and len_src fields from the disk image to memcpy data into a stack buffer without verifying that the source data falls within the parsed SUSP block. An attacker can craft a malicious ISO image that causes reads past the end of the SUSP data buffer, and a zero-length SUSP entry can trigger an infinite parsing loop. | CVSS3: 4.4 | 0% Низкий | 5 месяцев назад | |
GHSA-3pvc-g892-vvj8 SQL injection vulnerability in news.php in DGNews 2.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter in a newslist action. NOTE: this issue can produce resultant cross-site scripting (XSS). | 2% Низкий | больше 4 лет назад | ||
GHSA-3pv8-6f4r-ffg2 tar has a PAX header desynchronization issue | 3 месяца назад |
Уязвимостей на страницу