Количество 362 328
Количество 362 328
GHSA-3h6w-w73g-4wv9
Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromSetSysTime. This vulnerability allows attackers to cause a Denial of Service (DoS) via the timeZone parameter.
GHSA-3h6w-hjgc-hx7q
Windows permissions for ASPECT configuration toolsets are not fully secured allow-ing exposure of configuration informationThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*.
GHSA-3h6w-92g2-xgrr
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service and obtain sensitive information due to an out-of-bounds read.
GHSA-3h6v-4pff-pgf4
This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. A download's origin may be incorrectly associated.
GHSA-3h6r-gqmp-9v88
Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the function openSchedWifi.
GHSA-3h6p-jvww-q7w3
Sun Java System Access Manager 7.1, when installed in a Sun Java System Application Server 9.1 container, does not demand authentication after a container restart, which allows remote attackers to perform administrative tasks.
GHSA-3h6m-v52v-hvmw
Out of bounds read in compositing in Google Chrome prior to 102.0.5005.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
GHSA-3h6m-4cmj-f665
Subscriber Privilege Escalation in Sonaar <= 4.27.4 versions.
GHSA-3h6m-3jhx-cfg9
The vulnerability of hard-coded default credentials in QSAN SANOS allows unauthenticated remote attackers to obtain administrator’s permission and execute arbitrary functions.
GHSA-3h6j-9x8m-rg3g
Graby has stored XSS via iframe srcdoc Attribute in htmLawed Sanitization Config
GHSA-3h6h-wq56-3w89
The Add Comments WordPress plugin through 1.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
GHSA-3h6h-v2q2-7mx9
WUZHI CMS 4.1.0 allows coreframe/app/coupon/admin/copyfrom.php SQL injection via the index.php?m=promote&f=index&v=search keywords parameter, a related issue to CVE-2018-15893.
GHSA-3h6h-8756-mj4f
A vulnerability in Cisco Firepower Management Center could allow an authenticated, remote attacker to obtain user information. An attacker could use this information to perform reconnaissance. More Information: CSCvc10894. Known Affected Releases: 6.1.0.2 6.2.0. Known Fixed Releases: 6.2.0.
GHSA-3h6h-67x3-cv5x
Poweradmin: CSV Injection in log export endpoints allows formula execution in spreadsheet applications
GHSA-3h6g-vwfm-p62q
Cross-site scripting (XSS) vulnerability in display.php in Obsession-Design Image-Gallery (ODIG) 1.1 allows remote attackers to inject arbitrary web script or HTML via the folder parameter.
GHSA-3h6g-r953-7g4p
An issue was discovered in Emote Remote Mouse through 4.0.0.0. It uses cleartext HTTP to check, and request, updates. Thus, attackers can machine-in-the-middle a victim to download a malicious binary in place of the real update, with no SSL errors or warnings.
GHSA-3h6g-63ch-8mwf
In the Linux kernel, the following vulnerability has been resolved: net: ftgmac100: fix ring allocation unwind on open failure ftgmac100_alloc_rings() allocates rx_skbs, tx_skbs, rxdes, txdes, and rx_scratch in stages. On intermediate failures it returned -ENOMEM directly, leaking resources allocated earlier in the function. Rework the failure path to use staged local unwind labels and free allocated resources in reverse order before returning -ENOMEM. This matches common netdev allocation cleanup style.
GHSA-3h6f-g5f3-gc4w
Access Control Bypass in Spring Security
GHSA-3h6c-fr7r-7jmg
TOTOlink EX1200T V4.1.2cu.5232_B20210713 was discovered to contain a remote command execution (RCE) vulnerability via the "main" function.
GHSA-3h6c-c475-jm7v
Arbitrary Code Execution in Gitea
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3h6w-w73g-4wv9 Tenda AX3 v16.03.12.10_CN was discovered to contain a stack overflow in the function fromSetSysTime. This vulnerability allows attackers to cause a Denial of Service (DoS) via the timeZone parameter. | 1% Низкий | больше 4 лет назад | ||
GHSA-3h6w-hjgc-hx7q Windows permissions for ASPECT configuration toolsets are not fully secured allow-ing exposure of configuration informationThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Series: through 3.*. | CVSS3: 7.3 | 0% Низкий | больше 1 года назад | |
GHSA-3h6w-92g2-xgrr IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service and obtain sensitive information due to an out-of-bounds read. | CVSS3: 5.4 | 0% Низкий | 4 дня назад | |
GHSA-3h6v-4pff-pgf4 This issue was addressed through improved state management. This issue is fixed in Safari 18.4, iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4. A download's origin may be incorrectly associated. | CVSS3: 9.8 | 1% Низкий | больше 1 года назад | |
GHSA-3h6r-gqmp-9v88 Tenda AC9 V15.03.2.21_cn was discovered to contain a stack overflow via the function openSchedWifi. | 2% Низкий | больше 4 лет назад | ||
GHSA-3h6p-jvww-q7w3 Sun Java System Access Manager 7.1, when installed in a Sun Java System Application Server 9.1 container, does not demand authentication after a container restart, which allows remote attackers to perform administrative tasks. | 3% Низкий | больше 4 лет назад | ||
GHSA-3h6m-v52v-hvmw Out of bounds read in compositing in Google Chrome prior to 102.0.5005.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. | CVSS3: 9.3 | 1% Низкий | около 4 лет назад | |
GHSA-3h6m-4cmj-f665 Subscriber Privilege Escalation in Sonaar <= 4.27.4 versions. | CVSS3: 8.8 | 0% Низкий | 2 месяца назад | |
GHSA-3h6m-3jhx-cfg9 The vulnerability of hard-coded default credentials in QSAN SANOS allows unauthenticated remote attackers to obtain administrator’s permission and execute arbitrary functions. | 1% Низкий | около 4 лет назад | ||
GHSA-3h6j-9x8m-rg3g Graby has stored XSS via iframe srcdoc Attribute in htmLawed Sanitization Config | 5 месяцев назад | |||
GHSA-3h6h-wq56-3w89 The Add Comments WordPress plugin through 1.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | CVSS3: 4.8 | 1% Низкий | больше 3 лет назад | |
GHSA-3h6h-v2q2-7mx9 WUZHI CMS 4.1.0 allows coreframe/app/coupon/admin/copyfrom.php SQL injection via the index.php?m=promote&f=index&v=search keywords parameter, a related issue to CVE-2018-15893. | CVSS3: 9.8 | 2% Низкий | больше 4 лет назад | |
GHSA-3h6h-8756-mj4f A vulnerability in Cisco Firepower Management Center could allow an authenticated, remote attacker to obtain user information. An attacker could use this information to perform reconnaissance. More Information: CSCvc10894. Known Affected Releases: 6.1.0.2 6.2.0. Known Fixed Releases: 6.2.0. | CVSS3: 6.5 | 1% Низкий | больше 4 лет назад | |
GHSA-3h6h-67x3-cv5x Poweradmin: CSV Injection in log export endpoints allows formula execution in spreadsheet applications | CVSS3: 6.9 | 0% Низкий | 3 месяца назад | |
GHSA-3h6g-vwfm-p62q Cross-site scripting (XSS) vulnerability in display.php in Obsession-Design Image-Gallery (ODIG) 1.1 allows remote attackers to inject arbitrary web script or HTML via the folder parameter. | 1% Низкий | больше 4 лет назад | ||
GHSA-3h6g-r953-7g4p An issue was discovered in Emote Remote Mouse through 4.0.0.0. It uses cleartext HTTP to check, and request, updates. Thus, attackers can machine-in-the-middle a victim to download a malicious binary in place of the real update, with no SSL errors or warnings. | CVSS3: 8.1 | 1% Низкий | около 4 лет назад | |
GHSA-3h6g-63ch-8mwf In the Linux kernel, the following vulnerability has been resolved: net: ftgmac100: fix ring allocation unwind on open failure ftgmac100_alloc_rings() allocates rx_skbs, tx_skbs, rxdes, txdes, and rx_scratch in stages. On intermediate failures it returned -ENOMEM directly, leaking resources allocated earlier in the function. Rework the failure path to use staged local unwind labels and free allocated resources in reverse order before returning -ENOMEM. This matches common netdev allocation cleanup style. | CVSS3: 5.5 | 0% Низкий | 4 месяца назад | |
GHSA-3h6f-g5f3-gc4w Access Control Bypass in Spring Security | CVSS3: 9.1 | 4% Низкий | около 3 лет назад | |
GHSA-3h6c-fr7r-7jmg TOTOlink EX1200T V4.1.2cu.5232_B20210713 was discovered to contain a remote command execution (RCE) vulnerability via the "main" function. | CVSS3: 9.8 | 2% Низкий | больше 2 лет назад | |
GHSA-3h6c-c475-jm7v Arbitrary Code Execution in Gitea | CVSS3: 7.2 | 95% Критический | больше 2 лет назад |
Уязвимостей на страницу