Количество 362 328
Количество 362 328
GHSA-3h54-6g9g-h4w7
Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
GHSA-3h53-wqpp-2rw8
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
GHSA-3h53-6977-c549
Microsoft graphics in Windows 7 SP1 and Windows Server 2008 SP2 and R2 SP1 allows an attacker to potentially read data that was not intended to be disclosed due to the way that the Microsoft Windows Embedded OpenType (EOT) font engine parses specially crafted embedded fonts, aka "Windows EOT Font Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-11832.
GHSA-3h52-vv68-p6m9
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Joost de Valk Enhanced WP Contact Form plugin <= 2.2.3 versions.
GHSA-3h52-r54r-fvgf
macrozheng mall version 1.0.3 and prior contains an authentication vulnerability in the mall-portal password reset workflow that allows an unauthenticated attacker to reset arbitrary user account passwords using only a victim’s telephone number. The password reset flow exposes the one-time password (OTP) directly in the API response and validates password reset requests solely by comparing the provided OTP to a value stored by telephone number, without verifying user identity or ownership of the telephone number. This enables remote account takeover of any user with a known or guessable telephone number.
GHSA-3h52-fhpg-8fqw
An issue was discovered in libgpac.a in GPAC before 0.8.0, as demonstrated by MP4Box. It contains an invalid pointer dereference in gf_list_count in utils/list.c that can cause a denial of service via a crafted MP4 file.
GHSA-3h52-cx59-c456
OpenClaw: Feishu webhook reads and parses unauthenticated request bodies before signature validation
GHSA-3h52-6v6j-6wwv
TYPO3 SQL Injection in extension "Address List" (tt_address)
GHSA-3h52-269p-cp9r
Information exposure in Next.js dev server due to lack of origin verification
GHSA-3h4x-jrvr-p38w
An error in the URL handler Bosch IP cameras may lead to a reflected cross site scripting (XSS) in the web-based interface. An attacker with knowledge of the camera address can send a crafted link to a user, which will execute javascript code in the context of the user.
GHSA-3h4w-ppp7-mr7f
Subscriber Broken Access Control in Rank Math SEO <= 1.0.271 versions.
GHSA-3h4v-p542-7xmc
IXON VPN Client before 1.4.4 on Windows allows Local Privilege Escalation to SYSTEM because there is code execution from a configuration file that can be controlled by a low-privileged user. There is a race condition in which a temporary configuration file, in a world-writable directory, can be overwritten.
GHSA-3h4v-m4g6-c2v8
Heap buffer overflow in WebUI in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via specific input into DevTools.
GHSA-3h4v-5rmg-5m36
A vulnerability, which was classified as problematic, was found in Open5GS up to 2.7.5. Affected is the function gmm_state_de_registered/gmm_state_exception of the file src/amf/gmm-sm.c of the component AMF. The manipulation leads to denial of service. It is possible to launch the attack remotely. Upgrading to version 2.7.6 is able to address this issue. The name of the patch is 1f30edac27f69f61cff50162e980fe58fdeb30ca. It is recommended to upgrade the affected component.
GHSA-3h4r-x85w-hcrm
A Process Control vulnerability in ProductAgentUI.exe as used in Bitdefender Antivirus Plus allows an attacker to tamper with product settings via a specially crafted DLL file. This issue affects: Bitdefender Antivirus Plus versions prior to 24.0.26.136. Bitdefender Internet Security versions prior to 24.0.26.136. Bitdefender Total Security versions prior to 24.0.26.136.
GHSA-3h4r-pjv6-cph9
RubyGems Escape sequence injection vulnerability in api response handling
GHSA-3h4r-h95r-47jc
Integer signedness error in the virtio_net_load function in hw/net/virtio-net.c in QEMU 1.x before 1.7.2 allows remote attackers to execute arbitrary code via a crafted savevm image, which triggers a buffer overflow.
GHSA-3h4r-2q6q-wfr8
VMware Cloud Director Availability contains an HTML injection vulnerability. A malicious actor with network access to VMware Cloud Director Availability can craft malicious HTML tags to execute within replication tasks.
GHSA-3h4q-7386-ff6m
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 176475.
GHSA-3h4p-v99m-68x5
SQL injection vulnerability in the Diocese of Portsmouth Database (pd_diocesedatabase) extension before 0.7.13 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3h54-6g9g-h4w7 Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used. | больше 1 года назад | |||
GHSA-3h53-wqpp-2rw8 Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | CVSS3: 7.1 | 1% Низкий | 10 месяцев назад | |
GHSA-3h53-6977-c549 Microsoft graphics in Windows 7 SP1 and Windows Server 2008 SP2 and R2 SP1 allows an attacker to potentially read data that was not intended to be disclosed due to the way that the Microsoft Windows Embedded OpenType (EOT) font engine parses specially crafted embedded fonts, aka "Windows EOT Font Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2017-11832. | CVSS3: 5.5 | 2% Низкий | больше 4 лет назад | |
GHSA-3h52-vv68-p6m9 Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Joost de Valk Enhanced WP Contact Form plugin <= 2.2.3 versions. | CVSS3: 5.9 | 0% Низкий | около 3 лет назад | |
GHSA-3h52-r54r-fvgf macrozheng mall version 1.0.3 and prior contains an authentication vulnerability in the mall-portal password reset workflow that allows an unauthenticated attacker to reset arbitrary user account passwords using only a victim’s telephone number. The password reset flow exposes the one-time password (OTP) directly in the API response and validates password reset requests solely by comparing the provided OTP to a value stored by telephone number, without verifying user identity or ownership of the telephone number. This enables remote account takeover of any user with a known or guessable telephone number. | CVSS3: 9.8 | 1% Низкий | 7 месяцев назад | |
GHSA-3h52-fhpg-8fqw An issue was discovered in libgpac.a in GPAC before 0.8.0, as demonstrated by MP4Box. It contains an invalid pointer dereference in gf_list_count in utils/list.c that can cause a denial of service via a crafted MP4 file. | 1% Низкий | около 4 лет назад | ||
GHSA-3h52-cx59-c456 OpenClaw: Feishu webhook reads and parses unauthenticated request bodies before signature validation | 0% Низкий | 5 месяцев назад | ||
GHSA-3h52-6v6j-6wwv TYPO3 SQL Injection in extension "Address List" (tt_address) | 0% Низкий | 3 месяца назад | ||
GHSA-3h52-269p-cp9r Information exposure in Next.js dev server due to lack of origin verification | 0% Низкий | около 1 года назад | ||
GHSA-3h4x-jrvr-p38w An error in the URL handler Bosch IP cameras may lead to a reflected cross site scripting (XSS) in the web-based interface. An attacker with knowledge of the camera address can send a crafted link to a user, which will execute javascript code in the context of the user. | 1% Низкий | около 4 лет назад | ||
GHSA-3h4w-ppp7-mr7f Subscriber Broken Access Control in Rank Math SEO <= 1.0.271 versions. | CVSS3: 6.5 | 0% Низкий | 2 месяца назад | |
GHSA-3h4v-p542-7xmc IXON VPN Client before 1.4.4 on Windows allows Local Privilege Escalation to SYSTEM because there is code execution from a configuration file that can be controlled by a low-privileged user. There is a race condition in which a temporary configuration file, in a world-writable directory, can be overwritten. | CVSS3: 8.1 | 0% Низкий | больше 1 года назад | |
GHSA-3h4v-m4g6-c2v8 Heap buffer overflow in WebUI in Google Chrome prior to 100.0.4896.60 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via specific input into DevTools. | CVSS3: 8.8 | 1% Низкий | около 4 лет назад | |
GHSA-3h4v-5rmg-5m36 A vulnerability, which was classified as problematic, was found in Open5GS up to 2.7.5. Affected is the function gmm_state_de_registered/gmm_state_exception of the file src/amf/gmm-sm.c of the component AMF. The manipulation leads to denial of service. It is possible to launch the attack remotely. Upgrading to version 2.7.6 is able to address this issue. The name of the patch is 1f30edac27f69f61cff50162e980fe58fdeb30ca. It is recommended to upgrade the affected component. | CVSS3: 5.3 | 1% Низкий | около 1 года назад | |
GHSA-3h4r-x85w-hcrm A Process Control vulnerability in ProductAgentUI.exe as used in Bitdefender Antivirus Plus allows an attacker to tamper with product settings via a specially crafted DLL file. This issue affects: Bitdefender Antivirus Plus versions prior to 24.0.26.136. Bitdefender Internet Security versions prior to 24.0.26.136. Bitdefender Total Security versions prior to 24.0.26.136. | 0% Низкий | больше 4 лет назад | ||
GHSA-3h4r-pjv6-cph9 RubyGems Escape sequence injection vulnerability in api response handling | CVSS3: 7.5 | 3% Низкий | около 7 лет назад | |
GHSA-3h4r-h95r-47jc Integer signedness error in the virtio_net_load function in hw/net/virtio-net.c in QEMU 1.x before 1.7.2 allows remote attackers to execute arbitrary code via a crafted savevm image, which triggers a buffer overflow. | 5% Низкий | больше 4 лет назад | ||
GHSA-3h4r-2q6q-wfr8 VMware Cloud Director Availability contains an HTML injection vulnerability. A malicious actor with network access to VMware Cloud Director Availability can craft malicious HTML tags to execute within replication tasks. | CVSS3: 6.4 | 0% Низкий | около 2 лет назад | |
GHSA-3h4q-7386-ff6m IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 176475. | 1% Низкий | около 4 лет назад | ||
GHSA-3h4p-v99m-68x5 SQL injection vulnerability in the Diocese of Portsmouth Database (pd_diocesedatabase) extension before 0.7.13 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | 1% Низкий | больше 4 лет назад |
Уязвимостей на страницу