Количество 361 446
Количество 361 446
GHSA-3ff3-7r8m-47hr
The ProcRenderAddGlyphs function in the Render extension (render/render.c) in X.Org xserver 1.7.7 and earlier allows local users to read arbitrary memory and possibly cause a denial of service (server crash) via unspecified vectors related to an "input sanitization flaw."
GHSA-3ff2-r28g-w7h9
Heap buffer overflow in `Transpose`
GHSA-3ff2-4v74-vhq8
An unauthenticated format string vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by improper handling of externally controlled input during log message formatting in the login processing path. A remote attacker may exploit this vulnerability by sending crafted login data, potentially causing information disclosure, memory corruption, or a denial of service.
GHSA-3fcx-583q-ffvw
H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function WanModeSetMultiWan.
GHSA-3fcv-p6qc-8gvx
SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/view_parked_details.php.
GHSA-3fcv-jvfp-m4q9
Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access
GHSA-3fcr-xq7p-rffp
Vulnerabilities in the File Download and Get File handler components in CIPPlanner CIPAce before 9.17 allow attackers to download unauthorized files. An authenticated user can easily change the file id parameter or pass the physical file path in the URL query string to retrieve the files. (Retrieval is not intended without correct data access configured for documents.)
GHSA-3fcr-jvgp-7f58
pytonapi has a Webhook Custom Path Authentication Bypass
GHSA-3fcr-j3qp-6cjq
A vulnerability was identified in SourceCodester Student Grading System 1.0. Affected by this vulnerability is an unknown functionality of the file /view_user.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
GHSA-3fcr-4vvp-335p
The WP Login Security and History WordPress plugin through 1.0 did not have CSRF check when saving its settings, not any sanitisation or validation on them. This could allow attackers to make logged in administrators change the plugin's settings to arbitrary values, and set XSS payloads on them as well
GHSA-3fcr-249g-2cg3
IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to obtain sensitive information and cause a denial of service due to an out-of-bounds write.
GHSA-3fcq-hfv4-xfg4
There is insecure algorithm vulnerability in Huawei products. A module uses less random input in a secure mechanism. Attackers can exploit this vulnerability by brute forcing to obtain sensitive message. This can lead to information leak. Affected product versions include:USG9500 versions V500R001C30SPC200, V500R001C60SPC500,V500R005C00SPC200;USG9520 versions V500R005C00;USG9560 versions V500R005C00;USG9580 versions V500R005C00.
GHSA-3fcq-fcfj-jgfq
A flaw that allowed an attacker to corrupt memory and possibly escalate privileges was found in the mwifiex kernel module while connecting to a malicious wireless network.
GHSA-3fcp-jc98-wc37
trim_whitespace in lexer.l in libConfuse v3.2.1 has an out-of-bounds read.
GHSA-3fcp-gh22-82v3
Nessus Agent 8.2.4 and earlier for Windows were found to contain multiple local privilege escalation vulnerabilities which could allow an authenticated, local administrator to run specific Windows executables as the Nessus host. This is different than CVE-2021-20100.
GHSA-3fcp-6qqv-2826
GPAC MP4box 2.1-DEV-rev593-g007bf61a0 is vulnerable to Buffer Overflow in eac3_update_channels function of media_tools/av_parsers.c:9113
GHSA-3fcm-3v9f-gp92
Buffer Overflow vulnerability in Ardupiot Copter Latest commit 92693e023793133e49a035daf37c14433e484778 allows a local attacker to cause a denial of service via the AP_SmartAudio::loop, AP_SmartAudio, AP_SmartAudio.cpp components.
GHSA-3fcj-hp8x-9h3j
Missing Authorization vulnerability in hogash Kallyas kallyas.This issue affects Kallyas: from n/a through <= 4.22.0.
GHSA-3fcj-3m99-wmmp
Cross-zone scripting vulnerability in the Print Table of Links feature in Internet Explorer 6.0, 7.0, and 8.0b allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via an HTML document with a link containing JavaScript sequences, which are evaluated by a resource script when a user prints this document.
GHSA-3fch-xpx6-pcr2
In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix null dereference in find_network The variable pwlan has the possibility of being NULL when passed into rtw_free_network_nolock() which would later dereference the variable.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3ff3-7r8m-47hr The ProcRenderAddGlyphs function in the Render extension (render/render.c) in X.Org xserver 1.7.7 and earlier allows local users to read arbitrary memory and possibly cause a denial of service (server crash) via unspecified vectors related to an "input sanitization flaw." | 0% Низкий | больше 4 лет назад | ||
GHSA-3ff2-r28g-w7h9 Heap buffer overflow in `Transpose` | CVSS3: 5.5 | 0% Низкий | почти 5 лет назад | |
GHSA-3ff2-4v74-vhq8 An unauthenticated format string vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by improper handling of externally controlled input during log message formatting in the login processing path. A remote attacker may exploit this vulnerability by sending crafted login data, potentially causing information disclosure, memory corruption, or a denial of service. | CVSS3: 8.6 | 0% Низкий | около 2 месяцев назад | |
GHSA-3fcx-583q-ffvw H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function WanModeSetMultiWan. | CVSS3: 9.8 | 1% Низкий | почти 4 года назад | |
GHSA-3fcv-p6qc-8gvx SourceCodester Vehicle Parking Area Management System v1.0 is vulnerable to SQL Injection in the file /parking/view_parked_details.php. | CVSS3: 7.2 | 0% Низкий | 4 месяца назад | |
GHSA-3fcv-jvfp-m4q9 Cilium vulnerable to sensitive information disclosure and cluster disruption via local Envoy admin socket access | CVSS3: 9.2 | 0% Низкий | около 2 месяцев назад | |
GHSA-3fcr-xq7p-rffp Vulnerabilities in the File Download and Get File handler components in CIPPlanner CIPAce before 9.17 allow attackers to download unauthorized files. An authenticated user can easily change the file id parameter or pass the physical file path in the URL query string to retrieve the files. (Retrieval is not intended without correct data access configured for documents.) | CVSS3: 7.5 | 0% Низкий | 6 месяцев назад | |
GHSA-3fcr-jvgp-7f58 pytonapi has a Webhook Custom Path Authentication Bypass | CVSS3: 7.5 | 0% Низкий | 24 дня назад | |
GHSA-3fcr-j3qp-6cjq A vulnerability was identified in SourceCodester Student Grading System 1.0. Affected by this vulnerability is an unknown functionality of the file /view_user.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. | CVSS3: 6.3 | 0% Низкий | 11 месяцев назад | |
GHSA-3fcr-4vvp-335p The WP Login Security and History WordPress plugin through 1.0 did not have CSRF check when saving its settings, not any sanitisation or validation on them. This could allow attackers to make logged in administrators change the plugin's settings to arbitrary values, and set XSS payloads on them as well | CVSS3: 6.2 | 1% Низкий | около 4 лет назад | |
GHSA-3fcr-249g-2cg3 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to obtain sensitive information and cause a denial of service due to an out-of-bounds write. | CVSS3: 4.2 | 1 день назад | ||
GHSA-3fcq-hfv4-xfg4 There is insecure algorithm vulnerability in Huawei products. A module uses less random input in a secure mechanism. Attackers can exploit this vulnerability by brute forcing to obtain sensitive message. This can lead to information leak. Affected product versions include:USG9500 versions V500R001C30SPC200, V500R001C60SPC500,V500R005C00SPC200;USG9520 versions V500R005C00;USG9560 versions V500R005C00;USG9580 versions V500R005C00. | CVSS3: 7.5 | 1% Низкий | около 4 лет назад | |
GHSA-3fcq-fcfj-jgfq A flaw that allowed an attacker to corrupt memory and possibly escalate privileges was found in the mwifiex kernel module while connecting to a malicious wireless network. | CVSS3: 8.8 | 6% Низкий | около 4 лет назад | |
GHSA-3fcp-jc98-wc37 trim_whitespace in lexer.l in libConfuse v3.2.1 has an out-of-bounds read. | CVSS3: 8.8 | 2% Низкий | больше 4 лет назад | |
GHSA-3fcp-gh22-82v3 Nessus Agent 8.2.4 and earlier for Windows were found to contain multiple local privilege escalation vulnerabilities which could allow an authenticated, local administrator to run specific Windows executables as the Nessus host. This is different than CVE-2021-20100. | CVSS3: 6.7 | 0% Низкий | около 4 лет назад | |
GHSA-3fcp-6qqv-2826 GPAC MP4box 2.1-DEV-rev593-g007bf61a0 is vulnerable to Buffer Overflow in eac3_update_channels function of media_tools/av_parsers.c:9113 | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-3fcm-3v9f-gp92 Buffer Overflow vulnerability in Ardupiot Copter Latest commit 92693e023793133e49a035daf37c14433e484778 allows a local attacker to cause a denial of service via the AP_SmartAudio::loop, AP_SmartAudio, AP_SmartAudio.cpp components. | CVSS3: 6.2 | 0% Низкий | 3 месяца назад | |
GHSA-3fcj-hp8x-9h3j Missing Authorization vulnerability in hogash Kallyas kallyas.This issue affects Kallyas: from n/a through <= 4.22.0. | CVSS3: 5.3 | 0% Низкий | 10 месяцев назад | |
GHSA-3fcj-3m99-wmmp Cross-zone scripting vulnerability in the Print Table of Links feature in Internet Explorer 6.0, 7.0, and 8.0b allows user-assisted remote attackers to inject arbitrary web script or HTML in the Local Machine Zone via an HTML document with a link containing JavaScript sequences, which are evaluated by a resource script when a user prints this document. | 23% Средний | больше 4 лет назад | ||
GHSA-3fch-xpx6-pcr2 In the Linux kernel, the following vulnerability has been resolved: staging: rtl8723bs: fix null dereference in find_network The variable pwlan has the possibility of being NULL when passed into rtw_free_network_nolock() which would later dereference the variable. | CVSS3: 5.5 | 0% Низкий | 4 месяца назад |
Уязвимостей на страницу