Количество 361 446
Количество 361 446
GHSA-3f99-xvp7-g4c7
IBM Financial Transaction Manager for ACH Services for Multi-Platform 3.0.2 could allow an authenticated user to obtain sensitive information from an undocumented URL. IBM X-Force ID: 130735.
GHSA-3f99-rhv8-qg8h
The Web Browser & Explorer (aka com.explore.web.browser) application 2.0.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
GHSA-3f99-hvg4-qjwj
Insecure random number generation in keypair
GHSA-3f99-8qf2-g6v6
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.6. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H).
GHSA-3f98-v8mx-8cr7
The CairoFont::create function in CairoFontEngine.cc in Poppler, possibly before 0.8.0, as used in Xpdf, Evince, ePDFview, KWord, and other applications, does not properly handle embedded fonts in PDF files, which allows remote attackers to execute arbitrary code via a crafted font object, related to dereferencing a function pointer associated with the type of this font object.
GHSA-3f98-9h78-w5jh
Incorrect interaction of the parse_packet() and parse_part_sign_sha256() functions in network.c in collectd 5.7.1 and earlier allows remote attackers to cause a denial of service (infinite loop) of a collectd instance (configured with "SecurityLevel None" and with empty "AuthFile" options) via a crafted UDP packet.
GHSA-3f97-rj68-2pjf
Malicious Package in buffe2-xor
GHSA-3f97-7pgv-gmgr
Magento affected by a business logic error in the placeOrder graphql mutation
GHSA-3f96-f7jm-vmvm
The mDNS snooping functionality on Cisco Wireless LAN Controller (WLC) devices with software 7.4.1.54 and earlier does not properly manage buffers, which allows remote authenticated users to cause a denial of service (device reload) via crafted mDNS packets, aka Bug ID CSCue04153.
GHSA-3f95-w5h5-fq86
Prototype Pollution in mergify
GHSA-3f95-r44v-8mrg
Command injection in simple-git
GHSA-3f95-mxq2-2f63
Duplicate Advisory: Gradio Local File Inclusion vulnerability
GHSA-3f95-hm4q-h8pq
Cross-site scripting (XSS) vulnerability in Windows Search 4.0 for Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted file that appears in a preview in a search result, aka "Script Execution in Windows Search Vulnerability."
GHSA-3f95-cpcf-8h94
SQL injection vulnerability in function.php in MigasCMS 1.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the categorie parameter in a catalogo action. NOTE: some of these details are obtained from third party information.
GHSA-3f95-9gfm-mcx4
IBM Security Verify Information Queue 10.0.2 could allow an authenticated user to cause a denial of service with a specially crafted HTTP request.
GHSA-3f94-qwfc-p8gc
Buffer overflow in eXeScope 6.50 allows user-assisted remote attackers to execute arbitrary code via a crafted executable (.exe) file.
GHSA-3f94-mp5w-652q
Cross-site scripting (XSS) vulnerability in admin/edituser.php in CMS Made Simple 1.10.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the email parameter (aka the Email Address field in the Edit User template).
GHSA-3f94-44jv-m2pq
Mailcwp remote file upload vulnerability incomplete fix v1.100
GHSA-3f93-cwjr-ppr2
Adobe After Effects version 18.2 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose sensitive memory information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
GHSA-3f93-cvr2-mcrh
In display, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10196993; Issue ID: MSV-4805.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3f99-xvp7-g4c7 IBM Financial Transaction Manager for ACH Services for Multi-Platform 3.0.2 could allow an authenticated user to obtain sensitive information from an undocumented URL. IBM X-Force ID: 130735. | CVSS3: 6.5 | 1% Низкий | больше 4 лет назад | |
GHSA-3f99-rhv8-qg8h The Web Browser & Explorer (aka com.explore.web.browser) application 2.0.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 0% Низкий | больше 4 лет назад | ||
GHSA-3f99-hvg4-qjwj Insecure random number generation in keypair | CVSS3: 8.7 | 3% Низкий | почти 5 лет назад | |
GHSA-3f99-8qf2-g6v6 Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.6. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H). | CVSS3: 7.5 | 0% Низкий | 4 месяца назад | |
GHSA-3f98-v8mx-8cr7 The CairoFont::create function in CairoFontEngine.cc in Poppler, possibly before 0.8.0, as used in Xpdf, Evince, ePDFview, KWord, and other applications, does not properly handle embedded fonts in PDF files, which allows remote attackers to execute arbitrary code via a crafted font object, related to dereferencing a function pointer associated with the type of this font object. | 5% Низкий | больше 4 лет назад | ||
GHSA-3f98-9h78-w5jh Incorrect interaction of the parse_packet() and parse_part_sign_sha256() functions in network.c in collectd 5.7.1 and earlier allows remote attackers to cause a denial of service (infinite loop) of a collectd instance (configured with "SecurityLevel None" and with empty "AuthFile" options) via a crafted UDP packet. | CVSS3: 7.5 | 4% Низкий | больше 4 лет назад | |
GHSA-3f97-rj68-2pjf Malicious Package in buffe2-xor | CVSS3: 9.8 | почти 6 лет назад | ||
GHSA-3f97-7pgv-gmgr Magento affected by a business logic error in the placeOrder graphql mutation | CVSS3: 6.5 | 2% Низкий | около 4 лет назад | |
GHSA-3f96-f7jm-vmvm The mDNS snooping functionality on Cisco Wireless LAN Controller (WLC) devices with software 7.4.1.54 and earlier does not properly manage buffers, which allows remote authenticated users to cause a denial of service (device reload) via crafted mDNS packets, aka Bug ID CSCue04153. | 1% Низкий | больше 4 лет назад | ||
GHSA-3f95-w5h5-fq86 Prototype Pollution in mergify | почти 6 лет назад | |||
GHSA-3f95-r44v-8mrg Command injection in simple-git | CVSS3: 8.1 | 3% Низкий | больше 4 лет назад | |
GHSA-3f95-mxq2-2f63 Duplicate Advisory: Gradio Local File Inclusion vulnerability | CVSS3: 7.5 | больше 2 лет назад | ||
GHSA-3f95-hm4q-h8pq Cross-site scripting (XSS) vulnerability in Windows Search 4.0 for Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted file that appears in a preview in a search result, aka "Script Execution in Windows Search Vulnerability." | 33% Средний | больше 4 лет назад | ||
GHSA-3f95-cpcf-8h94 SQL injection vulnerability in function.php in MigasCMS 1.1, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the categorie parameter in a catalogo action. NOTE: some of these details are obtained from third party information. | 1% Низкий | больше 4 лет назад | ||
GHSA-3f95-9gfm-mcx4 IBM Security Verify Information Queue 10.0.2 could allow an authenticated user to cause a denial of service with a specially crafted HTTP request. | CVSS3: 6.5 | 1% Низкий | около 4 лет назад | |
GHSA-3f94-qwfc-p8gc Buffer overflow in eXeScope 6.50 allows user-assisted remote attackers to execute arbitrary code via a crafted executable (.exe) file. | 5% Низкий | больше 4 лет назад | ||
GHSA-3f94-mp5w-652q Cross-site scripting (XSS) vulnerability in admin/edituser.php in CMS Made Simple 1.10.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the email parameter (aka the Email Address field in the Edit User template). | 1% Низкий | больше 4 лет назад | ||
GHSA-3f94-44jv-m2pq Mailcwp remote file upload vulnerability incomplete fix v1.100 | CVSS3: 9.8 | 3% Низкий | больше 4 лет назад | |
GHSA-3f93-cwjr-ppr2 Adobe After Effects version 18.2 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to disclose sensitive memory information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | 2% Низкий | около 4 лет назад | ||
GHSA-3f93-cvr2-mcrh In display, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10196993; Issue ID: MSV-4805. | CVSS3: 7.8 | 0% Низкий | 9 месяцев назад |
Уязвимостей на страницу