Количество 361 446
Количество 361 446
GHSA-3f5f-xgrj-97pf
Parse Server is vulnerable to Server-Side Request Forgery (SSRF) via Instagram OAuth Adapter
GHSA-3f5f-x3vv-f92r
The password protection feature of Microsoft Money can store the password in plaintext, which allows attackers with physical access to the system to obtain the password, aka the "Money Password" vulnerability.
GHSA-3f5f-g8gg-c73f
Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Sun Products Suite 2.1.1 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Administration.
GHSA-3f5f-3xp4-rx44
Use after free in DNS Server allows an authorized attacker to execute code over a network.
GHSA-3f5c-xpwv-8wgm
In the Linux kernel, the following vulnerability has been resolved: media: i2c: dw9714: Disable the regulator when the driver fails to probe When the driver fails to probe, we will get the following splat: [ 59.305988] ------------[ cut here ]------------ [ 59.306417] WARNING: CPU: 2 PID: 395 at drivers/regulator/core.c:2257 _regulator_put+0x3ec/0x4e0 [ 59.310345] RIP: 0010:_regulator_put+0x3ec/0x4e0 [ 59.318362] Call Trace: [ 59.318582] <TASK> [ 59.318765] regulator_put+0x1f/0x30 [ 59.319058] devres_release_group+0x319/0x3d0 [ 59.319420] i2c_device_probe+0x766/0x940 Fix this by disabling the regulator in error handling.
GHSA-3f5c-4qxj-vmpf
Next.js Directory Traversal Vulnerability
GHSA-3f5c-485h-v36h
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CleverSoft Anon anon2x allows Reflected XSS.This issue affects Anon: from n/a through <= 2.2.10.
GHSA-3f59-325x-78rx
Insecure inherited permissions for the Intel(R) NUC M15 Laptop Kit Driver Pack software before updated version 1.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
GHSA-3f58-74qw-ph75
TYPO3 allows remote attackers to embed Flash videos from external domain
GHSA-3f58-59wc-xqp9
Heap-based buffer overflow in the DrawImage function in magick/draw.c in ImageMagick before 6.9.5-5 allows remote attackers to cause a denial of service (application crash) via a crafted image file.
GHSA-3f58-3q4v-mmv6
Rejected reason: Not used
GHSA-3f57-w2rp-72fc
Undertow Uncaught Exception vulnerability
GHSA-3f57-p85f-5486
In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services.
GHSA-3f56-w4g2-mx64
Duplicate Advisory: Open Babel has NULL pointer dereference in MOL2 OBAtom::SetFormalCharge
GHSA-3f56-hcw5-g566
GPAC v1.1.0 was discovered to contain an invalid memory address dereference via the function gf_sg_vrml_mf_reset(). This vulnerability allows attackers to cause a Denial of Service (DoS).
GHSA-3f56-567j-9g37
In Honeywell WIN-PAK 4.7.2, Web and prior versions, the affected product is vulnerable to a cross-site request forgery, which may allow an attacker to remotely execute arbitrary code.
GHSA-3f56-258r-mg3f
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes Aqua aqua allows PHP Local File Inclusion.This issue affects Aqua: from n/a through <= 5.1.2.
GHSA-3f55-wwxj-x5jc
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Null pointer dereference vulnerability. An authenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
GHSA-3f55-cgv8-774j
iNiLabs School Express (SMS Express) 6.2 is affected by a Stored Cross-Site Scripting (XSS) vulnerability in the content-management features available to authenticated admin users. The vulnerability resides in POSTed editor parameters submitted to the /posts/edit/{id} endpoint (and similarly in Notice and Pages editors). Due to insufficient input sanitization and output encoding, attackers can inject HTML/JS payloads. The payload is saved and later rendered unsanitized, resulting in JavaScript execution in other users' browsers when they access the affected content. This issue allows an authenticated attacker to execute arbitrary JavaScript in the context of another user, potentially leading to session hijacking, privilege escalation, data exfiltration, or administrative account takeover. The application does not enforce a restrictive Content Security Policy (CSP) or adequate filtering to prevent such attacks.
GHSA-3f55-6gfh-8xfx
FreePBX 16 contains an authenticated remote code execution vulnerability in the API module that allows attackers with valid session credentials to execute arbitrary commands. Attackers can exploit the 'generatedocs' endpoint by crafting malicious POST requests with bash command injection to establish remote shell access.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3f5f-xgrj-97pf Parse Server is vulnerable to Server-Side Request Forgery (SSRF) via Instagram OAuth Adapter | 0% Низкий | 8 месяцев назад | ||
GHSA-3f5f-x3vv-f92r The password protection feature of Microsoft Money can store the password in plaintext, which allows attackers with physical access to the system to obtain the password, aka the "Money Password" vulnerability. | 1% Низкий | больше 4 лет назад | ||
GHSA-3f5f-g8gg-c73f Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Sun Products Suite 2.1.1 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Administration. | 3% Низкий | больше 4 лет назад | ||
GHSA-3f5f-3xp4-rx44 Use after free in DNS Server allows an authorized attacker to execute code over a network. | CVSS3: 8 | 1% Низкий | около 1 месяца назад | |
GHSA-3f5c-xpwv-8wgm In the Linux kernel, the following vulnerability has been resolved: media: i2c: dw9714: Disable the regulator when the driver fails to probe When the driver fails to probe, we will get the following splat: [ 59.305988] ------------[ cut here ]------------ [ 59.306417] WARNING: CPU: 2 PID: 395 at drivers/regulator/core.c:2257 _regulator_put+0x3ec/0x4e0 [ 59.310345] RIP: 0010:_regulator_put+0x3ec/0x4e0 [ 59.318362] Call Trace: [ 59.318582] <TASK> [ 59.318765] regulator_put+0x1f/0x30 [ 59.319058] devres_release_group+0x319/0x3d0 [ 59.319420] i2c_device_probe+0x766/0x940 Fix this by disabling the regulator in error handling. | CVSS3: 5.5 | 0% Низкий | 10 месяцев назад | |
GHSA-3f5c-4qxj-vmpf Next.js Directory Traversal Vulnerability | CVSS3: 7.5 | 14% Средний | больше 8 лет назад | |
GHSA-3f5c-485h-v36h Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CleverSoft Anon anon2x allows Reflected XSS.This issue affects Anon: from n/a through <= 2.2.10. | CVSS3: 7.1 | 0% Низкий | 7 месяцев назад | |
GHSA-3f59-325x-78rx Insecure inherited permissions for the Intel(R) NUC M15 Laptop Kit Driver Pack software before updated version 1.1 may allow an authenticated user to potentially enable escalation of privilege via local access. | CVSS3: 7.8 | 0% Низкий | около 4 лет назад | |
GHSA-3f58-74qw-ph75 TYPO3 allows remote attackers to embed Flash videos from external domain | CVSS3: 6.1 | 1% Низкий | больше 4 лет назад | |
GHSA-3f58-59wc-xqp9 Heap-based buffer overflow in the DrawImage function in magick/draw.c in ImageMagick before 6.9.5-5 allows remote attackers to cause a denial of service (application crash) via a crafted image file. | CVSS3: 5.5 | 2% Низкий | больше 4 лет назад | |
GHSA-3f58-3q4v-mmv6 Rejected reason: Not used | 8 месяцев назад | |||
GHSA-3f57-w2rp-72fc Undertow Uncaught Exception vulnerability | CVSS3: 5.9 | 2% Низкий | больше 4 лет назад | |
GHSA-3f57-p85f-5486 In wlan driver, there is a possible missing bounds check. This could lead to local denial of service in wlan services. | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
GHSA-3f56-w4g2-mx64 Duplicate Advisory: Open Babel has NULL pointer dereference in MOL2 OBAtom::SetFormalCharge | CVSS3: 4.3 | 6 месяцев назад | ||
GHSA-3f56-hcw5-g566 GPAC v1.1.0 was discovered to contain an invalid memory address dereference via the function gf_sg_vrml_mf_reset(). This vulnerability allows attackers to cause a Denial of Service (DoS). | CVSS3: 5.5 | 1% Низкий | больше 4 лет назад | |
GHSA-3f56-567j-9g37 In Honeywell WIN-PAK 4.7.2, Web and prior versions, the affected product is vulnerable to a cross-site request forgery, which may allow an attacker to remotely execute arbitrary code. | 1% Низкий | около 4 лет назад | ||
GHSA-3f56-258r-mg3f Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes Aqua aqua allows PHP Local File Inclusion.This issue affects Aqua: from n/a through <= 5.1.2. | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
GHSA-3f55-wwxj-x5jc Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Null pointer dereference vulnerability. An authenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | 2% Низкий | около 4 лет назад | ||
GHSA-3f55-cgv8-774j iNiLabs School Express (SMS Express) 6.2 is affected by a Stored Cross-Site Scripting (XSS) vulnerability in the content-management features available to authenticated admin users. The vulnerability resides in POSTed editor parameters submitted to the /posts/edit/{id} endpoint (and similarly in Notice and Pages editors). Due to insufficient input sanitization and output encoding, attackers can inject HTML/JS payloads. The payload is saved and later rendered unsanitized, resulting in JavaScript execution in other users' browsers when they access the affected content. This issue allows an authenticated attacker to execute arbitrary JavaScript in the context of another user, potentially leading to session hijacking, privilege escalation, data exfiltration, or administrative account takeover. The application does not enforce a restrictive Content Security Policy (CSP) or adequate filtering to prevent such attacks. | CVSS3: 5.4 | 0% Низкий | 11 месяцев назад | |
GHSA-3f55-6gfh-8xfx FreePBX 16 contains an authenticated remote code execution vulnerability in the API module that allows attackers with valid session credentials to execute arbitrary commands. Attackers can exploit the 'generatedocs' endpoint by crafting malicious POST requests with bash command injection to establish remote shell access. | CVSS3: 8.8 | 4% Низкий | 8 месяцев назад |
Уязвимостей на страницу