Количество 359 267
Количество 359 267
GHSA-3829-mgmw-jcg4
Prototype Pollution in deep.assign
GHSA-3828-pjxx-wp2j
Untrusted pointer dereference in Storvsp.sys Driver allows an authorized attacker to deny service locally.
GHSA-3828-jgm6-f988
Directory traversal vulnerability in Oracle Reports allows remote attackers to read arbitrary files via an absolute or relative path to the (1) CUSTOMIZE or (2) desformat parameters to rwservlet. NOTE: vector 2 is probably the same as CVE-2006-0289, and fixed in Jan 2006 CPU.
GHSA-3827-x3c5-9qvc
Multiple buffer overflows in AllegroSoft RomPager, as used in Huawei Home Gateway products and other vendors and products, allow remote attackers to cause a denial of service or possibly execute arbitrary code via unspecified vectors related to authorization.
GHSA-3827-2vw5-3pm3
An Out-of-bounds Write in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to corrupt the memory of IO devices that use the library by sending a malicious RPC packet.
GHSA-3826-wfx9-8758
A weakness has been identified in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This impacts an unknown function of the file /index.php of the component SQL Handler. Executing a manipulation can lead to information exposure through error message. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks.
GHSA-3826-h8f4-w96h
The HubSpot – CRM, Email Marketing, Live Chat, Forms & Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' attribute of the HubSpot Meeting Widget in all versions up to, and including, 11.1.22 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
GHSA-3825-9v33-mrxq
A potential TOCTOU vulnerability was reported in PC Manager, Lenovo Browser, and Lenovo App Store that could allow a local attacker to cause a system crash.
GHSA-3825-537p-gqw4
Unrestricted Upload of File with Dangerous Type in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
GHSA-3825-4xhp-w9cc
Windows Backup Engine Information Disclosure Vulnerability
GHSA-3824-qmfq-2qv7
SurrealDB no JavaScript script function default timeout could facilitate DoS
GHSA-3823-wj6r-jpc9
gopher.c in the Gopher client 3.0.5 does not properly create temporary files, which allows local users to gain privileges.
GHSA-3823-hjpv-24g4
An Unquoted Service Path vulnerability exists in Ext2Fsd v0.68 via a specially crafted file in the Ext2Srv Service executable service path.
GHSA-3823-3p6j-72p3
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
GHSA-3822-wwjm-jgg2
Cross-site scripting (XSS) vulnerability in the Gantt applet viewer in IBM Tivoli Change and Configuration Management Database (CCMDB) 7.2.1 and IBM ILOG JViews Gantt allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
GHSA-3822-8jq8-pqhh
The server API endpoint /report/internet/urls reflects received data into the HTML response without applying proper encoding or filtering. This allows an attacker to execute arbitrary JavaScript in the victim's browser if the victim opens a URL prepared by the attacker.
GHSA-37xx-h5fj-hm7p
A remote code execution vulnerability is identified in FruityWifi through 2.4. Due to improperly escaped shell metacharacters obtained from the POST request at the page_config_adv.php page, it is possible to perform remote code execution by an authenticated attacker. This is similar to CVE-2018-17317.
GHSA-37xx-h4m8-x8wx
Simple Machines Forum (SMF) 1-0-5 and earlier supports the use of URLs for avatar images, which allows remote attackers to monitor sensitive information of forum visitors such as IP address and user agent, as demonstrated using a PHP script on a malicious server.
GHSA-37xx-8cjj-f57x
IBM Planning Analytics Local 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 182283.
GHSA-37xx-7qg6-2w7h
Trend Micro InterScan VirusWall for Windows NT 3.52 does not record the sender's IP address in the headers for a mail message when it is passed from VirusWall to the MTA, which allows remote attackers to hide the origin of the message.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3829-mgmw-jcg4 Prototype Pollution in deep.assign | CVSS3: 9.8 | 2% Низкий | около 4 лет назад | |
GHSA-3828-pjxx-wp2j Untrusted pointer dereference in Storvsp.sys Driver allows an authorized attacker to deny service locally. | CVSS3: 6.5 | 0% Низкий | 9 месяцев назад | |
GHSA-3828-jgm6-f988 Directory traversal vulnerability in Oracle Reports allows remote attackers to read arbitrary files via an absolute or relative path to the (1) CUSTOMIZE or (2) desformat parameters to rwservlet. NOTE: vector 2 is probably the same as CVE-2006-0289, and fixed in Jan 2006 CPU. | 9% Низкий | больше 4 лет назад | ||
GHSA-3827-x3c5-9qvc Multiple buffer overflows in AllegroSoft RomPager, as used in Huawei Home Gateway products and other vendors and products, allow remote attackers to cause a denial of service or possibly execute arbitrary code via unspecified vectors related to authorization. | 6% Низкий | больше 4 лет назад | ||
GHSA-3827-2vw5-3pm3 An Out-of-bounds Write in RT-Labs P-Net version 1.0.1 or earlier allows an attacker to corrupt the memory of IO devices that use the library by sending a malicious RPC packet. | CVSS3: 4.8 | 0% Низкий | больше 1 года назад | |
GHSA-3826-wfx9-8758 A weakness has been identified in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This impacts an unknown function of the file /index.php of the component SQL Handler. Executing a manipulation can lead to information exposure through error message. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. | CVSS3: 4.3 | 0% Низкий | 3 месяца назад | |
GHSA-3826-h8f4-w96h The HubSpot – CRM, Email Marketing, Live Chat, Forms & Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' attribute of the HubSpot Meeting Widget in all versions up to, and including, 11.1.22 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | CVSS3: 6.4 | 0% Низкий | почти 2 года назад | |
GHSA-3825-9v33-mrxq A potential TOCTOU vulnerability was reported in PC Manager, Lenovo Browser, and Lenovo App Store that could allow a local attacker to cause a system crash. | CVSS3: 4.7 | 0% Низкий | больше 1 года назад | |
GHSA-3825-537p-gqw4 Unrestricted Upload of File with Dangerous Type in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2. | CVSS3: 5.4 | 0% Низкий | почти 3 года назад | |
GHSA-3825-4xhp-w9cc Windows Backup Engine Information Disclosure Vulnerability | CVSS3: 5.5 | 1% Низкий | около 4 лет назад | |
GHSA-3824-qmfq-2qv7 SurrealDB no JavaScript script function default timeout could facilitate DoS | больше 1 года назад | |||
GHSA-3823-wj6r-jpc9 gopher.c in the Gopher client 3.0.5 does not properly create temporary files, which allows local users to gain privileges. | 1% Низкий | больше 4 лет назад | ||
GHSA-3823-hjpv-24g4 An Unquoted Service Path vulnerability exists in Ext2Fsd v0.68 via a specially crafted file in the Ext2Srv Service executable service path. | CVSS3: 7.8 | 0% Низкий | больше 4 лет назад | |
GHSA-3823-3p6j-72p3 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. | 5% Низкий | больше 4 лет назад | ||
GHSA-3822-wwjm-jgg2 Cross-site scripting (XSS) vulnerability in the Gantt applet viewer in IBM Tivoli Change and Configuration Management Database (CCMDB) 7.2.1 and IBM ILOG JViews Gantt allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 1% Низкий | больше 4 лет назад | ||
GHSA-3822-8jq8-pqhh The server API endpoint /report/internet/urls reflects received data into the HTML response without applying proper encoding or filtering. This allows an attacker to execute arbitrary JavaScript in the victim's browser if the victim opens a URL prepared by the attacker. | CVSS3: 6.1 | 0% Низкий | 6 месяцев назад | |
GHSA-37xx-h5fj-hm7p A remote code execution vulnerability is identified in FruityWifi through 2.4. Due to improperly escaped shell metacharacters obtained from the POST request at the page_config_adv.php page, it is possible to perform remote code execution by an authenticated attacker. This is similar to CVE-2018-17317. | 3% Низкий | около 4 лет назад | ||
GHSA-37xx-h4m8-x8wx Simple Machines Forum (SMF) 1-0-5 and earlier supports the use of URLs for avatar images, which allows remote attackers to monitor sensitive information of forum visitors such as IP address and user agent, as demonstrated using a PHP script on a malicious server. | 2% Низкий | больше 4 лет назад | ||
GHSA-37xx-8cjj-f57x IBM Planning Analytics Local 2.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 182283. | 1% Низкий | около 4 лет назад | ||
GHSA-37xx-7qg6-2w7h Trend Micro InterScan VirusWall for Windows NT 3.52 does not record the sender's IP address in the headers for a mail message when it is passed from VirusWall to the MTA, which allows remote attackers to hide the origin of the message. | 2% Низкий | больше 4 лет назад |
Уязвимостей на страницу