Количество 358 234
Количество 358 234
GHSA-36fv-g9xp-84xv
Missing Authorization vulnerability in Mizan Themes Mizan Demo Importer mizan-demo-importer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mizan Demo Importer: from n/a through <= 0.1.3.
GHSA-36fv-7fxv-xr4g
Buffer overflow in Microsoft Clip Art Gallery allows remote attackers to cause a denial of service or execute commands via a malformed CIL (clip art library) file, aka the "Clip Art Buffer Overrun" vulnerability.
GHSA-36fv-6vjc-jf92
If LDAP settings are accessed, authentication could be redirected to another server, potentially exposing credentials. This requires admin access and an active LDAP setup.
GHSA-36fr-xc4j-fmhw
Cryoserver Security Appliance 7.3.x uses weak permissions for /etc/init.d/cryoserver, which allows local users to gain privileges by leveraging access to the support account and running the /bin/cryo-mgmt program.
GHSA-36fr-w5h7-5f28
Stack-based buffer overflow in the TMregChange function in TMReg.dll in Trend Micro ServerProtect before 5.58 Security Patch 4 allows remote attackers to execute arbitrary code via a crafted packet to TCP port 5005.
GHSA-36fr-3wg8-q5v8
Concrete CMS Cross-site Scripting vulnerability
GHSA-36fr-2gcj-778v
A vulnerability, which was classified as problematic, was found in finixbit elf-parser. Affected is the function elf_parser::Elf_parser::get_segments of the file elf_parser.cpp. The manipulation leads to denial of service. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. VDB-222222 is the identifier assigned to this vulnerability.
GHSA-36fq-jgmw-4r9c
Keras is vulnerable to Deserialization of Untrusted Data
GHSA-36fq-6c6v-89gr
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Select-Themes Stockholm Core allows Reflected XSS.This issue affects Stockholm Core: from n/a through 2.4.1.
GHSA-36fq-3276-7898
A vulnerability classified as critical has been found in OpenRapid RapidCMS up to 1.3.1. Affected is an unknown function of the file /resource/runlogon.php. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
GHSA-36fp-xj79-95mx
Links may not be rewritten according to policy in some specially formatted emails.
GHSA-36fm-v9wv-56jf
Cross-site Scripting in OpenCart
GHSA-36fm-j33w-c25f
Privilege escalation (PR)/RCE from account through class sheet
GHSA-36fm-f9h6-j5xh
A vulnerability was found in Red Hat OpenShift Jenkins. The bearer token is not obfuscated in the logs and potentially carries a high risk if those logs are centralized when collected. The token is typically valid for one year. This flaw allows a malicious user to jeopardize the environment if they have access to sensitive information.
GHSA-36fh-9j3c-fp3f
Insufficient validation of untrusted input in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
GHSA-36fh-84j7-cv5h
JSZip contains Path Traversal via loadAsync
GHSA-36fh-2j8m-mpcw
Buffer overflow in MyWebServer 1.02 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request.
GHSA-36fg-whr2-g999
Jenkins NodeJS Plugin improper credential masking vulnerability
GHSA-36fg-v524-g4r4
A vulnerability was found in Mercusys MW301R 1.0.2 Build 190726 Rel.59423n. It has been rated as problematic. This issue affects some unknown processing of the component Login. The manipulation leads to improper restriction of excessive authentication attempts. The attack can only be initiated within the local network. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
GHSA-36fg-r84v-4px6
A flaw has been found in Tenda M3 1.0.0.12. Affected is the function formQuickIndex of the file /goform/QuickIndex. Executing manipulation of the argument PPPOEPassword can lead to stack-based buffer overflow. The attack can be launched remotely. The exploit has been published and may be used.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-36fv-g9xp-84xv Missing Authorization vulnerability in Mizan Themes Mizan Demo Importer mizan-demo-importer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Mizan Demo Importer: from n/a through <= 0.1.3. | CVSS3: 5.4 | 0% Низкий | 6 месяцев назад | |
GHSA-36fv-7fxv-xr4g Buffer overflow in Microsoft Clip Art Gallery allows remote attackers to cause a denial of service or execute commands via a malformed CIL (clip art library) file, aka the "Clip Art Buffer Overrun" vulnerability. | 16% Средний | больше 4 лет назад | ||
GHSA-36fv-6vjc-jf92 If LDAP settings are accessed, authentication could be redirected to another server, potentially exposing credentials. This requires admin access and an active LDAP setup. | CVSS3: 6.7 | 1% Низкий | больше 1 года назад | |
GHSA-36fr-xc4j-fmhw Cryoserver Security Appliance 7.3.x uses weak permissions for /etc/init.d/cryoserver, which allows local users to gain privileges by leveraging access to the support account and running the /bin/cryo-mgmt program. | 0% Низкий | около 4 лет назад | ||
GHSA-36fr-w5h7-5f28 Stack-based buffer overflow in the TMregChange function in TMReg.dll in Trend Micro ServerProtect before 5.58 Security Patch 4 allows remote attackers to execute arbitrary code via a crafted packet to TCP port 5005. | 10% Низкий | больше 4 лет назад | ||
GHSA-36fr-3wg8-q5v8 Concrete CMS Cross-site Scripting vulnerability | CVSS3: 3.5 | 1% Низкий | больше 2 лет назад | |
GHSA-36fr-2gcj-778v A vulnerability, which was classified as problematic, was found in finixbit elf-parser. Affected is the function elf_parser::Elf_parser::get_segments of the file elf_parser.cpp. The manipulation leads to denial of service. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. VDB-222222 is the identifier assigned to this vulnerability. | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
GHSA-36fq-jgmw-4r9c Keras is vulnerable to Deserialization of Untrusted Data | CVSS3: 7.3 | 0% Низкий | 11 месяцев назад | |
GHSA-36fq-6c6v-89gr Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Select-Themes Stockholm Core allows Reflected XSS.This issue affects Stockholm Core: from n/a through 2.4.1. | CVSS3: 7.1 | 0% Низкий | больше 2 лет назад | |
GHSA-36fq-3276-7898 A vulnerability classified as critical has been found in OpenRapid RapidCMS up to 1.3.1. Affected is an unknown function of the file /resource/runlogon.php. The manipulation of the argument username leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 6.3 | 1% Низкий | почти 2 года назад | |
GHSA-36fp-xj79-95mx Links may not be rewritten according to policy in some specially formatted emails. | CVSS3: 5.3 | 1% Низкий | больше 4 лет назад | |
GHSA-36fm-v9wv-56jf Cross-site Scripting in OpenCart | CVSS3: 5.4 | 3% Низкий | больше 5 лет назад | |
GHSA-36fm-j33w-c25f Privilege escalation (PR)/RCE from account through class sheet | CVSS3: 9.9 | 1% Низкий | больше 3 лет назад | |
GHSA-36fm-f9h6-j5xh A vulnerability was found in Red Hat OpenShift Jenkins. The bearer token is not obfuscated in the logs and potentially carries a high risk if those logs are centralized when collected. The token is typically valid for one year. This flaw allows a malicious user to jeopardize the environment if they have access to sensitive information. | CVSS3: 6.5 | 0% Низкий | около 1 года назад | |
GHSA-36fh-9j3c-fp3f Insufficient validation of untrusted input in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | CVSS3: 8.3 | 0% Низкий | 17 дней назад | |
GHSA-36fh-84j7-cv5h JSZip contains Path Traversal via loadAsync | CVSS3: 7.3 | 1% Низкий | больше 3 лет назад | |
GHSA-36fh-2j8m-mpcw Buffer overflow in MyWebServer 1.02 and earlier allows remote attackers to execute arbitrary code via a long HTTP GET request. | 3% Низкий | больше 4 лет назад | ||
GHSA-36fg-whr2-g999 Jenkins NodeJS Plugin improper credential masking vulnerability | CVSS3: 4.3 | 1% Низкий | почти 3 года назад | |
GHSA-36fg-v524-g4r4 A vulnerability was found in Mercusys MW301R 1.0.2 Build 190726 Rel.59423n. It has been rated as problematic. This issue affects some unknown processing of the component Login. The manipulation leads to improper restriction of excessive authentication attempts. The attack can only be initiated within the local network. The complexity of an attack is rather high. The exploitation is known to be difficult. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 3.1 | 0% Низкий | около 1 года назад | |
GHSA-36fg-r84v-4px6 A flaw has been found in Tenda M3 1.0.0.12. Affected is the function formQuickIndex of the file /goform/QuickIndex. Executing manipulation of the argument PPPOEPassword can lead to stack-based buffer overflow. The attack can be launched remotely. The exploit has been published and may be used. | CVSS3: 8.8 | 1% Низкий | 12 месяцев назад |
Уязвимостей на страницу