Количество 357 271
Количество 357 271
GHSA-33w2-v4x9-r4gw
Unspecified vulnerability in Journalness 3.0.7 and earlier allows remote attackers to create or modify posts via unknown attack vectors.
GHSA-33w2-prhc-2q89
Apport creates a world writable lock file with root ownership in the world writable /var/lock/apport directory. If the apport/ directory does not exist (this is not uncommon as /var/lock is a tmpfs), it will create the directory, otherwise it will simply continue execution using the existing directory. This allows for a symlink attack if an attacker were to create a symlink at /var/lock/apport, changing apport's lock file location. This file could then be used to escalate privileges, for example. Fixed in versions 2.20.1-0ubuntu2.23, 2.20.9-0ubuntu7.14, 2.20.11-0ubuntu8.8 and 2.20.11-0ubuntu22.
GHSA-33vw-m9w6-c8vf
The Logo Slider WordPress plugin before 4.6.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
GHSA-33vw-gcpr-pq49
Pexip Infinity before 28.1 allows remote attackers to trigger a software abort via G.719.
GHSA-33vv-xpr4-7w8v
Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A XCMD can lead to arbitrary command execution. An attacker can send a sequence of malicious commands to trigger these vulnerabilities.This vulnerability specifically focuses on the unsafe use of the `WL_SSID` and `WL_SSID_HEX` configuration values in the function at offset `0x1c7d28` of firmware 6.9Z.
GHSA-33vv-h74c-xmw5
Affected devices do not properly authorize the change password function of the web interface. This could allow low privileged users to escalate their privileges.
GHSA-33vv-cq7w-wvpr
In RestoreMSCWarning() of /coders/pdf.c there are several areas where calls to GetPixelIndex() could result in values outside the range of representable for the unsigned char type. The patch casts the return value of GetPixelIndex() to ssize_t type to avoid this bug. This undefined behavior could be triggered when ImageMagick processes a crafted pdf file. Red Hat Product Security marked this as Low severity because although it could potentially lead to an impact to application availability, no specific impact was demonstrated in this case. This flaw affects ImageMagick versions prior to 7.0.9-0.
GHSA-33vr-wwjf-63w6
An unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameter date_from, date_to, and id_product allows a remote attacker to bypass a web application's authentication and authorization mechanisms and retrieve the contents of an entire database.
GHSA-33vr-pr3m-mfcc
The Custom Login Page Styler – Login Protected Private Site , Change wp-admin login url , WordPress login logo , Temporary admin login access , Rename login , Login customizer, Hide wp-login – Limit Login Attempts – Locked Site plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the 'lps_generate_temp_access_url' AJAX action in all versions up to, and including, 7.1.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to login as other users such as subscribers.
GHSA-33vr-hv7f-mv36
An authenticated arbitrary file upload vulnerability in the /uploads/ endpoint of CMS Made Simple Foundation File Manager v2.2.22 allows attackers with Administrator privileges to execute arbitrary code via uploading a crafted PHP file.
GHSA-33vr-4wpq-62wv
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Remote Network Scanning (XSPA)/DoS OVE-20230524-0013.
GHSA-33vq-frr6-w8mj
In EmberZNet v9.0.2 and earlier, a malformed Level Control Move command can terminate the process through a divide-by-zero fault. This command must come from a device that has already joined the network. Only devices supporting the Level Control cluster may be impacted.
GHSA-33vq-3m9c-jf8p
A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to deny printer connections until the system is rebooted.
GHSA-33vj-x2w7-j3gv
OX App Suite through 7.10.6 allows OS Command Injection via Documentconverter (e.g., through an email attachment).
GHSA-33vj-r832-vf96
A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A malicious app may be able to break out of its sandbox.
GHSA-33vj-r6p6-x4p8
Cross-Site Request Forgery (CSRF) in snipe/snipe-it
GHSA-33vj-92qq-66hc
containerd CRI checkpoint restore CDI annotation smuggling
GHSA-33vh-7x8q-mg35
safe-eval vulnerable to Prototype Pollution
GHSA-33vg-hpx5-pfxg
omniauth-facebook Improper Authentication vulnerability
GHSA-33vg-fjg5-6p64
A directory traversal information disclosure vulnerability exists in HPE StoreOnce Software.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-33w2-v4x9-r4gw Unspecified vulnerability in Journalness 3.0.7 and earlier allows remote attackers to create or modify posts via unknown attack vectors. | 2% Низкий | больше 4 лет назад | ||
GHSA-33w2-prhc-2q89 Apport creates a world writable lock file with root ownership in the world writable /var/lock/apport directory. If the apport/ directory does not exist (this is not uncommon as /var/lock is a tmpfs), it will create the directory, otherwise it will simply continue execution using the existing directory. This allows for a symlink attack if an attacker were to create a symlink at /var/lock/apport, changing apport's lock file location. This file could then be used to escalate privileges, for example. Fixed in versions 2.20.1-0ubuntu2.23, 2.20.9-0ubuntu7.14, 2.20.11-0ubuntu8.8 and 2.20.11-0ubuntu22. | CVSS3: 5.5 | 1% Низкий | около 4 лет назад | |
GHSA-33vw-m9w6-c8vf The Logo Slider WordPress plugin before 4.6.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | CVSS3: 5.4 | 0% Низкий | больше 1 года назад | |
GHSA-33vw-gcpr-pq49 Pexip Infinity before 28.1 allows remote attackers to trigger a software abort via G.719. | CVSS3: 7.5 | 1% Низкий | около 4 лет назад | |
GHSA-33vv-xpr4-7w8v Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A XCMD can lead to arbitrary command execution. An attacker can send a sequence of malicious commands to trigger these vulnerabilities.This vulnerability specifically focuses on the unsafe use of the `WL_SSID` and `WL_SSID_HEX` configuration values in the function at offset `0x1c7d28` of firmware 6.9Z. | CVSS3: 10 | 3% Низкий | почти 4 года назад | |
GHSA-33vv-h74c-xmw5 Affected devices do not properly authorize the change password function of the web interface. This could allow low privileged users to escalate their privileges. | CVSS3: 8.8 | 1% Низкий | почти 4 года назад | |
GHSA-33vv-cq7w-wvpr In RestoreMSCWarning() of /coders/pdf.c there are several areas where calls to GetPixelIndex() could result in values outside the range of representable for the unsigned char type. The patch casts the return value of GetPixelIndex() to ssize_t type to avoid this bug. This undefined behavior could be triggered when ImageMagick processes a crafted pdf file. Red Hat Product Security marked this as Low severity because although it could potentially lead to an impact to application availability, no specific impact was demonstrated in this case. This flaw affects ImageMagick versions prior to 7.0.9-0. | CVSS3: 3.3 | 1% Низкий | около 4 лет назад | |
GHSA-33vr-wwjf-63w6 An unauthenticated Time-Based SQL injection found in Webkul QloApps 1.6.0 via GET parameter date_from, date_to, and id_product allows a remote attacker to bypass a web application's authentication and authorization mechanisms and retrieve the contents of an entire database. | CVSS3: 7.5 | 3% Низкий | около 3 лет назад | |
GHSA-33vr-pr3m-mfcc The Custom Login Page Styler – Login Protected Private Site , Change wp-admin login url , WordPress login logo , Temporary admin login access , Rename login , Login customizer, Hide wp-login – Limit Login Attempts – Locked Site plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the 'lps_generate_temp_access_url' AJAX action in all versions up to, and including, 7.1.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to login as other users such as subscribers. | CVSS3: 8.8 | 1% Низкий | больше 1 года назад | |
GHSA-33vr-hv7f-mv36 An authenticated arbitrary file upload vulnerability in the /uploads/ endpoint of CMS Made Simple Foundation File Manager v2.2.22 allows attackers with Administrator privileges to execute arbitrary code via uploading a crafted PHP file. | CVSS3: 3.8 | 0% Низкий | 9 месяцев назад | |
GHSA-33vr-4wpq-62wv Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Remote Network Scanning (XSPA)/DoS OVE-20230524-0013. | CVSS3: 7.5 | 1% Низкий | больше 1 года назад | |
GHSA-33vq-frr6-w8mj In EmberZNet v9.0.2 and earlier, a malformed Level Control Move command can terminate the process through a divide-by-zero fault. This command must come from a device that has already joined the network. Only devices supporting the Level Control cluster may be impacted. | CVSS3: 6.5 | 0% Низкий | около 2 месяцев назад | |
GHSA-33vq-3m9c-jf8p A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to deny printer connections until the system is rebooted. | CVSS3: 6.5 | 0% Низкий | почти 2 года назад | |
GHSA-33vj-x2w7-j3gv OX App Suite through 7.10.6 allows OS Command Injection via Documentconverter (e.g., through an email attachment). | CVSS3: 9.8 | 3% Низкий | около 4 лет назад | |
GHSA-33vj-r832-vf96 A path handling issue was addressed with improved validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Tahoe 26.6. A malicious app may be able to break out of its sandbox. | CVSS3: 9.8 | 0% Низкий | 16 дней назад | |
GHSA-33vj-r6p6-x4p8 Cross-Site Request Forgery (CSRF) in snipe/snipe-it | CVSS3: 8.8 | 0% Низкий | почти 3 года назад | |
GHSA-33vj-92qq-66hc containerd CRI checkpoint restore CDI annotation smuggling | 0% Низкий | около 2 месяцев назад | ||
GHSA-33vh-7x8q-mg35 safe-eval vulnerable to Prototype Pollution | CVSS3: 9.8 | 1% Низкий | больше 3 лет назад | |
GHSA-33vg-hpx5-pfxg omniauth-facebook Improper Authentication vulnerability | CVSS3: 7.5 | 2% Низкий | больше 4 лет назад | |
GHSA-33vg-fjg5-6p64 A directory traversal information disclosure vulnerability exists in HPE StoreOnce Software. | CVSS3: 9.8 | 1% Низкий | около 1 года назад |
Уязвимостей на страницу