Количество 357 271
Количество 357 271
GHSA-33vg-9h99-96pc
A denial of service issue was addressed with improved input validation.
GHSA-33vf-v7x5-68hh
Inappropriate implementation in Omnibox in Google Chrome on iOS prior to 77.0.3865.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
GHSA-33vf-chjh-98j4
Buffer overflow in the RTSP protocol parser for the View Source plug-in (vsrcplin.so or vsrcplin3260.dll) for RealNetworks Helix Universal Server 9 and RealSystem Server 8, 7 and RealServer G2 allows remote attackers to execute arbitrary code.
GHSA-33vf-9722-2226
softmagic.c in file before 5.17 and libmagic allows context-dependent attackers to cause a denial of service (out-of-bounds memory access and crash) via crafted offsets in the softmagic of a PE executable.
GHSA-33vf-4xgg-9r58
HTTP Response Splitting (Early Hints) in Puma
GHSA-33vc-wfww-vjfv
jsondiffpatch is vulnerable to Cross-site Scripting (XSS) via HtmlFormatter::nodeBegin
GHSA-33vc-mr28-327x
In GraphicsMagick 1.4 snapshot-20181209 Q8, there is a heap-based buffer overflow in the WriteTGAImage function of tga.c, which allows attackers to cause a denial of service via a crafted image file, because the number of rows or columns can exceed the pixel-dimension restrictions of the TGA specification.
GHSA-33vc-jm33-3f35
Zammad before 6.4.1 places sensitive data (such as auth_microsoft_office365_credentials and application_secret) in log files.
GHSA-33v9-rqhp-2p82
Multiple cross-site scripting (XSS) vulnerabilities in register.php in Piwigo 2.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) login and (2) mail_address parameters.
GHSA-33v9-jfq7-pmxc
Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 153.
GHSA-33v9-9rxf-3675
On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.2, and 13.1.x before 13.1.4, when JSON content profiles are configured for URLs as part of an F5 Advanced Web Application Firewall (WAF)/BIG-IP ASM security policy and applied to a virtual server, undisclosed requests may cause the BIG-IP ASM bd process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
GHSA-33v9-7cpf-3wr4
Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally.
GHSA-33v8-g7j5-qg76
OS Command Injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary OS command may be executed on the products.
GHSA-33v7-x483-jjjx
An out-of-bounds read exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service and read sensitive memory.
GHSA-33v7-h6gx-6h2h
In getAppSize of InstalldNativeService.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-220733817
GHSA-33v7-2ghp-xqch
Improper buffer restrictions in firmware for Intel(R) NUC may allow an authenticated user to potentially enable escalation of privilege via local access. The list of affected products is provided in intel-sa-00343: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00343.html
GHSA-33v5-vv3q-q64q
Cross-site scripting (XSS) vulnerability in EditModule.aspx for DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to inject arbitrary web script or HTML.
GHSA-33v5-9rfm-w3f4
The WP QuickLaTeX WordPress plugin before 3.8.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
GHSA-33v5-6gf6-m6w4
Multiple stack-based buffer overflows in the CPLI_ReadTag_OGG function in CPI_PlaylistItem.c in CoolPlayer 217 and earlier allow user-assisted remote attackers to execute arbitrary code via a long (1) cTag or (2) cValue field in an OGG Vorbis file.
GHSA-33v4-rh3c-mhcg
A local file disclosure vulnerability in /appConfig/userDB.json of Telos Alliance Omnia MPX Node through 1.5.0+r1 allows attackers to escalate privileges to root and execute arbitrary commands.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-33vg-9h99-96pc A denial of service issue was addressed with improved input validation. | 2% Низкий | около 4 лет назад | ||
GHSA-33vf-v7x5-68hh Inappropriate implementation in Omnibox in Google Chrome on iOS prior to 77.0.3865.75 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. | 1% Низкий | около 4 лет назад | ||
GHSA-33vf-chjh-98j4 Buffer overflow in the RTSP protocol parser for the View Source plug-in (vsrcplin.so or vsrcplin3260.dll) for RealNetworks Helix Universal Server 9 and RealSystem Server 8, 7 and RealServer G2 allows remote attackers to execute arbitrary code. | 49% Средний | больше 4 лет назад | ||
GHSA-33vf-9722-2226 softmagic.c in file before 5.17 and libmagic allows context-dependent attackers to cause a denial of service (out-of-bounds memory access and crash) via crafted offsets in the softmagic of a PE executable. | 4% Низкий | около 4 лет назад | ||
GHSA-33vf-4xgg-9r58 HTTP Response Splitting (Early Hints) in Puma | CVSS3: 6.5 | 2% Низкий | больше 6 лет назад | |
GHSA-33vc-wfww-vjfv jsondiffpatch is vulnerable to Cross-site Scripting (XSS) via HtmlFormatter::nodeBegin | CVSS3: 4.7 | 0% Низкий | 11 месяцев назад | |
GHSA-33vc-mr28-327x In GraphicsMagick 1.4 snapshot-20181209 Q8, there is a heap-based buffer overflow in the WriteTGAImage function of tga.c, which allows attackers to cause a denial of service via a crafted image file, because the number of rows or columns can exceed the pixel-dimension restrictions of the TGA specification. | CVSS3: 6.5 | 2% Низкий | больше 4 лет назад | |
GHSA-33vc-jm33-3f35 Zammad before 6.4.1 places sensitive data (such as auth_microsoft_office365_credentials and application_secret) in log files. | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
GHSA-33v9-rqhp-2p82 Multiple cross-site scripting (XSS) vulnerabilities in register.php in Piwigo 2.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) login and (2) mail_address parameters. | 1% Низкий | около 4 лет назад | ||
GHSA-33v9-jfq7-pmxc Spoofing issue in the Address Bar component. This vulnerability was fixed in Firefox 153. | CVSS3: 6.5 | 0% Низкий | 23 дня назад | |
GHSA-33v9-9rxf-3675 On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.2, and 13.1.x before 13.1.4, when JSON content profiles are configured for URLs as part of an F5 Advanced Web Application Firewall (WAF)/BIG-IP ASM security policy and applied to a virtual server, undisclosed requests may cause the BIG-IP ASM bd process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 1% Низкий | около 4 лет назад | ||
GHSA-33v9-7cpf-3wr4 Out-of-bounds read in Push Message Routing Service allows an authorized attacker to disclose information locally. | CVSS3: 5.5 | 0% Низкий | 5 месяцев назад | |
GHSA-33v8-g7j5-qg76 OS Command Injection vulnerability exists in BUFFALO Wi-Fi router products. If this vulnerability is exploited, an arbitrary OS command may be executed on the products. | CVSS3: 8.8 | 1% Низкий | 5 месяцев назад | |
GHSA-33v7-x483-jjjx An out-of-bounds read exists in Info-Zip UnZip version 6.10c22 that allows an attacker to perform a denial of service and read sensitive memory. | CVSS3: 9.1 | 1% Низкий | около 4 лет назад | |
GHSA-33v7-h6gx-6h2h In getAppSize of InstalldNativeService.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12LAndroid ID: A-220733817 | CVSS3: 6.7 | 0% Низкий | около 4 лет назад | |
GHSA-33v7-2ghp-xqch Improper buffer restrictions in firmware for Intel(R) NUC may allow an authenticated user to potentially enable escalation of privilege via local access. The list of affected products is provided in intel-sa-00343: https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00343.html | 0% Низкий | около 4 лет назад | ||
GHSA-33v5-vv3q-q64q Cross-site scripting (XSS) vulnerability in EditModule.aspx for DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to inject arbitrary web script or HTML. | 1% Низкий | больше 4 лет назад | ||
GHSA-33v5-9rfm-w3f4 The WP QuickLaTeX WordPress plugin before 3.8.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | CVSS3: 7.1 | 0% Низкий | около 2 лет назад | |
GHSA-33v5-6gf6-m6w4 Multiple stack-based buffer overflows in the CPLI_ReadTag_OGG function in CPI_PlaylistItem.c in CoolPlayer 217 and earlier allow user-assisted remote attackers to execute arbitrary code via a long (1) cTag or (2) cValue field in an OGG Vorbis file. | 5% Низкий | больше 4 лет назад | ||
GHSA-33v4-rh3c-mhcg A local file disclosure vulnerability in /appConfig/userDB.json of Telos Alliance Omnia MPX Node through 1.5.0+r1 allows attackers to escalate privileges to root and execute arbitrary commands. | CVSS3: 9.8 | 10% Низкий | почти 4 года назад |
Уязвимостей на страницу