Количество 343 076
Количество 343 076
GHSA-27qh-8cxx-2cr5
AWS SDK for PHP has CloudFront Policy Document Injection via Special Characters
GHSA-27qh-4m42-f89x
Unknown vulnerability in the eflags checking in the 32-bit ptrace emulation for the Linux kernel on AMD64 systems allows local users to gain privileges.
GHSA-27qg-h9vp-x2xp
HCL DRYiCE MyXalytics product is impacted by unauthenticated file upload vulnerability. The web application permits the upload of a certain file without requiring user authentication.
GHSA-27qg-f2r7-8953
Improper input validation for some Intel(R) PROSet/Wireless WiFi in multiple operating systems and Killer(TM) WiFi in Windows 10 and 11 may allow an authenticated user to potentially enable denial of service via adjacent access.
GHSA-27qf-jwm8-g7f3
FPE in LSH in TFLite
GHSA-27qc-m5gf-jv5r
SiYuan Bazaar marketplace renders unescaped package `name` and `version` metadata, allowing stored XSS and Electron code execution
GHSA-27qc-c946-g657
CUPS on Mandriva Linux 2008.0, 2008.1, 2009.0, Corporate Server (CS) 3.0 and 4.0, and Multi Network Firewall (MNF) 2.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pdf.log temporary file.
GHSA-27qc-3h99-8rcj
Parallels H-Sphere 3.6.2 allows XSS via the index_en.php from parameter.
GHSA-27qc-3c4c-hwfw
Mate 9 with software MHA-AL00AC00B125 has a denial of service (DoS) vulnerability. An attacker tricks a user into installing a malicious application. Since the system does not verify the broadcasting message from the application, it could be exploited to cause some functions of system unavailable.
GHSA-27q9-h529-q4g3
OpenSSH through 9.6, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) because the integer value of authenticated in mm_answer_authpassword does not resist flips of a single bit. NOTE: this is applicable to a certain threat model of attacker-victim co-location in which the attacker has user privileges.
GHSA-27q9-g54w-g6cm
msxlsview.sh in xlsview for catdoc 0.91 and earlier allows local users to overwrite arbitrary files via a symlink attack on predictable temporary file names ("word$$.html").
GHSA-27q8-8p72-c44c
Trend Micro Security (Consumer) 2020 (v16.x) is affected by a vulnerability in where null pointer dereference errors result in the crash of application, which could potentially lead to possible unsigned code execution under certain circumstances.
GHSA-27q8-895c-wpmq
Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.1, and 11.2.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2011-0832 and CVE-2011-0835.
GHSA-27q7-wq4m-6cjm
In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 820, SD 835, SD 845, SD 850, added a change to check if the pointer has been reset to NULL or not, before writing to the memory pointed by the pointer.
GHSA-27q7-wp8x-jjqq
A vulnerability has been found in D-Link DIR-816L 2_06_b09_beta. This affects the function genacgi_main of the file gena.cgi. The manipulation of the argument SERVER_ID/HTTP_SID leads to stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer.
GHSA-27q7-gwcr-rrqp
A vulnerability in Brocade Fabric OS before 9.2.1 could allow an authenticated attacker with admin privileges using the shell command “grep” to modify the path variables and move upwards in the directory structure or to traverse to different directories.
GHSA-27q6-m98q-fwm4
The Meatmeet Pro was found to be shipped with hardcoded Wi-Fi credentials in the firmware, for the test network it was developed on. If an attacker retrieved this, and found the physical location of the Wi-Fi network, they could gain unauthorized access to the Wi-Fi network of the vendor. Additionally, if an attacker were located in close physical proximity to the device when it was first set up, they may be able to force the device to auto-connect to an attacker-controlled access point by setting the SSID and password to the same as which was found in the firmware file.
GHSA-27q6-jp9h-qgc8
A vulnerability, which was classified as problematic, has been found in admont28 Ingnovarq. Affected by this issue is some unknown functionality of the file app/controller/insertarSliderAjax.php. The manipulation of the argument imagetitle leads to cross site scripting. The attack may be launched remotely. The name of the patch is 9d18a39944d79dfedacd754a742df38f99d3c0e2. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-217172.
GHSA-27q6-c3vc-27q9
StudentManage v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Add A New Student module.
GHSA-27q6-3499-5x87
In JetBrains TeamCity before 2023.05 parameters of the "password" type from build dependencies could be logged in some cases
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-27qh-8cxx-2cr5 AWS SDK for PHP has CloudFront Policy Document Injection via Special Characters | 5 месяцев назад | |||
GHSA-27qh-4m42-f89x Unknown vulnerability in the eflags checking in the 32-bit ptrace emulation for the Linux kernel on AMD64 systems allows local users to gain privileges. | 0% Низкий | больше 4 лет назад | ||
GHSA-27qg-h9vp-x2xp HCL DRYiCE MyXalytics product is impacted by unauthenticated file upload vulnerability. The web application permits the upload of a certain file without requiring user authentication. | CVSS3: 8.2 | 1% Низкий | больше 2 лет назад | |
GHSA-27qg-f2r7-8953 Improper input validation for some Intel(R) PROSet/Wireless WiFi in multiple operating systems and Killer(TM) WiFi in Windows 10 and 11 may allow an authenticated user to potentially enable denial of service via adjacent access. | CVSS3: 5.7 | 0% Низкий | больше 4 лет назад | |
GHSA-27qf-jwm8-g7f3 FPE in LSH in TFLite | CVSS3: 5.5 | 0% Низкий | почти 5 лет назад | |
GHSA-27qc-m5gf-jv5r SiYuan Bazaar marketplace renders unescaped package `name` and `version` metadata, allowing stored XSS and Electron code execution | CVSS3: 9 | 0% Низкий | 3 месяца назад | |
GHSA-27qc-c946-g657 CUPS on Mandriva Linux 2008.0, 2008.1, 2009.0, Corporate Server (CS) 3.0 and 4.0, and Multi Network Firewall (MNF) 2.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pdf.log temporary file. | 0% Низкий | больше 4 лет назад | ||
GHSA-27qc-3h99-8rcj Parallels H-Sphere 3.6.2 allows XSS via the index_en.php from parameter. | CVSS3: 6.1 | 2% Низкий | около 4 лет назад | |
GHSA-27qc-3c4c-hwfw Mate 9 with software MHA-AL00AC00B125 has a denial of service (DoS) vulnerability. An attacker tricks a user into installing a malicious application. Since the system does not verify the broadcasting message from the application, it could be exploited to cause some functions of system unavailable. | CVSS3: 3.3 | 0% Низкий | около 4 лет назад | |
GHSA-27q9-h529-q4g3 OpenSSH through 9.6, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) because the integer value of authenticated in mm_answer_authpassword does not resist flips of a single bit. NOTE: this is applicable to a certain threat model of attacker-victim co-location in which the attacker has user privileges. | CVSS3: 7 | 1% Низкий | больше 2 лет назад | |
GHSA-27q9-g54w-g6cm msxlsview.sh in xlsview for catdoc 0.91 and earlier allows local users to overwrite arbitrary files via a symlink attack on predictable temporary file names ("word$$.html"). | 0% Низкий | больше 4 лет назад | ||
GHSA-27q8-8p72-c44c Trend Micro Security (Consumer) 2020 (v16.x) is affected by a vulnerability in where null pointer dereference errors result in the crash of application, which could potentially lead to possible unsigned code execution under certain circumstances. | 3% Низкий | около 4 лет назад | ||
GHSA-27q8-895c-wpmq Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.1, and 11.2.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than CVE-2011-0832 and CVE-2011-0835. | 2% Низкий | около 4 лет назад | ||
GHSA-27q7-wq4m-6cjm In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 820, SD 835, SD 845, SD 850, added a change to check if the pointer has been reset to NULL or not, before writing to the memory pointed by the pointer. | CVSS3: 9.8 | 1% Низкий | около 4 лет назад | |
GHSA-27q7-wp8x-jjqq A vulnerability has been found in D-Link DIR-816L 2_06_b09_beta. This affects the function genacgi_main of the file gena.cgi. The manipulation of the argument SERVER_ID/HTTP_SID leads to stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. This vulnerability only affects products that are no longer supported by the maintainer. | CVSS3: 8.8 | 1% Низкий | 9 месяцев назад | |
GHSA-27q7-gwcr-rrqp A vulnerability in Brocade Fabric OS before 9.2.1 could allow an authenticated attacker with admin privileges using the shell command “grep” to modify the path variables and move upwards in the directory structure or to traverse to different directories. | CVSS3: 2.3 | 0% Низкий | 6 месяцев назад | |
GHSA-27q6-m98q-fwm4 The Meatmeet Pro was found to be shipped with hardcoded Wi-Fi credentials in the firmware, for the test network it was developed on. If an attacker retrieved this, and found the physical location of the Wi-Fi network, they could gain unauthorized access to the Wi-Fi network of the vendor. Additionally, if an attacker were located in close physical proximity to the device when it was first set up, they may be able to force the device to auto-connect to an attacker-controlled access point by setting the SSID and password to the same as which was found in the firmware file. | CVSS3: 9.8 | 0% Низкий | 8 месяцев назад | |
GHSA-27q6-jp9h-qgc8 A vulnerability, which was classified as problematic, has been found in admont28 Ingnovarq. Affected by this issue is some unknown functionality of the file app/controller/insertarSliderAjax.php. The manipulation of the argument imagetitle leads to cross site scripting. The attack may be launched remotely. The name of the patch is 9d18a39944d79dfedacd754a742df38f99d3c0e2. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-217172. | CVSS3: 6.1 | 1% Низкий | больше 3 лет назад | |
GHSA-27q6-c3vc-27q9 StudentManage v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Add A New Student module. | CVSS3: 4.8 | 0% Низкий | около 1 года назад | |
GHSA-27q6-3499-5x87 In JetBrains TeamCity before 2023.05 parameters of the "password" type from build dependencies could be logged in some cases | CVSS3: 4.3 | 1% Низкий | около 3 лет назад |
Уязвимостей на страницу