Количество 356 366
Количество 356 366
GHSA-3238-3xx2-28gw
Mozilla Firefox before 3.6.24 and 4.x through 7.0 and Thunderbird before 3.1.6 and 5.0 through 7.0 do not properly handle JavaScript files that contain many functions, which allows user-assisted remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a crafted file that is accessed by debugging APIs, as demonstrated by Firebug.
GHSA-3237-qqm7-mfv7
Information Leak of Memory in getimagesize
GHSA-3237-mfpp-3f69
Multiple SQL injection vulnerabilities in index.php in Pirates of The Caribbean in the E-Gold Game Series allow remote attackers to execute arbitrary SQL commands via the (1) x and (2) y parameters.
GHSA-3236-q4rc-wfw4
Contributor PHP Object Injection in Werkstatt <= 4.8.3 versions.
GHSA-3236-74vm-475v
Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apache Ranger <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue.
GHSA-3236-525j-98r4
The App Store process in CommerceKit Framework in Apple OS X before 10.10.2 places Apple ID credentials in App Store logs, which allows local users to obtain sensitive information by reading a file.
GHSA-3234-gxc3-pq6f
Pimcore Vulnerable to SQL Injection in Custom Reports Column Configuration
GHSA-3233-rgx3-c2wh
Moderate severity vulnerability that affects mustache
GHSA-3233-8p6g-fxq5
Foreman before 1.1 allows remote attackers to execute arbitrary code via a crafted YAML object to the (1) fact or (2) report import API.
GHSA-3232-c8xr-84gw
The Aardvertiser component before 2.2.1 for Joomla! uses insecure permissions (777) in unspecified folders, which allows local users to modify, create, or delete certain files.
GHSA-322x-v876-g883
@asymmetric-effort/nogginlessdom's Path Traversal in matchFileSnapshot allows arbitrary file write
GHSA-322x-jv5h-cvjh
Jenkins Ansible Plugin man in the middle vulnerability
GHSA-322w-f24m-rgpr
Cross-site request forgery (CSRF) vulnerability in Name Directory 1.17.4 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
GHSA-322v-vh2g-qvpv
Mattermost Fails to Restrict Certain Operations on System Admins
GHSA-322v-vc36-f6h9
Improper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause device inoperability.
GHSA-322v-p3jc-7hrg
Cross-Site Request Forgery in Anchor CMS
GHSA-322v-gpc6-pf9f
Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis True Image (Windows) before build 41736.
GHSA-322r-xwx7-m2r9
Adobe Flash Player before 10.2.152.26 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors related to a constructor for an unspecified ActionScript3 object and improper type checking, a different vulnerability than CVE-2011-0559, CVE-2011-0560, CVE-2011-0561, CVE-2011-0571, CVE-2011-0572, CVE-2011-0573, CVE-2011-0574, CVE-2011-0607, and CVE-2011-0608.
GHSA-322r-wfw4-wg3h
A vulnerability, which was classified as critical, was found in lty628 Aidigu up to 1.8.2. This affects the function checkUserCookie of the file /application/common.php of the component PHP Object Handler. The manipulation of the argument rememberMe leads to deserialization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
GHSA-322r-r98c-pph2
PAM exposure enabling unauthenticated access to remote host
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3238-3xx2-28gw Mozilla Firefox before 3.6.24 and 4.x through 7.0 and Thunderbird before 3.1.6 and 5.0 through 7.0 do not properly handle JavaScript files that contain many functions, which allows user-assisted remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a crafted file that is accessed by debugging APIs, as demonstrated by Firebug. | 2% Низкий | около 4 лет назад | ||
GHSA-3237-qqm7-mfv7 Information Leak of Memory in getimagesize | 0% Низкий | 8 месяцев назад | ||
GHSA-3237-mfpp-3f69 Multiple SQL injection vulnerabilities in index.php in Pirates of The Caribbean in the E-Gold Game Series allow remote attackers to execute arbitrary SQL commands via the (1) x and (2) y parameters. | 1% Низкий | больше 4 лет назад | ||
GHSA-3236-q4rc-wfw4 Contributor PHP Object Injection in Werkstatt <= 4.8.3 versions. | CVSS3: 8.8 | 0% Низкий | около 1 месяца назад | |
GHSA-3236-74vm-475v Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apache Ranger <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue. | 1 день назад | |||
GHSA-3236-525j-98r4 The App Store process in CommerceKit Framework in Apple OS X before 10.10.2 places Apple ID credentials in App Store logs, which allows local users to obtain sensitive information by reading a file. | 0% Низкий | около 4 лет назад | ||
GHSA-3234-gxc3-pq6f Pimcore Vulnerable to SQL Injection in Custom Reports Column Configuration | CVSS3: 8.7 | 0% Низкий | 3 месяца назад | |
GHSA-3233-rgx3-c2wh Moderate severity vulnerability that affects mustache | почти 8 лет назад | |||
GHSA-3233-8p6g-fxq5 Foreman before 1.1 allows remote attackers to execute arbitrary code via a crafted YAML object to the (1) fact or (2) report import API. | 3% Низкий | больше 4 лет назад | ||
GHSA-3232-c8xr-84gw The Aardvertiser component before 2.2.1 for Joomla! uses insecure permissions (777) in unspecified folders, which allows local users to modify, create, or delete certain files. | 0% Низкий | около 4 лет назад | ||
GHSA-322x-v876-g883 @asymmetric-effort/nogginlessdom's Path Traversal in matchFileSnapshot allows arbitrary file write | около 1 месяца назад | |||
GHSA-322x-jv5h-cvjh Jenkins Ansible Plugin man in the middle vulnerability | CVSS3: 5.6 | 1% Низкий | около 4 лет назад | |
GHSA-322w-f24m-rgpr Cross-site request forgery (CSRF) vulnerability in Name Directory 1.17.4 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors. | 1% Низкий | около 4 лет назад | ||
GHSA-322v-vh2g-qvpv Mattermost Fails to Restrict Certain Operations on System Admins | CVSS3: 4.7 | 0% Низкий | больше 1 года назад | |
GHSA-322v-vc36-f6h9 Improper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause device inoperability. | 1 день назад | |||
GHSA-322v-p3jc-7hrg Cross-Site Request Forgery in Anchor CMS | CVSS3: 4.5 | 0% Низкий | больше 4 лет назад | |
GHSA-322v-gpc6-pf9f Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis True Image (Windows) before build 41736. | CVSS3: 5.5 | 0% Низкий | больше 1 года назад | |
GHSA-322r-xwx7-m2r9 Adobe Flash Player before 10.2.152.26 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors related to a constructor for an unspecified ActionScript3 object and improper type checking, a different vulnerability than CVE-2011-0559, CVE-2011-0560, CVE-2011-0561, CVE-2011-0571, CVE-2011-0572, CVE-2011-0573, CVE-2011-0574, CVE-2011-0607, and CVE-2011-0608. | 6% Низкий | около 4 лет назад | ||
GHSA-322r-wfw4-wg3h A vulnerability, which was classified as critical, was found in lty628 Aidigu up to 1.8.2. This affects the function checkUserCookie of the file /application/common.php of the component PHP Object Handler. The manipulation of the argument rememberMe leads to deserialization. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 7.3 | 0% Низкий | около 1 года назад | |
GHSA-322r-r98c-pph2 PAM exposure enabling unauthenticated access to remote host | CVSS3: 9.8 | 1% Низкий | около 4 лет назад |
Уязвимостей на страницу