Количество 351 264
Количество 351 264
GHSA-2m6v-xpgq-6gwv
Edimax BR-6208AC V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. They forward ARP requests, which are sent as broadcast packets, between the host and the guest networks. To use this leakage as a direct covert channel, the sender can trivially issue an ARP request to an arbitrary computer on the network. (In general, some routers restrict ARP forwarding only to requests destined for the network's subnet mask, but these routers did not restrict this traffic in any way. Depending on this factor, one must use either the lower 8 bits of the IP address, or the entire 32 bits, as the data payload.)
GHSA-2m6v-mggf-5f9g
Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability
GHSA-2m6v-8g4p-879p
Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise CS Campus Community accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
GHSA-2m6r-pj86-q7hh
Improper input validation in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally.
GHSA-2m6q-rj94-6952
An issue has been discovered in GitLab CE/EE affecting all versions from 8.6 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. File integrity may be compromised when source code or installation packages are pulled from a tag or from a release containing a ref to another commit.
GHSA-2m6q-934x-xjrf
Multiple issues were addressed by updating to curl version 7.79.1. This issue is fixed in macOS Monterey 12.3. Multiple issues in curl.
GHSA-2m6q-44fc-j46f
A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7.
GHSA-2m6p-rg3r-28gh
The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21, when the Revision 1179239 patch is in place, does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a malformed URI containing an @ (at sign) character and a : (colon) character in invalid positions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-3368.
GHSA-2m6p-hm3w-6jm3
HAX CMS: Stored XSS via '<video-player>' component allows arbitrary JavaScript execution and token theft
GHSA-2m6m-r8c9-84hh
In the Linux kernel, the following vulnerability has been resolved: RDMA: During rereg_mr ensure that REREG_ACCESS is compatible If IB_MR_REREG_ACCESS changes from RO to RW then the umem has to be re-evaluated to ensure it is properly pinned as RW. Since the umem is hidden inside each driver's mr struct add a ib_umem_check_rereg() function that each driver has to call before processing IB_MR_REREG_ACCESS. mlx4 has to retain its duplicate ib_access_writable check because it implements IB_MR_REREG_ACCESS | IB_MR_REREG_TRANS by changing both items in place sequentially while the MR is live, so it will continue to not support this combination.
GHSA-2m6m-p8vh-r2f9
In Docker Notary before 0.1, the checkRoot function in gotuf/client/client.go does not check expiry of root.json files, despite a comment stating that it does. Even if a user creates a new root.json file after a key compromise, an attacker can produce update files referring to an old root.json file.
GHSA-2m6m-4m28-hxfc
Windows SharePoint Services and SharePoint Team Services for Windows Server 2003 does not properly validate an HTTP redirection query, which allows remote attackers to inject arbitrary HTML and web script via a cross-site scripting (XSS) attack, or to spoof the web cache.
GHSA-2m6j-m8rm-273p
Cross-site scripting (XSS) vulnerability in apps/app_comment/form_comment.php in Fiyo CMS 1.5.7 allows remote attackers to inject arbitrary web script or HTML via the Nama field.
GHSA-2m6j-6wxg-cj77
Adobe Premiere Pro versions 22.0 (and earlier) and 15.4.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
GHSA-2m6g-crv8-p3c6
Parse Server vulnerable to brute force guessing of user sensitive data via search patterns
GHSA-2m6f-mg5g-38jv
The Guile plugin for the Gnumeric spreadsheet package allows attackers to execute arbitrary code.
GHSA-2m6f-fj9h-6vmp
A Stored Cross-Site Scripting (XSS) Vulnerability in Chamilo LMS 1.11.26 allows a remote attacker to execute arbitrary JavaScript in a web browser by including a malicious payload in the 'content' parameter of 'group_topics.php'.
GHSA-2m69-x28v-rwx9
cgi-bin/admin.cgi in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 does not require token authentication, which allows remote attackers to add administrative accounts via a userprefs action.
GHSA-2m69-jmvh-6chr
CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule
GHSA-2m69-gcr7-jv3q
SQLitePCLRaw.lib.e_sqlite3 has a vulnerable dependency on SQLite
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2m6v-xpgq-6gwv Edimax BR-6208AC V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. They forward ARP requests, which are sent as broadcast packets, between the host and the guest networks. To use this leakage as a direct covert channel, the sender can trivially issue an ARP request to an arbitrary computer on the network. (In general, some routers restrict ARP forwarding only to requests destined for the network's subnet mask, but these routers did not restrict this traffic in any way. Depending on this factor, one must use either the lower 8 bits of the IP address, or the entire 32 bits, as the data payload.) | 1% Низкий | около 4 лет назад | ||
GHSA-2m6v-mggf-5f9g Microsoft Jet Red Database Engine and Access Connectivity Engine Remote Code Execution Vulnerability | CVSS3: 8.8 | 2% Низкий | около 4 лет назад | |
GHSA-2m6v-8g4p-879p Vulnerability in the PeopleSoft Enterprise CS Campus Community product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2.38. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise CS Campus Community. Successful attacks of this vulnerability can result in unauthorized read access to a subset of PeopleSoft Enterprise CS Campus Community accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N). | CVSS3: 5.3 | 0% Низкий | 18 дней назад | |
GHSA-2m6r-pj86-q7hh Improper input validation in Windows Storage VSP Driver allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | около 1 года назад | |
GHSA-2m6q-rj94-6952 An issue has been discovered in GitLab CE/EE affecting all versions from 8.6 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. File integrity may be compromised when source code or installation packages are pulled from a tag or from a release containing a ref to another commit. | CVSS3: 5.7 | 1% Низкий | больше 3 лет назад | |
GHSA-2m6q-934x-xjrf Multiple issues were addressed by updating to curl version 7.79.1. This issue is fixed in macOS Monterey 12.3. Multiple issues in curl. | CVSS3: 9.8 | больше 4 лет назад | ||
GHSA-2m6q-44fc-j46f A cross-site scripting issue existed in Safari. This issue was addressed with improved URL validation. This issue affected versions prior to iOS 12, tvOS 12, Safari 12, iTunes 12.9 for Windows, iCloud for Windows 7.7. | CVSS3: 6.1 | 1% Низкий | около 4 лет назад | |
GHSA-2m6p-rg3r-28gh The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21, when the Revision 1179239 patch is in place, does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a malformed URI containing an @ (at sign) character and a : (colon) character in invalid positions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-3368. | 60% Средний | около 4 лет назад | ||
GHSA-2m6p-hm3w-6jm3 HAX CMS: Stored XSS via '<video-player>' component allows arbitrary JavaScript execution and token theft | 0% Низкий | 3 месяца назад | ||
GHSA-2m6m-r8c9-84hh In the Linux kernel, the following vulnerability has been resolved: RDMA: During rereg_mr ensure that REREG_ACCESS is compatible If IB_MR_REREG_ACCESS changes from RO to RW then the umem has to be re-evaluated to ensure it is properly pinned as RW. Since the umem is hidden inside each driver's mr struct add a ib_umem_check_rereg() function that each driver has to call before processing IB_MR_REREG_ACCESS. mlx4 has to retain its duplicate ib_access_writable check because it implements IB_MR_REREG_ACCESS | IB_MR_REREG_TRANS by changing both items in place sequentially while the MR is live, so it will continue to not support this combination. | CVSS3: 7.8 | 0% Низкий | около 2 месяцев назад | |
GHSA-2m6m-p8vh-r2f9 In Docker Notary before 0.1, the checkRoot function in gotuf/client/client.go does not check expiry of root.json files, despite a comment stating that it does. Even if a user creates a new root.json file after a key compromise, an attacker can produce update files referring to an old root.json file. | CVSS3: 9.8 | 1% Низкий | около 4 лет назад | |
GHSA-2m6m-4m28-hxfc Windows SharePoint Services and SharePoint Team Services for Windows Server 2003 does not properly validate an HTTP redirection query, which allows remote attackers to inject arbitrary HTML and web script via a cross-site scripting (XSS) attack, or to spoof the web cache. | 20% Средний | больше 4 лет назад | ||
GHSA-2m6j-m8rm-273p Cross-site scripting (XSS) vulnerability in apps/app_comment/form_comment.php in Fiyo CMS 1.5.7 allows remote attackers to inject arbitrary web script or HTML via the Nama field. | 2% Низкий | около 4 лет назад | ||
GHSA-2m6j-6wxg-cj77 Adobe Premiere Pro versions 22.0 (and earlier) and 15.4.2 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | CVSS3: 5.5 | 0% Низкий | почти 3 года назад | |
GHSA-2m6g-crv8-p3c6 Parse Server vulnerable to brute force guessing of user sensitive data via search patterns | CVSS3: 8.6 | 1% Низкий | почти 4 года назад | |
GHSA-2m6f-mg5g-38jv The Guile plugin for the Gnumeric spreadsheet package allows attackers to execute arbitrary code. | 0% Низкий | больше 4 лет назад | ||
GHSA-2m6f-fj9h-6vmp A Stored Cross-Site Scripting (XSS) Vulnerability in Chamilo LMS 1.11.26 allows a remote attacker to execute arbitrary JavaScript in a web browser by including a malicious payload in the 'content' parameter of 'group_topics.php'. | CVSS3: 6.1 | 0% Низкий | почти 2 года назад | |
GHSA-2m69-x28v-rwx9 cgi-bin/admin.cgi in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 does not require token authentication, which allows remote attackers to add administrative accounts via a userprefs action. | 44% Средний | около 4 лет назад | ||
GHSA-2m69-jmvh-6chr CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule | CVSS3: 5.4 | 0% Низкий | 3 месяца назад | |
GHSA-2m69-gcr7-jv3q SQLitePCLRaw.lib.e_sqlite3 has a vulnerable dependency on SQLite | CVSS3: 9.8 | 73% Высокий | около 1 года назад |
Уязвимостей на страницу