Количество 355 558
Количество 355 558
GHSA-2vw7-9m84-rphf
Multiple buffer overflows in squidGuard 1.4 allow remote attackers to bypass intended URL blocking via a long URL, related to (1) the relationship between a certain buffer size in squidGuard and a certain buffer size in Squid and (2) a redirect URL that contains information about the originally requested URL.
GHSA-2vw7-5jhc-pc89
Authenticated SQL Injection (SQLi) vulnerability in Mufeng's Hermit ????? plugin <= 3.1.6 on WordPress allows attackers with Subscriber or higher user roles to execute SQLi attack via (&ids).
GHSA-2vw6-vp5j-cgp9
finger .@host on some systems may print information on some user accounts.
GHSA-2vw6-5f85-h22m
Reference to Expired Domain Vulnerability in OpenText™ ArcSight Enterprise Security Manager.
GHSA-2vw5-mf9h-8p68
A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setVpnPassCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument pptpPassThru leads to os command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.
GHSA-2vw5-8fhm-cvqc
TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a stack overflow in the Form_Login function. This vulnerability allows attackers to cause a Denial of Service (DoS) via the flag parameter.
GHSA-2vw5-8crq-9vmf
The ext4_isize function in fs/ext4/ext4.h in the Linux kernel 2.6.27 before 2.6.27.19 and 2.6.28 before 2.6.28.7 uses the i_size_high structure member during operations on arbitrary types of files, which allows local users to cause a denial of service (CPU consumption and error-message flood) by attempting to mount a crafted ext4 filesystem.
GHSA-2vw4-j4g8-m4r4
Multiple cross-site scripting (XSS) vulnerabilities in index.php in NC LinkList 1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) cat and (2) view parameters.
GHSA-2vw3-r555-jwcc
Unauthenticated denial of service
GHSA-2vw3-5xf5-vwq6
A security flaw has been discovered in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /treatment.php. Performing a manipulation of the argument editid results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.
GHSA-2vw3-5r88-9c5p
A TOCTOU (Time-Of-Check to Time-Of-Use) in the graphics interface may allow an attacker to load registers repeatedly creating a race condition potentially leading to a loss of integrity.
GHSA-2vw2-h5mp-gfhw
Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing framework.
GHSA-2vw2-587w-g9v6
Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API functions that allows attackers to upload and execute arbitrary code.
GHSA-2vvx-6336-xm8p
A weakness has been identified in CodeAstro Gym Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/equipment-entry.php. Executing manipulation of the argument ename can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be exploited.
GHSA-2vvx-5g27-9gvj
The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.10 stores sensitive LDAP logs in a buffer file when an administrator wants to export said logs. Unfortunately, this log file is never removed, and remains accessible to any users knowing the URL to do so.
GHSA-2vvw-3422-x4g5
Stack-based buffer overflow in the VSFlexGrid.VSFlexGridL ActiveX control in ComponentOne VSFlexGrid 7.0.1.151 and 8.0.20072.239 allows remote attackers to execute arbitrary code via a long first argument to the Archive method. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
GHSA-2vvv-3xfp-234v
Improper access control in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature locally.
GHSA-2vvr-5757-qp87
Open redirect vulnerability in Jenkins CAS Plugin
GHSA-2vvq-r7r7-rh56
Multiple cross-site scripting (XSS) vulnerabilities in JBlog 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to (a) index.php, or the (2) search parameter or (3) theme cookie to (b) recherche.php.
GHSA-2vvq-mgpq-88xw
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2vw7-9m84-rphf Multiple buffer overflows in squidGuard 1.4 allow remote attackers to bypass intended URL blocking via a long URL, related to (1) the relationship between a certain buffer size in squidGuard and a certain buffer size in Squid and (2) a redirect URL that contains information about the originally requested URL. | 4% Низкий | больше 4 лет назад | ||
GHSA-2vw7-5jhc-pc89 Authenticated SQL Injection (SQLi) vulnerability in Mufeng's Hermit ????? plugin <= 3.1.6 on WordPress allows attackers with Subscriber or higher user roles to execute SQLi attack via (&ids). | CVSS3: 8.8 | 1% Низкий | больше 4 лет назад | |
GHSA-2vw6-vp5j-cgp9 finger .@host on some systems may print information on some user accounts. | 2% Низкий | больше 4 лет назад | ||
GHSA-2vw6-5f85-h22m Reference to Expired Domain Vulnerability in OpenText™ ArcSight Enterprise Security Manager. | 0% Низкий | больше 1 года назад | ||
GHSA-2vw5-mf9h-8p68 A vulnerability was identified in Totolink A7100RU 7.4cu.2313_b20191024. This affects the function setVpnPassCfg of the file /cgi-bin/cstecgi.cgi of the component CGI Handler. The manipulation of the argument pptpPassThru leads to os command injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. | CVSS3: 9.8 | 16% Средний | 4 месяца назад | |
GHSA-2vw5-8fhm-cvqc TOTOLINK A720R v4.1.5cu.470_B20200911 was discovered to contain a stack overflow in the Form_Login function. This vulnerability allows attackers to cause a Denial of Service (DoS) via the flag parameter. | CVSS3: 7.5 | 1% Низкий | больше 4 лет назад | |
GHSA-2vw5-8crq-9vmf The ext4_isize function in fs/ext4/ext4.h in the Linux kernel 2.6.27 before 2.6.27.19 and 2.6.28 before 2.6.28.7 uses the i_size_high structure member during operations on arbitrary types of files, which allows local users to cause a denial of service (CPU consumption and error-message flood) by attempting to mount a crafted ext4 filesystem. | 0% Низкий | больше 4 лет назад | ||
GHSA-2vw4-j4g8-m4r4 Multiple cross-site scripting (XSS) vulnerabilities in index.php in NC LinkList 1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) cat and (2) view parameters. | 1% Низкий | больше 4 лет назад | ||
GHSA-2vw3-r555-jwcc Unauthenticated denial of service | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | |
GHSA-2vw3-5xf5-vwq6 A security flaw has been discovered in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /treatment.php. Performing a manipulation of the argument editid results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. | CVSS3: 6.3 | 0% Низкий | 2 дня назад | |
GHSA-2vw3-5r88-9c5p A TOCTOU (Time-Of-Check to Time-Of-Use) in the graphics interface may allow an attacker to load registers repeatedly creating a race condition potentially leading to a loss of integrity. | 0% Низкий | 3 месяца назад | ||
GHSA-2vw2-h5mp-gfhw Multiple use-after-free vulnerabilities in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allow context-dependent attackers to cause a denial of service (application crash) via crafted (1) Notation or (2) Enumeration attribute types in an XML file, as demonstrated by the Codenomicon XML fuzzing framework. | CVSS3: 6.5 | 2% Низкий | больше 4 лет назад | |
GHSA-2vw2-587w-g9v6 Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API functions that allows attackers to upload and execute arbitrary code. | CVSS3: 8.8 | 6% Низкий | больше 4 лет назад | |
GHSA-2vvx-6336-xm8p A weakness has been identified in CodeAstro Gym Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/equipment-entry.php. Executing manipulation of the argument ename can lead to sql injection. It is possible to launch the attack remotely. The exploit has been made available to the public and could be exploited. | CVSS3: 6.3 | 0% Низкий | 10 месяцев назад | |
GHSA-2vvx-5g27-9gvj The Active Directory Integration / LDAP Integration WordPress plugin before 4.1.10 stores sensitive LDAP logs in a buffer file when an administrator wants to export said logs. Unfortunately, this log file is never removed, and remains accessible to any users knowing the URL to do so. | CVSS3: 7.5 | 26% Средний | почти 3 года назад | |
GHSA-2vvw-3422-x4g5 Stack-based buffer overflow in the VSFlexGrid.VSFlexGridL ActiveX control in ComponentOne VSFlexGrid 7.0.1.151 and 8.0.20072.239 allows remote attackers to execute arbitrary code via a long first argument to the Archive method. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 4% Низкий | больше 4 лет назад | ||
GHSA-2vvv-3xfp-234v Improper access control in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature locally. | CVSS3: 7.8 | 0% Низкий | 7 месяцев назад | |
GHSA-2vvr-5757-qp87 Open redirect vulnerability in Jenkins CAS Plugin | CVSS3: 6.1 | 2% Низкий | около 4 лет назад | |
GHSA-2vvq-r7r7-rh56 Multiple cross-site scripting (XSS) vulnerabilities in JBlog 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter to (a) index.php, or the (2) search parameter or (3) theme cookie to (b) recherche.php. | 3% Низкий | больше 4 лет назад | ||
GHSA-2vvq-mgpq-88xw Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | около 2 лет назад |
Уязвимостей на страницу