Количество 355 558
Количество 355 558
GHSA-2vjc-5wcf-g24v
Due to client-controlled permission check parameter, PAD CMS's photo upload functionality allows an unauthenticated remote attacker to upload files of any type and extension without restriction, which can then be executed leading to Remote Code Execution. This issue affects all 3 templates: www, bip and ww+bip. This product is End-Of-Life and producent will not publish patches for this vulnerability.
GHSA-2vj9-cx9q-8m6r
Stack-based buffer overflow in the RichFX component in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.4, and RealPlayer Enterprise 2.1.2 allows remote attackers to have an unspecified impact via unknown vectors.
GHSA-2vj9-882j-v7fm
Windows Cryptographic Primitives Library Information Disclosure Vulnerability
GHSA-2vj8-5447-hhff
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in moveaddons Move Addons for Elementor allows Stored XSS.This issue affects Move Addons for Elementor: from n/a through 1.3.3.
GHSA-2vj7-qv54-wqmr
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local user with specialized access to obtain sensitive information from a detailed technical error message. This information could be used in further attacks against the system. IBM X-Force ID: 185370.
GHSA-2vj7-37qg-hm7q
The vulnerability allows an authenticated remote attacker to download arbitrary files in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request.
GHSA-2vj6-wmm6-q722
In the Linux kernel, the following vulnerability has been resolved: smb: client: let recv_done verify data_offset, data_length and remaining_data_length This is inspired by the related server fixes.
GHSA-2vj6-p9c5-8h3v
main/translate.c in Sangoma Asterisk 13.28.0 and 16.5.0 allows a remote attacker to send a specific RTP packet during a call and cause a crash in a specific scenario.
GHSA-2vj6-mvxm-4f5f
The _gnutls_ciphertext2compressed function in lib/gnutls_cipher.c in GnuTLS 2.12.23 allows remote attackers to cause a denial of service (buffer over-read and crash) via a crafted padding length. NOTE: this might be due to an incorrect fix for CVE-2013-0169.
GHSA-2vj5-r237-wrxw
Out-of-bounds read in applying binary of voice content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory.
GHSA-2vj5-px25-gjrp
pytorch-lightning is vulnerable to Deserialization of Untrusted Data
GHSA-2vj5-ff34-px52
Unauthenticated Cross Site Scripting (XSS) in MagOne <= 9.0 versions.
GHSA-2vj5-chrh-vh25
A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_uploadify.php. Performing a manipulation of the argument Filedata[] results in unrestricted upload. The attack is possible to be carried out remotely. The exploit is now public and may be used.
GHSA-2vj4-mfcc-xffc
MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 uses the thumbnail ImageMagick command line argument, which allows remote attackers to obtain the installation path by reading the metadata of a PNG thumbnail file.
GHSA-2vj4-82m3-c6h5
Buffer overflow in efax 0.9 and earlier, when installed setuid root, allows local users to execute arbitrary code via a long -x argument.
GHSA-2vj3-wf4c-q7hg
In Gxlcms QY v1.0.0713, Lib\Lib\Action\Admin\DataAction.class.php allows remote attackers to delete any file via directory traversal sequences in the id parameter of an Admin-Data-del request.
GHSA-2vj3-75qw-x4pm
SQL injection vulnerability in pblguestbook.php in Pixelated By Lev (PBL) Guestbook 1.32 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) name, (2) email, (3) website, (4) comments, (5) rate, and (6) private parameters.
GHSA-2vhx-gg9g-r3h4
The official drupal docker images before 8.5.10-fpm-alpine (Alpine specific) contain a blank password for a root user. System using the drupal docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password.
GHSA-2vhx-cw73-6rc9
Buffer overflow in HECI subsystem in Intel(R) CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 and Intel(R) TXE version before 3.1.60 or 4.0.10, or Intel(R) Server Platform Services before version 5.00.04.012 may allow an unauthenticated user to potentially execute arbitrary code via physical access.
GHSA-2vhw-q7vh-7xv2
openssl-encrypt's readiness endpoint leaks database error details to unauthenticated callers
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2vjc-5wcf-g24v Due to client-controlled permission check parameter, PAD CMS's photo upload functionality allows an unauthenticated remote attacker to upload files of any type and extension without restriction, which can then be executed leading to Remote Code Execution. This issue affects all 3 templates: www, bip and ww+bip. This product is End-Of-Life and producent will not publish patches for this vulnerability. | CVSS3: 9.8 | 1% Низкий | 10 месяцев назад | |
GHSA-2vj9-cx9q-8m6r Stack-based buffer overflow in the RichFX component in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.4, and RealPlayer Enterprise 2.1.2 allows remote attackers to have an unspecified impact via unknown vectors. | 3% Низкий | около 4 лет назад | ||
GHSA-2vj9-882j-v7fm Windows Cryptographic Primitives Library Information Disclosure Vulnerability | CVSS3: 5.5 | 1% Низкий | около 4 лет назад | |
GHSA-2vj8-5447-hhff Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in moveaddons Move Addons for Elementor allows Stored XSS.This issue affects Move Addons for Elementor: from n/a through 1.3.3. | CVSS3: 6.5 | 0% Низкий | почти 2 года назад | |
GHSA-2vj7-qv54-wqmr IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a local user with specialized access to obtain sensitive information from a detailed technical error message. This information could be used in further attacks against the system. IBM X-Force ID: 185370. | 0% Низкий | около 4 лет назад | ||
GHSA-2vj7-37qg-hm7q The vulnerability allows an authenticated remote attacker to download arbitrary files in all paths of the system under the context of the application OS user (“root”) via a crafted HTTP request. | CVSS3: 6.5 | 1% Низкий | больше 2 лет назад | |
GHSA-2vj6-wmm6-q722 In the Linux kernel, the following vulnerability has been resolved: smb: client: let recv_done verify data_offset, data_length and remaining_data_length This is inspired by the related server fixes. | CVSS3: 5.5 | 0% Низкий | 10 месяцев назад | |
GHSA-2vj6-p9c5-8h3v main/translate.c in Sangoma Asterisk 13.28.0 and 16.5.0 allows a remote attacker to send a specific RTP packet during a call and cause a crash in a specific scenario. | CVSS3: 7.5 | 22% Средний | около 4 лет назад | |
GHSA-2vj6-mvxm-4f5f The _gnutls_ciphertext2compressed function in lib/gnutls_cipher.c in GnuTLS 2.12.23 allows remote attackers to cause a denial of service (buffer over-read and crash) via a crafted padding length. NOTE: this might be due to an incorrect fix for CVE-2013-0169. | 4% Низкий | около 4 лет назад | ||
GHSA-2vj5-r237-wrxw Out-of-bounds read in applying binary of voice content in Samsung Notes prior to version 4.4.26.71 allows attackers to read out-of-bounds memory. | CVSS3: 5.5 | 0% Низкий | больше 1 года назад | |
GHSA-2vj5-px25-gjrp pytorch-lightning is vulnerable to Deserialization of Untrusted Data | CVSS3: 7.8 | 1% Низкий | больше 4 лет назад | |
GHSA-2vj5-ff34-px52 Unauthenticated Cross Site Scripting (XSS) in MagOne <= 9.0 versions. | CVSS3: 7.1 | 0% Низкий | около 2 месяцев назад | |
GHSA-2vj5-chrh-vh25 A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_uploadify.php. Performing a manipulation of the argument Filedata[] results in unrestricted upload. The attack is possible to be carried out remotely. The exploit is now public and may be used. | CVSS3: 7.3 | 1% Низкий | 19 дней назад | |
GHSA-2vj4-mfcc-xffc MediaWiki before 1.23.11, 1.24.x before 1.24.4, and 1.25.x before 1.25.3 uses the thumbnail ImageMagick command line argument, which allows remote attackers to obtain the installation path by reading the metadata of a PNG thumbnail file. | 1% Низкий | около 4 лет назад | ||
GHSA-2vj4-82m3-c6h5 Buffer overflow in efax 0.9 and earlier, when installed setuid root, allows local users to execute arbitrary code via a long -x argument. | 0% Низкий | больше 4 лет назад | ||
GHSA-2vj3-wf4c-q7hg In Gxlcms QY v1.0.0713, Lib\Lib\Action\Admin\DataAction.class.php allows remote attackers to delete any file via directory traversal sequences in the id parameter of an Admin-Data-del request. | CVSS3: 7.5 | 2% Низкий | около 4 лет назад | |
GHSA-2vj3-75qw-x4pm SQL injection vulnerability in pblguestbook.php in Pixelated By Lev (PBL) Guestbook 1.32 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) name, (2) email, (3) website, (4) comments, (5) rate, and (6) private parameters. | 1% Низкий | больше 4 лет назад | ||
GHSA-2vhx-gg9g-r3h4 The official drupal docker images before 8.5.10-fpm-alpine (Alpine specific) contain a blank password for a root user. System using the drupal docker container deployed by affected versions of the docker image may allow a remote attacker to achieve root access with a blank password. | 5% Низкий | около 4 лет назад | ||
GHSA-2vhx-cw73-6rc9 Buffer overflow in HECI subsystem in Intel(R) CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 and Intel(R) TXE version before 3.1.60 or 4.0.10, or Intel(R) Server Platform Services before version 5.00.04.012 may allow an unauthenticated user to potentially execute arbitrary code via physical access. | CVSS3: 7.6 | 1% Низкий | около 4 лет назад | |
GHSA-2vhw-q7vh-7xv2 openssl-encrypt's readiness endpoint leaks database error details to unauthenticated callers | 4 месяца назад |
Уязвимостей на страницу