Количество 354 500
Количество 354 500
GHSA-2qq2-jxgg-2w76
Improper restriction of operations within the bounds of a memory buffer in PCIe® Link could allow an attacker with access to a guest virtual machine to potentially perform a denial of service attack against the host resulting in loss of availability.
GHSA-2qq2-3mq9-pfmj
The dbclient in Dropbear SSH before 2016.74 allows remote attackers to execute arbitrary code via a crafted (1) -m or (2) -c argument.
GHSA-2qpx-8vpw-42x9
An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. An attacker could traverse the file system and extract files that can result in information disclosure.
GHSA-2qpw-jpx2-w9hr
The Find and Replace All WordPress plugin before 1.3 does not have CSRF check when replacing string, which could allow attackers to make a logged admin replace arbitrary string in database tables via a CSRF attack
GHSA-2qpw-f425-8j85
Multiple SQL injection vulnerabilities in eTicket 1.5.7 allow remote attackers to execute arbitrary SQL commands via the pri parameter to (1) index.php, (2) open.php, (3) open_raw.php, and (4) newticket.php.
GHSA-2qpw-94pp-r3cv
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Vathemes Business Pro theme <= 1.10.4 versions.
GHSA-2qpv-6w5r-q697
Multiple cross-site scripting (XSS) vulnerabilities in the image map feature in JFreeChart 1.0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) chart name or (2) chart tool tip text; or the (3) href, (4) shape, or (5) coords attribute of a chart area.
GHSA-2qpr-jh9p-xf8p
Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally.
GHSA-2qpq-x4m7-gjf3
Weak encoding for password vulnerability exists in HMI ViewJet C-more series. If this vulnerability is exploited, authentication information may be obtained by a local authenticated attacker.
GHSA-2qpq-rm7r-m2pp
In LibSass 3.4.5, there is a heap-based buffer over-read in the function json_mkstream() in sass_context.cpp. A crafted input will lead to a remote denial of service attack.
GHSA-2qpq-mrrj-2hc9
The Connectables feature in Adobe PhotoDeluxe 3.1 prepends the Adobe directory to the CLASSPATH environment variable, which allows applets to run with higher privileges and remote attackers to gain privileges via an HTML e-mail message or a web page.
GHSA-2qpq-5447-wmrc
The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/report-search.php by adding a question mark (?) followed by the payload.
GHSA-2qpp-9v9c-5979
A vulnerability has been found in Dahua products. Attackers could exploit a buffer overflow vulnerability by sending specially crafted malicious packets, potentially causing service disruption (e.g., crashes) or remote code execution (RCE). Some devices may have deployed protection mechanisms such as Address Space Layout Randomization (ASLR), which reduces the likelihood of successful RCE exploitation. However, denial-of-service (DoS) attacks remain a concern.
GHSA-2qpp-8m4h-3vg9
The Auto-Scaling agent in Liberty for Java in IBM Bluemix before 2.7-20160321-1358 allows remote authenticated users to disable X.509 certificate validation, and consequently bypass an intended HTTPS trust-management feature, via unspecified vectors.
GHSA-2qpm-xf67-jj26
Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via superuser writing password to unprotected temporary file.
GHSA-2qpj-g893-v358
SQL injection vulnerability in news.php in Ero Auktion 2.0 and 2010 allows remote attackers to execute arbitrary SQL commands via the id parameter.
GHSA-2qph-v9p2-q2gv
Apache StreamPipes potentially allows creation of multiple identical accounts
GHSA-2qph-qpvm-2qf7
tls-listener affected by the slow loris vulnerability with default configuration
GHSA-2qph-q8xw-gv7q
Drupal Core Improperly Controlled Modification of Dynamically-Determined Object Attributes Vulnerability
GHSA-2qph-mf22-rc4p
Multiple cross-site scripting (XSS) vulnerabilities in Coursemill Learning Management System (LMS) 6.8 allow remote attackers to inject arbitrary web script or HTML via vectors related to error messages and (1) crafted event attributes or (2) > (greater than) characters that are optional within a browser's HTML implementation, a different issue than CVE-2013-3603.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2qq2-jxgg-2w76 Improper restriction of operations within the bounds of a memory buffer in PCIe® Link could allow an attacker with access to a guest virtual machine to potentially perform a denial of service attack against the host resulting in loss of availability. | 0% Низкий | 6 месяцев назад | ||
GHSA-2qq2-3mq9-pfmj The dbclient in Dropbear SSH before 2016.74 allows remote attackers to execute arbitrary code via a crafted (1) -m or (2) -c argument. | CVSS3: 8.8 | 4% Низкий | около 4 лет назад | |
GHSA-2qpx-8vpw-42x9 An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. An attacker could traverse the file system and extract files that can result in information disclosure. | CVSS3: 7.5 | 8% Низкий | около 4 лет назад | |
GHSA-2qpw-jpx2-w9hr The Find and Replace All WordPress plugin before 1.3 does not have CSRF check when replacing string, which could allow attackers to make a logged admin replace arbitrary string in database tables via a CSRF attack | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад | |
GHSA-2qpw-f425-8j85 Multiple SQL injection vulnerabilities in eTicket 1.5.7 allow remote attackers to execute arbitrary SQL commands via the pri parameter to (1) index.php, (2) open.php, (3) open_raw.php, and (4) newticket.php. | 1% Низкий | около 4 лет назад | ||
GHSA-2qpw-94pp-r3cv Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Vathemes Business Pro theme <= 1.10.4 versions. | CVSS3: 7.1 | 0% Низкий | почти 3 года назад | |
GHSA-2qpv-6w5r-q697 Multiple cross-site scripting (XSS) vulnerabilities in the image map feature in JFreeChart 1.0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) chart name or (2) chart tool tip text; or the (3) href, (4) shape, or (5) coords attribute of a chart area. | 3% Низкий | больше 4 лет назад | ||
GHSA-2qpr-jh9p-xf8p Out-of-bounds read in Windows Storage Management Provider allows an authorized attacker to disclose information locally. | CVSS3: 5.5 | 1% Низкий | около 1 года назад | |
GHSA-2qpq-x4m7-gjf3 Weak encoding for password vulnerability exists in HMI ViewJet C-more series. If this vulnerability is exploited, authentication information may be obtained by a local authenticated attacker. | CVSS3: 6.5 | 0% Низкий | больше 1 года назад | |
GHSA-2qpq-rm7r-m2pp In LibSass 3.4.5, there is a heap-based buffer over-read in the function json_mkstream() in sass_context.cpp. A crafted input will lead to a remote denial of service attack. | CVSS3: 7.5 | 2% Низкий | около 4 лет назад | |
GHSA-2qpq-mrrj-2hc9 The Connectables feature in Adobe PhotoDeluxe 3.1 prepends the Adobe directory to the CLASSPATH environment variable, which allows applets to run with higher privileges and remote attackers to gain privileges via an HTML e-mail message or a web page. | 2% Низкий | больше 4 лет назад | ||
GHSA-2qpq-5447-wmrc The way URIs are handled in admin/header.php in Chadha PHPKB Standard Multi-Language 9 allows Reflected XSS (injecting arbitrary web script or HTML) in admin/report-search.php by adding a question mark (?) followed by the payload. | CVSS3: 4.8 | 1% Низкий | около 4 лет назад | |
GHSA-2qpp-9v9c-5979 A vulnerability has been found in Dahua products. Attackers could exploit a buffer overflow vulnerability by sending specially crafted malicious packets, potentially causing service disruption (e.g., crashes) or remote code execution (RCE). Some devices may have deployed protection mechanisms such as Address Space Layout Randomization (ASLR), which reduces the likelihood of successful RCE exploitation. However, denial-of-service (DoS) attacks remain a concern. | CVSS3: 8.1 | 1% Низкий | около 1 года назад | |
GHSA-2qpp-8m4h-3vg9 The Auto-Scaling agent in Liberty for Java in IBM Bluemix before 2.7-20160321-1358 allows remote authenticated users to disable X.509 certificate validation, and consequently bypass an intended HTTPS trust-management feature, via unspecified vectors. | CVSS3: 6.5 | 1% Низкий | около 4 лет назад | |
GHSA-2qpm-xf67-jj26 Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via superuser writing password to unprotected temporary file. | CVSS3: 7 | 0% Низкий | около 4 лет назад | |
GHSA-2qpj-g893-v358 SQL injection vulnerability in news.php in Ero Auktion 2.0 and 2010 allows remote attackers to execute arbitrary SQL commands via the id parameter. | 2% Низкий | больше 4 лет назад | ||
GHSA-2qph-v9p2-q2gv Apache StreamPipes potentially allows creation of multiple identical accounts | CVSS3: 3.7 | 1% Низкий | около 2 лет назад | |
GHSA-2qph-qpvm-2qf7 tls-listener affected by the slow loris vulnerability with default configuration | CVSS3: 7.5 | 1% Низкий | больше 2 лет назад | |
GHSA-2qph-q8xw-gv7q Drupal Core Improperly Controlled Modification of Dynamically-Determined Object Attributes Vulnerability | 1% Низкий | больше 1 года назад | ||
GHSA-2qph-mf22-rc4p Multiple cross-site scripting (XSS) vulnerabilities in Coursemill Learning Management System (LMS) 6.8 allow remote attackers to inject arbitrary web script or HTML via vectors related to error messages and (1) crafted event attributes or (2) > (greater than) characters that are optional within a browser's HTML implementation, a different issue than CVE-2013-3603. | 1% Низкий | около 4 лет назад |
Уязвимостей на страницу