Количество 345 180
Количество 345 180
GHSA-273v-g3x4-r3rc
Improper Certificate Validation in vt-ldap
GHSA-273r-v888-vgc6
Magento Cross-site Scripting (XSS)
GHSA-273r-rm8g-7f3x
Uncaught Exception in mercurius
GHSA-273r-q5cp-p9c2
A memory leak was discovered in image_buffer_resize in fromsixel.c in libsixel 1.8.4.
GHSA-273r-mgr4-v34f
Uncaught Exception in engine.io
GHSA-273r-f986-fq9q
Stored cross-site scripting vulnerability exists in multiple versions of PowerCMS. If a product user accesses a malicious page, an arbitrary script may be executed on the browser.
GHSA-273r-585g-q7wv
The Slider by Soliloquy – Responsive Image Slider for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.1 via the map_meta_cap. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract draft slider metadata including unpublished media URLs, captions, and slider configuration authored by administrators or editors.
GHSA-273q-qgh5-wrj6
nebula-mesh's web UI lacks CSRF tokens on /ui/* mutating endpoints
GHSA-273p-w65h-573c
Several stack-based buffer overflow vulnerabilities exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.1. A specially crafted MFER file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger these vulnerabilities.When Tag is 67
GHSA-273p-m2cw-6833
Rekor's COSE v0.0.1 entry type nil pointer dereference in Canonicalize via empty Message
GHSA-273m-fmw2-8c3p
Multiple buffer overflows in Miranda before 0.7.1 allow remote attackers to execute arbitrary code via unspecified vectors involving (1) IRC options, (2) Jabber forms, and unspecified aspects of the (3) ICQ and (4) Yahoo! instant messaging functionality. NOTE: some of these details are obtained from third party information.
GHSA-273m-f252-4rf8
Sugar Suite Open Source (SugarCRM) 4.2 and earlier, when register_globals is enabled, does not protect critical variables such as $_GLOBALS and $_SESSION from modification, which allows remote attackers to conduct attacks such as directory traversal or PHP remote file inclusion, as demonstrated by modifying the GLOBALS[sugarEntry] parameter.
GHSA-273j-j8fx-2wqf
The Device Model in ACRN through 2.5 has a devicemodel/core/mem.c use-after-free for a freed rb_entry.
GHSA-273j-fjrx-gf2f
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Concurrency). Supported versions that are affected are Oracle Java SE: 8u401, 8u401-perf, 11.0.22; Oracle GraalVM Enterprise Edition: 20.3.13 and 21.3.9. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely...
GHSA-273j-3w9c-cwgw
Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the funcpara1 parameter in the formSetCfm function.
GHSA-273h-mfpf-cvq6
An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 850, Exynos 1080, Exynos 2100, Exynos 1280, Exynos 1380, Exynos 1330, Exynos W920, Exynos W930. The mobile processor lacks proper memory deallocation checking, which can result in a UAF (Use-After-Free) vulnerability.
GHSA-273h-m46v-96q4
ImageMagick: Integer Overflow in PSB (PSD v2) RLE decoding path causes heap Out of Bounds reads for 32-bit builds
GHSA-273h-gvwr-c3qj
CrowdSec LAPI: Denial of Service via Unbounded Gzip Decompression
GHSA-273h-28gx-8f5j
A format string issue in the Controller 6000's optional diagnostic web interface can be used to write/read from memory, and in some instances crash the Controller 6000 leading to a Denial of Service. This issue affects: Gallagher Controller 6000 8.60 prior to vCR8.60.231116a (distributed in 8.60.2550 (MR7)), all versions of 8.50 and prior.
GHSA-273g-rphj-ghmm
Heap-buffer overflow in the randomize_iparp function in edit_packet.c. of Tcpreplay v4.3.2 allows attackers to cause a denial of service (DOS) via a crafted pcap.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-273v-g3x4-r3rc Improper Certificate Validation in vt-ldap | CVSS3: 5.9 | 1% Низкий | около 4 лет назад | |
GHSA-273r-v888-vgc6 Magento Cross-site Scripting (XSS) | CVSS3: 6.1 | 1% Низкий | около 4 лет назад | |
GHSA-273r-rm8g-7f3x Uncaught Exception in mercurius | CVSS3: 7.5 | 2% Низкий | больше 4 лет назад | |
GHSA-273r-q5cp-p9c2 A memory leak was discovered in image_buffer_resize in fromsixel.c in libsixel 1.8.4. | CVSS3: 6.5 | 1% Низкий | около 4 лет назад | |
GHSA-273r-mgr4-v34f Uncaught Exception in engine.io | CVSS3: 7.5 | 3% Низкий | больше 4 лет назад | |
GHSA-273r-f986-fq9q Stored cross-site scripting vulnerability exists in multiple versions of PowerCMS. If a product user accesses a malicious page, an arbitrary script may be executed on the browser. | CVSS3: 5.4 | 0% Низкий | около 1 года назад | |
GHSA-273r-585g-q7wv The Slider by Soliloquy – Responsive Image Slider for WordPress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.1 via the map_meta_cap. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract draft slider metadata including unpublished media URLs, captions, and slider configuration authored by administrators or editors. | CVSS3: 4.3 | 0% Низкий | 3 месяца назад | |
GHSA-273q-qgh5-wrj6 nebula-mesh's web UI lacks CSRF tokens on /ui/* mutating endpoints | около 2 месяцев назад | |||
GHSA-273p-w65h-573c Several stack-based buffer overflow vulnerabilities exists in the MFER parsing functionality of The Biosig Project libbiosig 3.9.1. A specially crafted MFER file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger these vulnerabilities.When Tag is 67 | CVSS3: 9.8 | 0% Низкий | 8 месяцев назад | |
GHSA-273p-m2cw-6833 Rekor's COSE v0.0.1 entry type nil pointer dereference in Canonicalize via empty Message | CVSS3: 5.3 | 0% Низкий | 6 месяцев назад | |
GHSA-273m-fmw2-8c3p Multiple buffer overflows in Miranda before 0.7.1 allow remote attackers to execute arbitrary code via unspecified vectors involving (1) IRC options, (2) Jabber forms, and unspecified aspects of the (3) ICQ and (4) Yahoo! instant messaging functionality. NOTE: some of these details are obtained from third party information. | 4% Низкий | больше 4 лет назад | ||
GHSA-273m-f252-4rf8 Sugar Suite Open Source (SugarCRM) 4.2 and earlier, when register_globals is enabled, does not protect critical variables such as $_GLOBALS and $_SESSION from modification, which allows remote attackers to conduct attacks such as directory traversal or PHP remote file inclusion, as demonstrated by modifying the GLOBALS[sugarEntry] parameter. | 10% Средний | больше 4 лет назад | ||
GHSA-273j-j8fx-2wqf The Device Model in ACRN through 2.5 has a devicemodel/core/mem.c use-after-free for a freed rb_entry. | 1% Низкий | около 4 лет назад | ||
GHSA-273j-fjrx-gf2f Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Concurrency). Supported versions that are affected are Oracle Java SE: 8u401, 8u401-perf, 11.0.22; Oracle GraalVM Enterprise Edition: 20.3.13 and 21.3.9. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Java SE, Oracle GraalVM Enterprise Edition. Note: This vulnerability can be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. This vulnerability also applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely... | CVSS3: 3.7 | 1% Низкий | больше 2 лет назад | |
GHSA-273j-3w9c-cwgw Tenda i22 V1.0.0.3(4687) was discovered to contain a buffer overflow via the funcpara1 parameter in the formSetCfm function. | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | |
GHSA-273h-mfpf-cvq6 An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 850, Exynos 1080, Exynos 2100, Exynos 1280, Exynos 1380, Exynos 1330, Exynos W920, Exynos W930. The mobile processor lacks proper memory deallocation checking, which can result in a UAF (Use-After-Free) vulnerability. | CVSS3: 8.4 | 0% Низкий | около 2 лет назад | |
GHSA-273h-m46v-96q4 ImageMagick: Integer Overflow in PSB (PSD v2) RLE decoding path causes heap Out of Bounds reads for 32-bit builds | CVSS3: 3.7 | 5 месяцев назад | ||
GHSA-273h-gvwr-c3qj CrowdSec LAPI: Denial of Service via Unbounded Gzip Decompression | 2 месяца назад | |||
GHSA-273h-28gx-8f5j A format string issue in the Controller 6000's optional diagnostic web interface can be used to write/read from memory, and in some instances crash the Controller 6000 leading to a Denial of Service. This issue affects: Gallagher Controller 6000 8.60 prior to vCR8.60.231116a (distributed in 8.60.2550 (MR7)), all versions of 8.50 and prior. | CVSS3: 7.5 | 1% Низкий | больше 2 лет назад | |
GHSA-273g-rphj-ghmm Heap-buffer overflow in the randomize_iparp function in edit_packet.c. of Tcpreplay v4.3.2 allows attackers to cause a denial of service (DOS) via a crafted pcap. | CVSS3: 5.5 | 1% Низкий | около 4 лет назад |
Уязвимостей на страницу