Количество 375 268
Количество 375 268
GHSA-3rcq-39xp-7xjp
ic-stable-structures vulnerable to BTreeMap memory leak when deallocating nodes with overflows
GHSA-3rcp-jp25-8fmh
A vulnerability was identified in MediaCrush 1.0.0/1.0.1. The affected element is an unknown function of the file /mediacrush/paths.py of the component Header Handler. Such manipulation of the argument Host leads to improper neutralization of http headers for scripting syntax. The attack can be launched remotely.
GHSA-3rcm-vjrc-p45j
JustHTML has a Sanitizer Bypass (in Markdown)
GHSA-3rcm-mfq3-5m2c
PHP remote file inclusion vulnerability in lib/onguma.class.php in the Onguma Time Sheet (com_ongumatimesheet20) 2.0 4b component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
GHSA-3rcm-9xw5-hpx9
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability
GHSA-3rcm-5vqm-53w6
In the Linux kernel, the following vulnerability has been resolved: nfnetlink_osf: validate individual option lengths in fingerprints nfnl_osf_add_callback() validates opt_num bounds and string NUL-termination but does not check individual option length fields. A zero-length option causes nf_osf_match_one() to enter the option matching loop even when foptsize sums to zero, which matches packets with no TCP options where ctx->optp is NULL: Oops: general protection fault KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] RIP: 0010:nf_osf_match_one (net/netfilter/nfnetlink_osf.c:98) Call Trace: nf_osf_match (net/netfilter/nfnetlink_osf.c:227) xt_osf_match_packet (net/netfilter/xt_osf.c:32) ipt_do_table (net/ipv4/netfilter/ip_tables.c:293) nf_hook_slow (net/netfilter/core.c:623) ip_local_deliver (net/ipv4/ip_input.c:262) ip_rcv (net/ipv4/ip_input.c:573) Additionally, an MSS option (kind=2) with length < 4 causes out-of-bounds reads when nf_osf_mat...
GHSA-3rcm-33w6-82vp
baijiacms V3 has physical path leakage via an index.php?mod=mobile&name=member&do=index request.
GHSA-3rcg-gg9q-9688
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Struktur struktur allows PHP Local File Inclusion.This issue affects Struktur: from n/a through <= 2.5.1.
GHSA-3rcg-83x5-6r67
Memory corruption while processing a video session to set video parameters.
GHSA-3rcg-456g-86p6
In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in session logoff The sess->user object can currently be in use by another thread, for example if another connection has sent a session setup request to bind to the session being free'd. The handler for that connection could be in the smb2_sess_setup function which makes use of sess->user.
GHSA-3rcf-hxhh-73gh
Sendmail 8.6.9 allows remote attackers to execute root commands, using ident.
GHSA-3rcf-g93x-vh3q
Missing Authorization vulnerability in Jose Specific Content For Mobile allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Specific Content For Mobile: from n/a through 0.5.3.
GHSA-3rcc-385q-f2hc
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the getPageNthWordQuads method. By performing actions in JavaScript, an attacker can trigger a type confusion condition. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-6022.
GHSA-3rcc-2gfp-q4g4
PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the category.php chid1 parameter.
GHSA-3rc9-qgq4-2p4w
There is a local privilege escalation vulnerability in Alfredo Milani Comparetti SpeedFan 4.52. Attackers can use constructed programs to increase user privileges
GHSA-3rc9-h6hx-fvf7
** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
GHSA-3rc9-f2pv-xp95
After Effects versions 23.6.9, 24.6.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
GHSA-3rc9-46g7-hmvc
In modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed
GHSA-3rc8-xjj4-xjp5
OKI Configuration Tool 1.6.53 contains an unquoted service path vulnerability in the OKI Local Port Manager service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Okidata\Common\extend3\portmgrsrv.exe' to inject malicious executables and escalate privileges.
GHSA-3rc8-cff9-mc2h
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions that are affected are 10 and 11.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via NFS to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Solaris. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3rcq-39xp-7xjp ic-stable-structures vulnerable to BTreeMap memory leak when deallocating nodes with overflows | CVSS3: 5.9 | 1% Низкий | больше 2 лет назад | |
GHSA-3rcp-jp25-8fmh A vulnerability was identified in MediaCrush 1.0.0/1.0.1. The affected element is an unknown function of the file /mediacrush/paths.py of the component Header Handler. Such manipulation of the argument Host leads to improper neutralization of http headers for scripting syntax. The attack can be launched remotely. | CVSS3: 7.3 | 0% Низкий | 10 месяцев назад | |
GHSA-3rcm-vjrc-p45j JustHTML has a Sanitizer Bypass (in Markdown) | 6 месяцев назад | |||
GHSA-3rcm-mfq3-5m2c PHP remote file inclusion vulnerability in lib/onguma.class.php in the Onguma Time Sheet (com_ongumatimesheet20) 2.0 4b component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | 20% Средний | больше 4 лет назад | ||
GHSA-3rcm-9xw5-hpx9 Microsoft Edge (Chromium-based) Information Disclosure Vulnerability | CVSS3: 8.2 | 2% Низкий | больше 2 лет назад | |
GHSA-3rcm-5vqm-53w6 In the Linux kernel, the following vulnerability has been resolved: nfnetlink_osf: validate individual option lengths in fingerprints nfnl_osf_add_callback() validates opt_num bounds and string NUL-termination but does not check individual option length fields. A zero-length option causes nf_osf_match_one() to enter the option matching loop even when foptsize sums to zero, which matches packets with no TCP options where ctx->optp is NULL: Oops: general protection fault KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] RIP: 0010:nf_osf_match_one (net/netfilter/nfnetlink_osf.c:98) Call Trace: nf_osf_match (net/netfilter/nfnetlink_osf.c:227) xt_osf_match_packet (net/netfilter/xt_osf.c:32) ipt_do_table (net/ipv4/netfilter/ip_tables.c:293) nf_hook_slow (net/netfilter/core.c:623) ip_local_deliver (net/ipv4/ip_input.c:262) ip_rcv (net/ipv4/ip_input.c:573) Additionally, an MSS option (kind=2) with length < 4 causes out-of-bounds reads when nf_osf_mat... | CVSS3: 7.1 | 0% Низкий | 6 месяцев назад | |
GHSA-3rcm-33w6-82vp baijiacms V3 has physical path leakage via an index.php?mod=mobile&name=member&do=index request. | CVSS3: 5.3 | 1% Низкий | больше 4 лет назад | |
GHSA-3rcg-gg9q-9688 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Struktur struktur allows PHP Local File Inclusion.This issue affects Struktur: from n/a through <= 2.5.1. | CVSS3: 8.1 | 1% Низкий | 7 месяцев назад | |
GHSA-3rcg-83x5-6r67 Memory corruption while processing a video session to set video parameters. | CVSS3: 7.8 | 0% Низкий | 9 месяцев назад | |
GHSA-3rcg-456g-86p6 In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix use-after-free in session logoff The sess->user object can currently be in use by another thread, for example if another connection has sent a session setup request to bind to the session being free'd. The handler for that connection could be in the smb2_sess_setup function which makes use of sess->user. | CVSS3: 7.8 | 1% Низкий | больше 1 года назад | |
GHSA-3rcf-hxhh-73gh Sendmail 8.6.9 allows remote attackers to execute root commands, using ident. | 9% Низкий | больше 4 лет назад | ||
GHSA-3rcf-g93x-vh3q Missing Authorization vulnerability in Jose Specific Content For Mobile allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Specific Content For Mobile: from n/a through 0.5.3. | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
GHSA-3rcc-385q-f2hc This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the getPageNthWordQuads method. By performing actions in JavaScript, an attacker can trigger a type confusion condition. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-6022. | CVSS3: 8.8 | 3% Низкий | больше 4 лет назад | |
GHSA-3rcc-2gfp-q4g4 PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the category.php chid1 parameter. | CVSS3: 6.1 | 1% Низкий | больше 4 лет назад | |
GHSA-3rc9-qgq4-2p4w There is a local privilege escalation vulnerability in Alfredo Milani Comparetti SpeedFan 4.52. Attackers can use constructed programs to increase user privileges | 0% Низкий | больше 4 лет назад | ||
GHSA-3rc9-h6hx-fvf7 ** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. | CVSS3: 7.5 | 1% Низкий | около 2 месяцев назад | |
GHSA-3rc9-f2pv-xp95 After Effects versions 23.6.9, 24.6.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | CVSS3: 7.8 | 0% Низкий | почти 2 года назад | |
GHSA-3rc9-46g7-hmvc In modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed | CVSS3: 7.5 | 0% Низкий | 10 месяцев назад | |
GHSA-3rc8-xjj4-xjp5 OKI Configuration Tool 1.6.53 contains an unquoted service path vulnerability in the OKI Local Port Manager service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in 'C:\Program Files\Okidata\Common\extend3\portmgrsrv.exe' to inject malicious executables and escalate privileges. | CVSS3: 7.8 | 0% Низкий | 8 месяцев назад | |
GHSA-3rc8-cff9-mc2h Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). Supported versions that are affected are 10 and 11.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via NFS to compromise Solaris. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Solaris. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). | CVSS3: 7.5 | 3% Низкий | больше 4 лет назад |
Уязвимостей на страницу