Количество 354 225
Количество 354 225
GHSA-2pm8-xgpx-w63v
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HireHive HireHive Job Plugin allows Stored XSS.This issue affects HireHive Job Plugin: from n/a through 2.9.0.
GHSA-2pm8-794w-p8m4
Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
GHSA-2pm7-wcx5-9h5j
Cross-site scripting (XSS) vulnerability in MyWebSQL 3.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the table parameter to index.php.
GHSA-2pm7-q8pc-xhvq
MantisBT HTML Injection vulnerability
GHSA-2pm7-3m95-7x49
Repetier Server through 1.4.10 does not have CSRF protection.
GHSA-2pm6-rcw9-992f
UTT Aggressive HiPER 810G v3v1.7.7-171114 was discovered to contain a buffer overflow in the selDateType parameter of the formTaskEdit function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.
GHSA-2pm6-hr95-ggxq
A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3.3). Affected SIMATIC RTLS Locating Manager Report Clients do not properly protect credentials that are used to authenticate to the server. This could allow an authenticated local attacker to extract the credentials and use them to escalate their access rights from the Manager to the Systemadministrator role.
GHSA-2pm6-9fhx-vvg3
The mailqueue TYPO3 extension has Insecure Deserialization in `TransportFailure` class
GHSA-2pm5-r39v-pr4r
SQL injection vulnerability in the Novalnet Payment Module Ubercart module for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
GHSA-2pm5-h4rp-cjq3
The original patch for CVE-2007-3999 in svc_auth_gss.c in the RPCSEC_GSS RPC library in MIT Kerberos 5 (krb5) 1.4 through 1.6.2, as used by the Kerberos administration daemon (kadmind) and other applications that use krb5, does not correctly check the buffer length in some environments and architectures, which might allow remote attackers to conduct a buffer overflow attack.
GHSA-2pm5-c2hr-7xg4
Remote Desktop Protocol Remote Code Execution Vulnerability.
GHSA-2pm5-4pq3-87vj
Missing Authorization vulnerability in Israpil Textmetrics allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Textmetrics: from n/a through 3.6.1.
GHSA-2pm4-86cq-h56g
ActivePresenter 6.1.6 is affected by a memory corruption vulnerability that may result in a denial of service (DoS) or arbitrary code execution.
GHSA-2pm2-v5jq-cp26
cgi-bin/makecgi-pro in Iomega StorCenter Pro generates predictable session IDs, which allows remote attackers to hijack active sessions and gain privileges via brute force guessing attacks on the session_id parameter.
GHSA-2pm2-h49w-3rj5
An improper privilege management vulnerability was identified in GitHub Enterprise Server that allowed users with improper privileges to create or delete pages via the API. To exploit this vulnerability, an attacker would need to be added to an organization's repo with write permissions. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.7 and was fixed in versions 3.2.20, 3.3.15, 3.4.10, 3.5.7, and 3.6.3. This vulnerability was reported via the GitHub Bug Bounty program.
GHSA-2pm2-cpjx-462g
Webedition CMS 9.2.2.0 has a Stored XSS vulnerability via /webEdition/we_cmd.php.
GHSA-2pm2-9wvh-w2w9
In pmucal_rae_handle_seq_int of flexpmu_cal_rae.c, there is a possible arbitrary write due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
GHSA-2pjx-wvcg-vhr8
7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of archived files. When extracting files from a crafted archive that bears the Mark-of-the-Web, 7-Zip does not propagate the Mark-of-the-Web to the extracted files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user. Was ZDI-CAN-25456.
GHSA-2pjx-v75h-827m
An improper implementation of the new iframe sandbox keyword <code>allow-top-navigation-by-user-activation</code> could lead to script execution without <code>allow-scripts</code> being present. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100.
GHSA-2pjx-m5vr-xg6f
Multiple integer overflows in the (1) dodecrypt and (2) doencrypt functions in cfs_fh.c in cfsd in Matt Blaze Cryptographic File System (CFS) 1.4.1 before Debian GNU/Linux package 1.4.1-17 allow local users to cause a denial of service (daemon crash) by appending data to a file that is larger than 2 Gb.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2pm8-xgpx-w63v Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HireHive HireHive Job Plugin allows Stored XSS.This issue affects HireHive Job Plugin: from n/a through 2.9.0. | CVSS3: 6.5 | 0% Низкий | больше 1 года назад | |
GHSA-2pm8-794w-p8m4 Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical) | CVSS3: 8.3 | 0% Низкий | 2 месяца назад | |
GHSA-2pm7-wcx5-9h5j Cross-site scripting (XSS) vulnerability in MyWebSQL 3.4 and earlier allows remote attackers to inject arbitrary web script or HTML via the table parameter to index.php. | 2% Низкий | около 4 лет назад | ||
GHSA-2pm7-q8pc-xhvq MantisBT HTML Injection vulnerability | CVSS3: 4.8 | 2% Низкий | около 4 лет назад | |
GHSA-2pm7-3m95-7x49 Repetier Server through 1.4.10 does not have CSRF protection. | CVSS3: 8.8 | 0% Низкий | больше 3 лет назад | |
GHSA-2pm6-rcw9-992f UTT Aggressive HiPER 810G v3v1.7.7-171114 was discovered to contain a buffer overflow in the selDateType parameter of the formTaskEdit function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input. | CVSS3: 4.5 | 0% Низкий | 4 месяца назад | |
GHSA-2pm6-hr95-ggxq A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3.3). Affected SIMATIC RTLS Locating Manager Report Clients do not properly protect credentials that are used to authenticate to the server. This could allow an authenticated local attacker to extract the credentials and use them to escalate their access rights from the Manager to the Systemadministrator role. | CVSS3: 6.3 | 0% Низкий | 12 месяцев назад | |
GHSA-2pm6-9fhx-vvg3 The mailqueue TYPO3 extension has Insecure Deserialization in `TransportFailure` class | CVSS3: 8.8 | 0% Низкий | 5 месяцев назад | |
GHSA-2pm5-r39v-pr4r SQL injection vulnerability in the Novalnet Payment Module Ubercart module for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | 2% Низкий | около 4 лет назад | ||
GHSA-2pm5-h4rp-cjq3 The original patch for CVE-2007-3999 in svc_auth_gss.c in the RPCSEC_GSS RPC library in MIT Kerberos 5 (krb5) 1.4 through 1.6.2, as used by the Kerberos administration daemon (kadmind) and other applications that use krb5, does not correctly check the buffer length in some environments and architectures, which might allow remote attackers to conduct a buffer overflow attack. | 5% Низкий | больше 4 лет назад | ||
GHSA-2pm5-c2hr-7xg4 Remote Desktop Protocol Remote Code Execution Vulnerability. | CVSS3: 8 | 5% Низкий | больше 4 лет назад | |
GHSA-2pm5-4pq3-87vj Missing Authorization vulnerability in Israpil Textmetrics allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Textmetrics: from n/a through 3.6.1. | CVSS3: 5.4 | 0% Низкий | больше 1 года назад | |
GHSA-2pm4-86cq-h56g ActivePresenter 6.1.6 is affected by a memory corruption vulnerability that may result in a denial of service (DoS) or arbitrary code execution. | 4% Низкий | около 4 лет назад | ||
GHSA-2pm2-v5jq-cp26 cgi-bin/makecgi-pro in Iomega StorCenter Pro generates predictable session IDs, which allows remote attackers to hijack active sessions and gain privileges via brute force guessing attacks on the session_id parameter. | CVSS3: 9.8 | 23% Средний | больше 4 лет назад | |
GHSA-2pm2-h49w-3rj5 An improper privilege management vulnerability was identified in GitHub Enterprise Server that allowed users with improper privileges to create or delete pages via the API. To exploit this vulnerability, an attacker would need to be added to an organization's repo with write permissions. This vulnerability affected all versions of GitHub Enterprise Server prior to 3.7 and was fixed in versions 3.2.20, 3.3.15, 3.4.10, 3.5.7, and 3.6.3. This vulnerability was reported via the GitHub Bug Bounty program. | CVSS3: 6.5 | 1% Низкий | больше 3 лет назад | |
GHSA-2pm2-cpjx-462g Webedition CMS 9.2.2.0 has a Stored XSS vulnerability via /webEdition/we_cmd.php. | CVSS3: 6.3 | 0% Низкий | больше 2 лет назад | |
GHSA-2pm2-9wvh-w2w9 In pmucal_rae_handle_seq_int of flexpmu_cal_rae.c, there is a possible arbitrary write due to uninitialized data. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. | CVSS3: 7.8 | 0% Низкий | почти 2 года назад | |
GHSA-2pjx-wvcg-vhr8 7-Zip Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of 7-Zip. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of archived files. When extracting files from a crafted archive that bears the Mark-of-the-Web, 7-Zip does not propagate the Mark-of-the-Web to the extracted files. An attacker can leverage this vulnerability to execute arbitrary code in the context of the current user. Was ZDI-CAN-25456. | CVSS3: 7 | 67% Средний | больше 1 года назад | |
GHSA-2pjx-v75h-827m An improper implementation of the new iframe sandbox keyword <code>allow-top-navigation-by-user-activation</code> could lead to script execution without <code>allow-scripts</code> being present. This vulnerability affects Thunderbird < 91.9, Firefox ESR < 91.9, and Firefox < 100. | CVSS3: 6.1 | 1% Низкий | больше 3 лет назад | |
GHSA-2pjx-m5vr-xg6f Multiple integer overflows in the (1) dodecrypt and (2) doencrypt functions in cfs_fh.c in cfsd in Matt Blaze Cryptographic File System (CFS) 1.4.1 before Debian GNU/Linux package 1.4.1-17 allow local users to cause a denial of service (daemon crash) by appending data to a file that is larger than 2 Gb. | 0% Низкий | больше 4 лет назад |
Уязвимостей на страницу