Количество 353 883
Количество 353 883
GHSA-2m7q-4j9m-89vh
In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored value could lead to stored XSS/HTML/CSS injection on shared mailboxes.
GHSA-2m7p-qcqr-gfv2
The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr operations, which allows local users to bypass intended access restrictions and modify the attributes of arbitrary overlay files via a crafted application.
GHSA-2m7m-jhx5-8crh
IBM Aspera Orchestrator 4.0.1 could allow a remote attacker to enumerate usernames due to observable response discrepancies. IBM X-Force ID: 248545.
GHSA-2m7m-j3mq-9g6p
A vulnerability, which was classified as critical, has been found in gmg137 snap7-rs up to 1.142.1. Affected by this issue is the function pthread_cond_destroy of the component Public API. The manipulation leads to memory corruption. The exploit has been disclosed to the public and may be used.
GHSA-2m7m-3qp3-4h9x
IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190741.
GHSA-2m7j-prfm-384p
Buffer overflow in mah-jong 1.5.6 and earlier allows remote attackers to execute arbitrary code.
GHSA-2m7j-4ff8-h52q
Northern.tech Mender before 3.6.5 and 3.7.x before 3.7.5 has Incorrect Access Control.
GHSA-2m7h-86qq-fp4v
Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params
GHSA-2m7h-5m38-vhh4
The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'move_as_original_file' function in all versions up to, and including, 4.2.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
GHSA-2m7g-9q74-9m3q
Improper Certificate Validation in Apache Beam
GHSA-2m7g-9m2h-fmjg
Cross-site Scripting (XSS) - Reflected in GitHub repository lirantal/daloradius prior to master-branch.
GHSA-2m7g-78xc-qr55
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0, 10.3.6.0, 12.1.1.0, and 12.1.2.0 allows remote attackers to affect integrity via unknown vectors related to Console.
GHSA-2m7f-2c58-jfxc
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and 9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
GHSA-2m79-pc7w-p467
A vulnerability was found in KylinSoft hedron-domain-hook up to 3.8.0.12-0k0.5. It has been declared as critical. This vulnerability affects the function init_kcm of the component DBus Handler. The manipulation leads to improper access controls. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. VDB-248578 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
GHSA-2m78-3m48-94h8
SQL-Injection vulnerability caused by the lack of verification of input values for the table name of DB used by the Mangboard bulletin board. A remote attacker can use this vulnerability to execute arbitrary code on the server where the bulletin board is running.
GHSA-2m77-r9w3-w44v
A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic. The soup_message_headers_append_common() function in libsoup/soup-message-headers.c unconditionally appends each header value without validating for duplicate or conflicting Content-Length fields. This allows an attacker to send HTTP requests containing multiple Content-Length headers with differing values.
GHSA-2m77-r88p-x375
Dell Peripheral Manager, versions prior to 1.7.6, contain an uncontrolled search path element vulnerability. An attacker could potentially exploit this vulnerability through preloading malicious DLL or symbolic link exploitation, leading to arbitrary code execution and escalation of privilege
GHSA-2m76-xr87-v8p2
The WiFi component in Apple iOS before 5 stores WiFi credentials in an unspecified file, which makes it easier for remote attackers to obtain sensitive information via a crafted application.
GHSA-2m76-jw89-jx9c
The decode_frame function in libavcodec/eamad.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted Electronic Arts Madcow video data, which triggers an out-of-bounds array access.
GHSA-2m76-j3f4-m2c2
The Access Control Bypass vulnerability found in ALC WebCTRL and Carrier i-Vu in versions up to and including 8.5 allows a malicious actor to bypass intended access restrictions and expose sensitive information via the web based building automation server.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2m7q-4j9m-89vh In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored value could lead to stored XSS/HTML/CSS injection on shared mailboxes. | CVSS3: 4.4 | 0% Низкий | 2 месяца назад | |
GHSA-2m7p-qcqr-gfv2 The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr operations, which allows local users to bypass intended access restrictions and modify the attributes of arbitrary overlay files via a crafted application. | CVSS3: 6.7 | 22% Средний | около 4 лет назад | |
GHSA-2m7m-jhx5-8crh IBM Aspera Orchestrator 4.0.1 could allow a remote attacker to enumerate usernames due to observable response discrepancies. IBM X-Force ID: 248545. | CVSS3: 5.3 | 0% Низкий | около 2 лет назад | |
GHSA-2m7m-j3mq-9g6p A vulnerability, which was classified as critical, has been found in gmg137 snap7-rs up to 1.142.1. Affected by this issue is the function pthread_cond_destroy of the component Public API. The manipulation leads to memory corruption. The exploit has been disclosed to the public and may be used. | CVSS3: 5.5 | 0% Низкий | около 1 года назад | |
GHSA-2m7m-3qp3-4h9x IBM Jazz Foundation products is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190741. | 1% Низкий | около 4 лет назад | ||
GHSA-2m7j-prfm-384p Buffer overflow in mah-jong 1.5.6 and earlier allows remote attackers to execute arbitrary code. | 5% Низкий | больше 4 лет назад | ||
GHSA-2m7j-4ff8-h52q Northern.tech Mender before 3.6.5 and 3.7.x before 3.7.5 has Incorrect Access Control. | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
GHSA-2m7h-86qq-fp4v Insecure entropy in Argo CD's PKCE/Oauth2/OIDC params | CVSS3: 8.3 | 1% Низкий | около 4 лет назад | |
GHSA-2m7h-5m38-vhh4 The Podlove Podcast Publisher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'move_as_original_file' function in all versions up to, and including, 4.2.6. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. | CVSS3: 9.8 | 1% Низкий | 10 месяцев назад | |
GHSA-2m7g-9q74-9m3q Improper Certificate Validation in Apache Beam | CVSS3: 7.5 | 1% Низкий | около 6 лет назад | |
GHSA-2m7g-9m2h-fmjg Cross-site Scripting (XSS) - Reflected in GitHub repository lirantal/daloradius prior to master-branch. | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-2m7g-78xc-qr55 Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0, 10.3.6.0, 12.1.1.0, and 12.1.2.0 allows remote attackers to affect integrity via unknown vectors related to Console. | 3% Низкий | около 4 лет назад | ||
GHSA-2m7f-2c58-jfxc Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.43, 8.4.0-8.4.6 and 9.0.0-9.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H). | CVSS3: 4.9 | 1% Низкий | 9 месяцев назад | |
GHSA-2m79-pc7w-p467 A vulnerability was found in KylinSoft hedron-domain-hook up to 3.8.0.12-0k0.5. It has been declared as critical. This vulnerability affects the function init_kcm of the component DBus Handler. The manipulation leads to improper access controls. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. VDB-248578 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 7.8 | 0% Низкий | больше 2 лет назад | |
GHSA-2m78-3m48-94h8 SQL-Injection vulnerability caused by the lack of verification of input values for the table name of DB used by the Mangboard bulletin board. A remote attacker can use this vulnerability to execute arbitrary code on the server where the bulletin board is running. | CVSS3: 9.8 | 1% Низкий | больше 3 лет назад | |
GHSA-2m77-r9w3-w44v A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic. The soup_message_headers_append_common() function in libsoup/soup-message-headers.c unconditionally appends each header value without validating for duplicate or conflicting Content-Length fields. This allows an attacker to send HTTP requests containing multiple Content-Length headers with differing values. | CVSS3: 3.7 | 0% Низкий | 3 месяца назад | |
GHSA-2m77-r88p-x375 Dell Peripheral Manager, versions prior to 1.7.6, contain an uncontrolled search path element vulnerability. An attacker could potentially exploit this vulnerability through preloading malicious DLL or symbolic link exploitation, leading to arbitrary code execution and escalation of privilege | CVSS3: 7.3 | 0% Низкий | около 2 лет назад | |
GHSA-2m76-xr87-v8p2 The WiFi component in Apple iOS before 5 stores WiFi credentials in an unspecified file, which makes it easier for remote attackers to obtain sensitive information via a crafted application. | 2% Низкий | около 4 лет назад | ||
GHSA-2m76-jw89-jx9c The decode_frame function in libavcodec/eamad.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via crafted Electronic Arts Madcow video data, which triggers an out-of-bounds array access. | 2% Низкий | около 4 лет назад | ||
GHSA-2m76-j3f4-m2c2 The Access Control Bypass vulnerability found in ALC WebCTRL and Carrier i-Vu in versions up to and including 8.5 allows a malicious actor to bypass intended access restrictions and expose sensitive information via the web based building automation server. | 0% Низкий | 8 месяцев назад |
Уязвимостей на страницу