Количество 353 883
Количество 353 883
GHSA-2m58-mxxr-fwgc
D-Link DIR-615 2.5.17 devices allow Remote Code Execution via shell metacharacters in the Host field of the System / Traceroute screen.
GHSA-2m58-j4rw-6qj5
Lucent Ascend MAX Router 5.0 and earlier, Lucent Ascend Pipeline Router 6.0.2 and earlier and Lucent DSLTerminator allows remote attackers to obtain sensitive information such as hostname, MAC, and IP address of the Ethernet interface via a discard (UDP port 9) packet, which causes the device to leak the information in the response.
GHSA-2m57-vvf7-q43j
Adobe Illustrator versions 26.4 (and earlier) and 25.4.7 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
GHSA-2m57-rxhp-5h39
The strong name (SN) implementation in Microsoft .NET Framework 2.0.50727 relies on the digital signature Public Key Token embedded in the pathname of a DLL file instead of the digital signature of this file itself, which makes it easier for attackers to bypass Global Assembly Cache (GAC) and Code Access Security (CAS) protection mechanisms, aka MSRC ticket MSRC8566gs.
GHSA-2m57-hf25-phgg
sqlparse parsing heavily nested list leads to Denial of Service
GHSA-2m57-99r8-vg66
Buffer overflow in the dissect_tlv function in epan/dissectors/packet-ldp.c in the LDP dissector in Wireshark 1.8.x before 1.8.3 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a malformed packet.
GHSA-2m57-2jcm-c3xj
Deserialization of Untrusted Data vulnerability in universam UNIVERSAM universam-demo allows Object Injection.This issue affects UNIVERSAM: from n/a through <= 8.72.34.
GHSA-2m56-rv9w-ph64
Improper Privilege Management vulnerability in Jacques Malgrange Rencontre – Dating Site allows Privilege Escalation.This issue affects Rencontre – Dating Site: from n/a through 3.10.1.
GHSA-2m54-c69q-qw3j
Unspecified vulnerability in the admin script in Open Business Management (OBM) before 2.0.0 allows remote attackers to have an unknown impact by calling the script "in txt mode from a browser."
GHSA-2m54-8m6g-qf93
Duplicate Advisory: Open Babel has an out-of-bounds read in CIF transform3d::DescribeAsString
GHSA-2m54-4wrp-wqr2
Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
GHSA-2m53-83f3-562j
Prototype pollution in min-dash
GHSA-2m53-6p59-jfh3
Software installed and run as a non-privileged user may conduct improper GPU system calls to allow unprivileged access to arbitrary physical memory page.
GHSA-2m53-35qc-87r8
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. An app may be able to cause unexpected system termination.
GHSA-2m52-fc9q-48mj
Logic vulnerability in the mobile application (com.transsion.carlcare) may lead to the risk of account takeover.
GHSA-2m52-9vfw-wq4v
Cross-site scripting (XSS) vulnerability in the PageTriage toolbar in the PageTriage extension for MediWiki allows remote attackers to inject arbitrary web script or HTML via the page title.
GHSA-2m4x-rxx6-8xjw
A vulnerability has been found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. Affected by this issue is some unknown functionality of the file /assets/uploadSllyabus.php. Such manipulation of the argument File leads to unrestricted upload. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable.
GHSA-2m4x-88vm-2g75
An improper use of the SD card for sensitive data vulnerability was reported in the Motorola Device Help application that could allow a local attacker to read system logs.
GHSA-2m4x-4q9j-w97g
Denial of service in Open Policy Agent
GHSA-2m4v-vm5r-wqxw
The callforward module in User Control Panel (UCP) in Nicolas Gudino (aka Asternic) Flash Operator Panel (FOP) 2.31.03 allows remote authenticated users to execute arbitrary commands via the command parameter.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2m58-mxxr-fwgc D-Link DIR-615 2.5.17 devices allow Remote Code Execution via shell metacharacters in the Host field of the System / Traceroute screen. | CVSS3: 7.2 | 3% Низкий | около 4 лет назад | |
GHSA-2m58-j4rw-6qj5 Lucent Ascend MAX Router 5.0 and earlier, Lucent Ascend Pipeline Router 6.0.2 and earlier and Lucent DSLTerminator allows remote attackers to obtain sensitive information such as hostname, MAC, and IP address of the Ethernet interface via a discard (UDP port 9) packet, which causes the device to leak the information in the response. | 1% Низкий | больше 4 лет назад | ||
GHSA-2m57-vvf7-q43j Adobe Illustrator versions 26.4 (and earlier) and 25.4.7 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | CVSS3: 7.8 | 1% Низкий | почти 4 года назад | |
GHSA-2m57-rxhp-5h39 The strong name (SN) implementation in Microsoft .NET Framework 2.0.50727 relies on the digital signature Public Key Token embedded in the pathname of a DLL file instead of the digital signature of this file itself, which makes it easier for attackers to bypass Global Assembly Cache (GAC) and Code Access Security (CAS) protection mechanisms, aka MSRC ticket MSRC8566gs. | 8% Низкий | около 4 лет назад | ||
GHSA-2m57-hf25-phgg sqlparse parsing heavily nested list leads to Denial of Service | CVSS3: 7.5 | 3% Низкий | больше 2 лет назад | |
GHSA-2m57-99r8-vg66 Buffer overflow in the dissect_tlv function in epan/dissectors/packet-ldp.c in the LDP dissector in Wireshark 1.8.x before 1.8.3 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a malformed packet. | 1% Низкий | около 4 лет назад | ||
GHSA-2m57-2jcm-c3xj Deserialization of Untrusted Data vulnerability in universam UNIVERSAM universam-demo allows Object Injection.This issue affects UNIVERSAM: from n/a through <= 8.72.34. | CVSS3: 9.8 | 1% Низкий | 9 месяцев назад | |
GHSA-2m56-rv9w-ph64 Improper Privilege Management vulnerability in Jacques Malgrange Rencontre – Dating Site allows Privilege Escalation.This issue affects Rencontre – Dating Site: from n/a through 3.10.1. | CVSS3: 9.8 | 1% Низкий | больше 2 лет назад | |
GHSA-2m54-c69q-qw3j Unspecified vulnerability in the admin script in Open Business Management (OBM) before 2.0.0 allows remote attackers to have an unknown impact by calling the script "in txt mode from a browser." | 2% Низкий | больше 4 лет назад | ||
GHSA-2m54-8m6g-qf93 Duplicate Advisory: Open Babel has an out-of-bounds read in CIF transform3d::DescribeAsString | CVSS3: 4.3 | 5 месяцев назад | ||
GHSA-2m54-4wrp-wqr2 Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | CVSS3: 7.8 | 1% Низкий | почти 4 года назад | |
GHSA-2m53-83f3-562j Prototype pollution in min-dash | CVSS3: 7.5 | 2% Низкий | больше 4 лет назад | |
GHSA-2m53-6p59-jfh3 Software installed and run as a non-privileged user may conduct improper GPU system calls to allow unprivileged access to arbitrary physical memory page. | CVSS3: 8.1 | 0% Низкий | больше 1 года назад | |
GHSA-2m53-35qc-87r8 A use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Sequoia 15.7.8, macOS Tahoe 26.6, tvOS 26.6, visionOS 26.6. An app may be able to cause unexpected system termination. | CVSS3: 9.8 | 0% Низкий | 6 дней назад | |
GHSA-2m52-fc9q-48mj Logic vulnerability in the mobile application (com.transsion.carlcare) may lead to the risk of account takeover. | CVSS3: 9.8 | 0% Низкий | больше 1 года назад | |
GHSA-2m52-9vfw-wq4v Cross-site scripting (XSS) vulnerability in the PageTriage toolbar in the PageTriage extension for MediWiki allows remote attackers to inject arbitrary web script or HTML via the page title. | 1% Низкий | около 4 лет назад | ||
GHSA-2m4x-rxx6-8xjw A vulnerability has been found in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. Affected by this issue is some unknown functionality of the file /assets/uploadSllyabus.php. Such manipulation of the argument File leads to unrestricted upload. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. | CVSS3: 7.3 | 0% Низкий | 10 месяцев назад | |
GHSA-2m4x-88vm-2g75 An improper use of the SD card for sensitive data vulnerability was reported in the Motorola Device Help application that could allow a local attacker to read system logs. | CVSS3: 5 | 0% Низкий | около 2 лет назад | |
GHSA-2m4x-4q9j-w97g Denial of service in Open Policy Agent | CVSS3: 7.5 | 2% Низкий | около 4 лет назад | |
GHSA-2m4v-vm5r-wqxw The callforward module in User Control Panel (UCP) in Nicolas Gudino (aka Asternic) Flash Operator Panel (FOP) 2.31.03 allows remote authenticated users to execute arbitrary commands via the command parameter. | CVSS3: 8.8 | 2% Низкий | около 4 лет назад |
Уязвимостей на страницу