Количество 375 356
Количество 375 356
GHSA-3p94-vj97-fm4q
OS Command Injection in fsa
GHSA-3p94-98w5-cmg9
This issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges.
GHSA-3p93-j4fw-gpx2
Unspecified vulnerability in Java Runtime Environment (JRE) for Sun JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 or earlier allows untrusted applets and applications to read arbitrary memory via a crafted ZIP file.
GHSA-3p92-jw9p-xx95
The PPP wvdial.lxdialog script in wvdial 1.4 and earlier creates a .config file with world readable permissions, which allows a local attacker in the dialout group to access login and password information.
GHSA-3p92-886g-qxpq
Remote Memory Exposure in floody
GHSA-3p92-82mx-28gc
Exposure of sensitive information to an unauthorized actor in Azure Data Factory allows an unauthorized attacker to disclose information over a network.
GHSA-3p92-26vx-7f7j
A vulnerability was found in SourceCodester Free Hospital Management System for Small Practices 1.0. It has been classified as critical. This affects an unknown part of the file appointment.php. The manipulation of the argument sheduledate leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-237561 was assigned to this vulnerability.
GHSA-3p92-24w5-4jr6
SQL injection vulnerability in the Seed Coupon plugin before 1.6 for EC-CUBE allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
GHSA-3p8x-pc99-4p67
Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to handling of .nessus files.
GHSA-3p8x-c3hm-xmp2
An improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.1, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiSOAR on-premise 7.5.0 through 7.5.1, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise 7.3 all versions may allow information disclosure to an authenticated attacker via crafted requests
GHSA-3p8v-w8mr-m3x8
Butterfly has path/URL confusion in resource handling leading to multiple weaknesses
GHSA-3p8v-593f-mgx8
In the Linux kernel, the following vulnerability has been resolved: tcp: fix skb_copy_ubufs() vs BIG TCP David Ahern reported crashes in skb_copy_ubufs() caused by TCP tx zerocopy using hugepages, and skb length bigger than ~68 KB. skb_copy_ubufs() assumed it could copy all payload using up to MAX_SKB_FRAGS order-0 pages. This assumption broke when BIG TCP was able to put up to 512 KB per skb. We did not hit this bug at Google because we use CONFIG_MAX_SKB_FRAGS=45 and limit gso_max_size to 180000. A solution is to use higher order pages if needed. v2: add missing __GFP_COMP, or we leak memory.
GHSA-3p8r-p4q5-mc44
Violation Comments to GitLab Plugin has Insufficiently Protected Credentials
GHSA-3p8r-f28v-66f3
Improper Encoding or Escaping of Output vulnerability in Hallo Welt! GmbH BlueSpice (Extension:BlueSpiceAvatars) allows Cross-Site Scripting (XSS). This issue affects BlueSpice: from 5 through 5.1.1.
GHSA-3p8q-7cfq-r67x
Cross-site scripting (XSS) vulnerability in Octopus Deploy 3.7.0-3.17.13 (fixed in 3.17.14) allows remote authenticated users to inject arbitrary web script or HTML via the Step Template Name parameter.
GHSA-3p8p-5mc4-hgmc
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8399.
GHSA-3p8m-qpqj-m94w
PowerScripts PlusMail CGI program allows remote attackers to execute commands via a password file with improper permissions.
GHSA-3p8m-mr3f-jqg6
Cryptographic Issue when using a static initialization vector for AES-GCM key wrapping, which requires a unique value for each call to ensure security.
GHSA-3p8m-j85q-pgmj
Netty's decoders vulnerable to DoS via zip bomb style attack
GHSA-3p8m-82f9-hcgw
Cross-site scripting (XSS) vulnerability in IBM Forms Experience Builder 8.5.x and 8.6.x before 8.6.3 allows remote authenticated users to inject arbitrary web script or HTML via crafted input to an application that was built with this product.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3p94-vj97-fm4q OS Command Injection in fsa | CVSS3: 7.8 | 1% Низкий | почти 5 лет назад | |
GHSA-3p94-98w5-cmg9 This issue was addressed with improved checks. This issue is fixed in macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7. An app may be able to gain root privileges. | CVSS3: 7.8 | 0% Низкий | 7 дней назад | |
GHSA-3p93-j4fw-gpx2 Unspecified vulnerability in Java Runtime Environment (JRE) for Sun JDK and JRE 5.0 Update 16 and earlier; SDK and JRE 1.4.2_18 and earlier; and SDK and JRE 1.3.1_23 or earlier allows untrusted applets and applications to read arbitrary memory via a crafted ZIP file. | 3% Низкий | больше 4 лет назад | ||
GHSA-3p92-jw9p-xx95 The PPP wvdial.lxdialog script in wvdial 1.4 and earlier creates a .config file with world readable permissions, which allows a local attacker in the dialout group to access login and password information. | 0% Низкий | больше 4 лет назад | ||
GHSA-3p92-886g-qxpq Remote Memory Exposure in floody | CVSS3: 5.1 | больше 7 лет назад | ||
GHSA-3p92-82mx-28gc Exposure of sensitive information to an unauthorized actor in Azure Data Factory allows an unauthorized attacker to disclose information over a network. | CVSS3: 8.6 | 1% Низкий | 6 месяцев назад | |
GHSA-3p92-26vx-7f7j A vulnerability was found in SourceCodester Free Hospital Management System for Small Practices 1.0. It has been classified as critical. This affects an unknown part of the file appointment.php. The manipulation of the argument sheduledate leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-237561 was assigned to this vulnerability. | CVSS3: 6.3 | 1% Низкий | около 3 лет назад | |
GHSA-3p92-24w5-4jr6 SQL injection vulnerability in the Seed Coupon plugin before 1.6 for EC-CUBE allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | CVSS3: 9.8 | 2% Низкий | больше 4 лет назад | |
GHSA-3p8x-pc99-4p67 Cross-site scripting (XSS) vulnerability in Tenable Nessus before 6.9 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to handling of .nessus files. | CVSS3: 5.4 | 1% Низкий | больше 4 лет назад | |
GHSA-3p8x-c3hm-xmp2 An improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.1, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiSOAR on-premise 7.5.0 through 7.5.1, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise 7.3 all versions may allow information disclosure to an authenticated attacker via crafted requests | CVSS3: 6.5 | 0% Низкий | 10 месяцев назад | |
GHSA-3p8v-w8mr-m3x8 Butterfly has path/URL confusion in resource handling leading to multiple weaknesses | CVSS3: 9.1 | 2% Низкий | почти 2 года назад | |
GHSA-3p8v-593f-mgx8 In the Linux kernel, the following vulnerability has been resolved: tcp: fix skb_copy_ubufs() vs BIG TCP David Ahern reported crashes in skb_copy_ubufs() caused by TCP tx zerocopy using hugepages, and skb length bigger than ~68 KB. skb_copy_ubufs() assumed it could copy all payload using up to MAX_SKB_FRAGS order-0 pages. This assumption broke when BIG TCP was able to put up to 512 KB per skb. We did not hit this bug at Google because we use CONFIG_MAX_SKB_FRAGS=45 and limit gso_max_size to 180000. A solution is to use higher order pages if needed. v2: add missing __GFP_COMP, or we leak memory. | CVSS3: 5.5 | 0% Низкий | 12 месяцев назад | |
GHSA-3p8r-p4q5-mc44 Violation Comments to GitLab Plugin has Insufficiently Protected Credentials | CVSS3: 4.3 | 1% Низкий | больше 4 лет назад | |
GHSA-3p8r-f28v-66f3 Improper Encoding or Escaping of Output vulnerability in Hallo Welt! GmbH BlueSpice (Extension:BlueSpiceAvatars) allows Cross-Site Scripting (XSS). This issue affects BlueSpice: from 5 through 5.1.1. | CVSS3: 6.4 | 0% Низкий | около 1 года назад | |
GHSA-3p8q-7cfq-r67x Cross-site scripting (XSS) vulnerability in Octopus Deploy 3.7.0-3.17.13 (fixed in 3.17.14) allows remote authenticated users to inject arbitrary web script or HTML via the Step Template Name parameter. | CVSS3: 5.4 | 1% Низкий | больше 4 лет назад | |
GHSA-3p8p-5mc4-hgmc An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8399. | CVSS3: 7 | 1% Низкий | больше 4 лет назад | |
GHSA-3p8m-qpqj-m94w PowerScripts PlusMail CGI program allows remote attackers to execute commands via a password file with improper permissions. | 10% Низкий | больше 4 лет назад | ||
GHSA-3p8m-mr3f-jqg6 Cryptographic Issue when using a static initialization vector for AES-GCM key wrapping, which requires a unique value for each call to ensure security. | CVSS3: 7.1 | 0% Низкий | 3 месяца назад | |
GHSA-3p8m-j85q-pgmj Netty's decoders vulnerable to DoS via zip bomb style attack | 1% Низкий | около 1 года назад | ||
GHSA-3p8m-82f9-hcgw Cross-site scripting (XSS) vulnerability in IBM Forms Experience Builder 8.5.x and 8.6.x before 8.6.3 allows remote authenticated users to inject arbitrary web script or HTML via crafted input to an application that was built with this product. | CVSS3: 2.7 | 1% Низкий | больше 4 лет назад |
Уязвимостей на страницу