Количество 353 269
Количество 353 269
GHSA-2h9q-63fq-25hj
IPRoute 0.973, 0.974 and 1.18 allows remote attackers to cause a denial of service via fragmented IP packets that split the TCP header.
GHSA-2h9q-5qx9-w5fm
Reusing a nonce, key pair in encryption issue exists in "FreeFrom - the nostr client" App versions prior to 1.3.5 for Android and iOS. If this vulnerability is exploited, the content of direct messages (DMs) between users may be manipulated by a man-in-the-middle attack.
GHSA-2h9p-q5rr-fvrp
An authenticated remote code execution (RCE) vulnerability exists in multiple WSO2 products due to improper input validation in the event processor admin service. A user with administrative access to the SOAP admin services can exploit this flaw by deploying a Siddhi execution plan containing malicious Java code, resulting in arbitrary code execution on the server. Exploitation of this vulnerability requires a valid user account with administrative privileges, limiting the attack surface to authenticated but potentially malicious users.
GHSA-2h9p-fvvm-92g9
Tablet Windows User Interface Application Core Elevation of Privilege Vulnerability.
GHSA-2h9m-7wj7-h654
IBM MQ Appliance 9.3 LTS and 9.3 CD could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request to view arbitrary files on the system. IBM X-Force ID: 269536.
GHSA-2h9j-hxw7-2jf3
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
GHSA-2h9h-wfvh-5r96
Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involving PREAUTH, which is a less secure behavior than the alternative of closing the connection and letting the user decide what they would like to do.
GHSA-2h9h-pcw6-4f34
A buffer overflow in the g_cfg.MaxUsers component of LightFTP v2.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.
GHSA-2h9h-4f6p-xvfc
Cross-site scripting (XSS) vulnerability in view.php in eTicket 1.5.5.2 allows remote attackers to inject arbitrary web script or HTML via the s parameter.
GHSA-2h9g-8p3q-w23q
A vulnerability has been found in code-projects Real State Services 1.0. This impacts an unknown function of the file /loginuser.php of the component Login. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
GHSA-2h9f-xm25-q379
In wlan STA, there is a possible way to trick a client to connect to an AP with spoofed SSID. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08990446 / ALPS09057442; Issue ID: MSV-1598.
GHSA-2h9f-vrvc-wfwh
An information disclosure vulnerability exists in Windows 8.1, Windows RT 8.1, Windows Server 2012 R2, Windows 10, and Windows Server 2016 when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user's system, a.k.a. "Windows Kernel Information Disclosure Vulnerability."
GHSA-2h9f-vc99-85c4
A system-critical Windows NT registry key has inappropriate permissions.
GHSA-2h9f-ppj9-gcvv
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Piotnet Piotnet Addons For Elementor allows Stored XSS.This issue affects Piotnet Addons For Elementor: from n/a through 2.4.26.
GHSA-2h9f-48qh-w996
Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_support/index.php?page=edit_customer.
GHSA-2h9c-p959-263w
Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.
GHSA-2h9c-gjwm-vfqx
Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme Rara Business allows Cross Site Request Forgery.This issue affects Rara Business: from n/a through 1.2.5.
GHSA-2h9c-34v6-3qmr
Kubernetes in OpenShift3 Access Control Misconfiguration
GHSA-2h98-r334-3wg6
siteadmin/useredit.php in AlstraSoft Video Share Enterprise does not check authentication, which allows remote attackers to obtain or modify user information via a direct request.
GHSA-2h98-6q8m-mm63
textract before 1.5.0 allows OS Command Injection attacks via a filename in a call to the process function. This may be a remote attack if a web application accepts names of arbitrary uploaded files.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2h9q-63fq-25hj IPRoute 0.973, 0.974 and 1.18 allows remote attackers to cause a denial of service via fragmented IP packets that split the TCP header. | 1% Низкий | больше 4 лет назад | ||
GHSA-2h9q-5qx9-w5fm Reusing a nonce, key pair in encryption issue exists in "FreeFrom - the nostr client" App versions prior to 1.3.5 for Android and iOS. If this vulnerability is exploited, the content of direct messages (DMs) between users may be manipulated by a man-in-the-middle attack. | CVSS3: 5.3 | 0% Низкий | около 2 лет назад | |
GHSA-2h9p-q5rr-fvrp An authenticated remote code execution (RCE) vulnerability exists in multiple WSO2 products due to improper input validation in the event processor admin service. A user with administrative access to the SOAP admin services can exploit this flaw by deploying a Siddhi execution plan containing malicious Java code, resulting in arbitrary code execution on the server. Exploitation of this vulnerability requires a valid user account with administrative privileges, limiting the attack surface to authenticated but potentially malicious users. | CVSS3: 6.7 | 1% Низкий | 10 месяцев назад | |
GHSA-2h9p-fvvm-92g9 Tablet Windows User Interface Application Core Elevation of Privilege Vulnerability. | CVSS3: 7 | 1% Низкий | около 4 лет назад | |
GHSA-2h9m-7wj7-h654 IBM MQ Appliance 9.3 LTS and 9.3 CD could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request to view arbitrary files on the system. IBM X-Force ID: 269536. | CVSS3: 6.5 | 1% Низкий | больше 2 лет назад | |
GHSA-2h9j-hxw7-2jf3 Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | CVSS3: 7.8 | 0% Низкий | 17 дней назад | |
GHSA-2h9h-wfvh-5r96 Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involving PREAUTH, which is a less secure behavior than the alternative of closing the connection and letting the user decide what they would like to do. | CVSS3: 7.5 | 2% Низкий | около 4 лет назад | |
GHSA-2h9h-pcw6-4f34 A buffer overflow in the g_cfg.MaxUsers component of LightFTP v2.0 allows attackers to cause a Denial of Service (DoS) via a crafted input. | CVSS3: 6.5 | 0% Низкий | 8 месяцев назад | |
GHSA-2h9h-4f6p-xvfc Cross-site scripting (XSS) vulnerability in view.php in eTicket 1.5.5.2 allows remote attackers to inject arbitrary web script or HTML via the s parameter. | 2% Низкий | около 4 лет назад | ||
GHSA-2h9g-8p3q-w23q A vulnerability has been found in code-projects Real State Services 1.0. This impacts an unknown function of the file /loginuser.php of the component Login. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 7.3 | 0% Низкий | около 2 месяцев назад | |
GHSA-2h9f-xm25-q379 In wlan STA, there is a possible way to trick a client to connect to an AP with spoofed SSID. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08990446 / ALPS09057442; Issue ID: MSV-1598. | CVSS3: 7.5 | 0% Низкий | больше 1 года назад | |
GHSA-2h9f-vrvc-wfwh An information disclosure vulnerability exists in Windows 8.1, Windows RT 8.1, Windows Server 2012 R2, Windows 10, and Windows Server 2016 when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user's system, a.k.a. "Windows Kernel Information Disclosure Vulnerability." | CVSS3: 5.5 | 6% Низкий | около 4 лет назад | |
GHSA-2h9f-vc99-85c4 A system-critical Windows NT registry key has inappropriate permissions. | 2% Низкий | больше 4 лет назад | ||
GHSA-2h9f-ppj9-gcvv Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Piotnet Piotnet Addons For Elementor allows Stored XSS.This issue affects Piotnet Addons For Elementor: from n/a through 2.4.26. | CVSS3: 6.5 | 0% Низкий | больше 2 лет назад | |
GHSA-2h9f-48qh-w996 Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_support/index.php?page=edit_customer. | CVSS3: 4.3 | 1% Низкий | больше 2 лет назад | |
GHSA-2h9c-p959-263w Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 17 дней назад | |
GHSA-2h9c-gjwm-vfqx Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme Rara Business allows Cross Site Request Forgery.This issue affects Rara Business: from n/a through 1.2.5. | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
GHSA-2h9c-34v6-3qmr Kubernetes in OpenShift3 Access Control Misconfiguration | CVSS3: 3.1 | 1% Низкий | около 4 лет назад | |
GHSA-2h98-r334-3wg6 siteadmin/useredit.php in AlstraSoft Video Share Enterprise does not check authentication, which allows remote attackers to obtain or modify user information via a direct request. | 2% Низкий | около 4 лет назад | ||
GHSA-2h98-6q8m-mm63 textract before 1.5.0 allows OS Command Injection attacks via a filename in a call to the process function. This may be a remote attack if a web application accepts names of arbitrary uploaded files. | CVSS3: 7.8 | 2% Низкий | около 4 лет назад |
Уязвимостей на страницу