Количество 375 453
Количество 375 453
GHSA-3mv6-r7mf-4mmv
Cross-site scripting (XSS) vulnerability in the web framework in Cisco Content Security Management on Security Management Appliance (SMA) devices allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCuh24749.
GHSA-3mv5-rjm2-qwx6
An information disclosure vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that could allow unauthenticated access to some configuration files which may contain usernames, license keys, IP addresses, and encrypted password hashes.
GHSA-3mv5-343c-w2qg
Ref methods into_ref, into_mut, into_slice, and into_slice_mut are unsound when used with cell::Ref or cell::RefMut
GHSA-3mv4-jjf4-j7wj
Adobe InDesign versions ID18.3 (and earlier) and ID17.4.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
GHSA-3mv4-77hr-gc5g
Launch Services in Apple Mac OS X 10.5.8 does not properly recognize an unsafe Uniform Type Identifier (UTI) in an exported document type in a downloaded application, which allows remote attackers to trigger the automatic opening of a file, and execute arbitrary code, via a crafted web site.
GHSA-3mv4-6x34-qw3c
A floating point exception (divide-by-zero) issue was discovered in SoX in functon read_samples() of voc.c file. An attacker with a crafted file, could cause an application to crash.
GHSA-3mv4-59rc-qvqm
WordPress before 5.2.3 allows XSS in post previews by authenticated users.
GHSA-3mv3-hfpq-vvw5
In IP Multimedia Subsystem, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
GHSA-3mv3-2f4g-87xm
Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments. Several URI Schemes are defined for this purpose. Links can be activated by clicks, or by automatic document events. The execution of such links must be subject to user approval. In the affected versions of OpenOffice, approval for certain links is not requested; when activated, such links could therefore result in arbitrary script execution.
GHSA-3mv2-vmwh-rwfx
AVideo: 2FA toggle endpoint has no CSRF protection, letting an attacker page silently disable a logged-in victim's 2FA
GHSA-3mv2-86j6-x44q
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
GHSA-3mrx-hx45-5865
Windows USB Video Class System Driver Elevation of Privilege Vulnerability
GHSA-3mrx-5p8g-6q5j
PHPMemcachedAdmin 1.2.2 and earlier allows remote attackers to execute arbitrary PHP code via vectors related "serialized data and the last part of the concatenated filename," which creates a file in webroot.
GHSA-3mrx-4wfm-g48p
An issue discovered in Obsidian Canvas 1.1.9 allows remote attackers to send desktop notifications, record user audio and other unspecified impacts via embedded website on the canvas page.
GHSA-3mrw-xf65-fqjh
In the Linux kernel, the following vulnerability has been resolved: cifs: Fix busy dentry used after unmounting Since commit 340cea84f691c ("cifs: open files should not hold ref on superblock"), cifs file only holds the dentry ref_cnt, the cifs file close work(cfile->deferred) could be executed after unmounting, which will trigger a warning in generic_shutdown_super: BUG: Dentry 00000000a14a6845{i=c,n=file} still in use (1) [unmount of cifs cifs] The detailed processs is: process A process B kworker fd = open(PATH) vfs_open file->__f_path = *path // dentry->d_lockref.count = 1 cifs_open cifs_new_fileinfo cfile->dentry = dget(dentry) // dentry->d_lockref.count = 2 close(fd) __fput cifs_close queue_delayed_work(deferredclose_wq, cfile->deferred) dput(dentry) // dentry->d_lockref.count = 1 smb2_deferred_work_close _cifsFileInfo_put list_del(&cifs_file->flist) umount cl...
GHSA-3mrv-v95f-r4rx
AOM v2.0.1 was discovered to contain a NULL pointer dereference via the component rate_hist.c.
GHSA-3mrv-rm2p-hfgx
Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 156.
GHSA-3mrv-3jj9-w487
The Allow SVG Files WordPress plugin through 1.1 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads
GHSA-3mrr-qqw5-mqj9
The School Manage System, developed by ALLE INFORMATION CO., LTD., contains a vulnerability of Path Traversal, allowing attackers to access arbitrary files.
GHSA-3mrr-pqw6-73rq
Multiple SQL injection vulnerabilities in Zoph (aka Zoph Organizes Photos) 0.9.1 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) _action parameter to group.php or (2) user.php or the (3) location_id parameter to photos.php in php/.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3mv6-r7mf-4mmv Cross-site scripting (XSS) vulnerability in the web framework in Cisco Content Security Management on Security Management Appliance (SMA) devices allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter, aka Bug ID CSCuh24749. | 1% Низкий | больше 4 лет назад | ||
GHSA-3mv5-rjm2-qwx6 An information disclosure vulnerability was reported in Lenovo XClarity Administrator (LXCA) versions prior to 2.6.6 that could allow unauthenticated access to some configuration files which may contain usernames, license keys, IP addresses, and encrypted password hashes. | 1% Низкий | больше 4 лет назад | ||
GHSA-3mv5-343c-w2qg Ref methods into_ref, into_mut, into_slice, and into_slice_mut are unsound when used with cell::Ref or cell::RefMut | почти 3 года назад | |||
GHSA-3mv4-jjf4-j7wj Adobe InDesign versions ID18.3 (and earlier) and ID17.4.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | CVSS3: 5.5 | 0% Низкий | около 3 лет назад | |
GHSA-3mv4-77hr-gc5g Launch Services in Apple Mac OS X 10.5.8 does not properly recognize an unsafe Uniform Type Identifier (UTI) in an exported document type in a downloaded application, which allows remote attackers to trigger the automatic opening of a file, and execute arbitrary code, via a crafted web site. | 2% Низкий | больше 4 лет назад | ||
GHSA-3mv4-6x34-qw3c A floating point exception (divide-by-zero) issue was discovered in SoX in functon read_samples() of voc.c file. An attacker with a crafted file, could cause an application to crash. | CVSS3: 5.5 | 0% Низкий | около 4 лет назад | |
GHSA-3mv4-59rc-qvqm WordPress before 5.2.3 allows XSS in post previews by authenticated users. | CVSS3: 5.4 | 5% Низкий | больше 4 лет назад | |
GHSA-3mv3-hfpq-vvw5 In IP Multimedia Subsystem, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. | CVSS3: 8.8 | 0% Низкий | 7 дней назад | |
GHSA-3mv3-2f4g-87xm Apache OpenOffice documents can contain links that call internal macros with arbitrary arguments. Several URI Schemes are defined for this purpose. Links can be activated by clicks, or by automatic document events. The execution of such links must be subject to user approval. In the affected versions of OpenOffice, approval for certain links is not requested; when activated, such links could therefore result in arbitrary script execution. | CVSS3: 7.8 | 1% Низкий | больше 3 лет назад | |
GHSA-3mv2-vmwh-rwfx AVideo: 2FA toggle endpoint has no CSRF protection, letting an attacker page silently disable a logged-in victim's 2FA | CVSS3: 5.7 | 0% Низкий | 4 месяца назад | |
GHSA-3mv2-86j6-x44q Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally. | CVSS3: 7 | 0% Низкий | 4 месяца назад | |
GHSA-3mrx-hx45-5865 Windows USB Video Class System Driver Elevation of Privilege Vulnerability | CVSS3: 6.8 | 1% Низкий | почти 2 года назад | |
GHSA-3mrx-5p8g-6q5j PHPMemcachedAdmin 1.2.2 and earlier allows remote attackers to execute arbitrary PHP code via vectors related "serialized data and the last part of the concatenated filename," which creates a file in webroot. | CVSS3: 9.8 | 12% Средний | больше 4 лет назад | |
GHSA-3mrx-4wfm-g48p An issue discovered in Obsidian Canvas 1.1.9 allows remote attackers to send desktop notifications, record user audio and other unspecified impacts via embedded website on the canvas page. | CVSS3: 6.5 | 2% Низкий | больше 3 лет назад | |
GHSA-3mrw-xf65-fqjh In the Linux kernel, the following vulnerability has been resolved: cifs: Fix busy dentry used after unmounting Since commit 340cea84f691c ("cifs: open files should not hold ref on superblock"), cifs file only holds the dentry ref_cnt, the cifs file close work(cfile->deferred) could be executed after unmounting, which will trigger a warning in generic_shutdown_super: BUG: Dentry 00000000a14a6845{i=c,n=file} still in use (1) [unmount of cifs cifs] The detailed processs is: process A process B kworker fd = open(PATH) vfs_open file->__f_path = *path // dentry->d_lockref.count = 1 cifs_open cifs_new_fileinfo cfile->dentry = dget(dentry) // dentry->d_lockref.count = 2 close(fd) __fput cifs_close queue_delayed_work(deferredclose_wq, cfile->deferred) dput(dentry) // dentry->d_lockref.count = 1 smb2_deferred_work_close _cifsFileInfo_put list_del(&cifs_file->flist) umount cl... | CVSS3: 7.8 | 0% Низкий | 2 месяца назад | |
GHSA-3mrv-v95f-r4rx AOM v2.0.1 was discovered to contain a NULL pointer dereference via the component rate_hist.c. | CVSS3: 6.5 | 1% Низкий | почти 5 лет назад | |
GHSA-3mrv-rm2p-hfgx Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 156. | 0% Низкий | 7 дней назад | ||
GHSA-3mrv-3jj9-w487 The Allow SVG Files WordPress plugin through 1.1 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads | CVSS3: 5.4 | 1% Низкий | около 4 лет назад | |
GHSA-3mrr-qqw5-mqj9 The School Manage System, developed by ALLE INFORMATION CO., LTD., contains a vulnerability of Path Traversal, allowing attackers to access arbitrary files. | 1% Низкий | больше 4 лет назад | ||
GHSA-3mrr-pqw6-73rq Multiple SQL injection vulnerabilities in Zoph (aka Zoph Organizes Photos) 0.9.1 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) _action parameter to group.php or (2) user.php or the (3) location_id parameter to photos.php in php/. | 2% Низкий | больше 4 лет назад |
Уязвимостей на страницу