Количество 375 453
Количество 375 453
GHSA-3mpv-vc7v-xpc6
ipchat.php in Invision Power Board 1.1.1 allows remote attackers to execute arbitrary PHP code, if register_globals is enabled, by modifying the root_path parameter to reference a URL on a remote web server that contains the code.
GHSA-3mpv-gr2q-vh5j
A Reflected Cross-Site Scripting (XSS) vulnerability in the index.php login-portal webpage of SourceCodester Tailor Management System v1.0 allows remote attackers to harvest keys pressed by an unauthenticated victim who clicks on a malicious URL and begins typing.
GHSA-3mpv-g3cv-rx7h
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a security bypass vulnerability. Successful exploitation could lead to arbitrary folder creation.
GHSA-3mpv-3cfr-mgjj
With MariaDB running on Windows, when local clients connect to the server over named pipes, it's possible for an unprivileged user with an ability to run code on the server machine to intercept the named pipe connection and act as a man-in-the-middle, gaining access to all the data passed between the client and the server, and getting the ability to run SQL commands on behalf of the connected user. This occurs because of an incorrect security descriptor. This affects MariaDB Server before 10.1.48, 10.2.x before 10.2.35, 10.3.x before 10.3.26, 10.4.x before 10.4.16, and 10.5.x before 10.5.7. NOTE: this issue exists because certain details of the MariaDB CVE-2019-2503 fix did not comprehensively address attack variants against MariaDB. This situation is specific to MariaDB, and thus CVE-2020-28912 does NOT apply to other vendors that were originally affected by CVE-2019-2503.
GHSA-3mpr-vw5v-hq89
In JetBrains YouTrack before 2021.2.16363, system user passwords were hashed with SHA-256.
GHSA-3mpr-qj98-wfp9
The UberMedia UberSocial (com.twidroid) application 7.x before 7.2.4 for Android does not properly protect data, which allows remote attackers to read or modify Twitter information via a crafted application.
GHSA-3mpr-hq3p-49h9
Prototype Pollution in mixin-deep
GHSA-3mpr-9r86-mfv2
Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the pwd parameter at /aprocess.php.
GHSA-3mpq-x397-f3cg
FreeBit ServersMan 3.1.5 on Apple iPhone OS 3.1.2, and iPhone OS for iPod touch, allows remote attackers to cause a denial of service (daemon crash) via a HEAD request for the / URI.
GHSA-3mpq-f59x-83gx
Array index error in gd_gif_in.c in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (crash and heap corruption) via large color index values in crafted image data, which results in a segmentation fault.
GHSA-3mpq-55rm-gc7g
SQL injection vulnerability in post.php for MercuryBoard 1.1.1 allows remote attackers to execute arbitrary SQL commands via a reply post action for index.php with (1) the t parameter or (2) the qu parameter.
GHSA-3mpp-xhfx-rv7h
Adobe Substance 3D Stager version 2.0.1 (and earlier) is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
GHSA-3mpp-xh9p-vf59
Cisco VPN 3000 Concentrator 2.2.x, 3.6(Rel), and 3.x before 3.5.5, allows remote attackers to cause a denial of service via a long user name.
GHSA-3mpp-xfvh-qh37
node-ipc behavior change
GHSA-3mpm-jx38-9m8w
sassdoc-extras vulnerable to prototype pollution
GHSA-3mpm-5q2w-wr7w
HCL Commerce Remote Store server could allow a remote attacker, using a specially-crafted URL, to read arbitrary files on the system.
GHSA-3mpj-wgvw-fw9v
SQL Injection vulnerability in HiPresta "Gift Wrapping Pro" (hiadvancedgiftwrapping) module for PrestaShop before version 1.4.1, allows remote attackers to escalate privileges and obtain sensitive information via the HiAdvancedGiftWrappingGiftWrappingModuleFrontController::addGiftWrappingCartValue() method.
GHSA-3mpj-h64q-x7gf
In CODESYS EtherNetIP before 4.1.0.0, specific EtherNet/IP requests may cause a null pointer dereference in the downloaded vulnerable EtherNet/IP stack that is executed by the CODESYS Control runtime system.
GHSA-3mpj-g9cw-f3hj
A null pointer dereference issue was discovered in fs/io_uring.c in the Linux kernel before 5.15.62. A local user could use this flaw to crash the system or potentially cause a denial of service.
GHSA-3mpj-92q9-pvw2
Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow a local user to obtain information and spoof a server via a man-in-the-middle (MITM) attack between a client and a domain controller when PKINIT smart card authentication is being used.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3mpv-vc7v-xpc6 ipchat.php in Invision Power Board 1.1.1 allows remote attackers to execute arbitrary PHP code, if register_globals is enabled, by modifying the root_path parameter to reference a URL on a remote web server that contains the code. | 4% Низкий | больше 4 лет назад | ||
GHSA-3mpv-gr2q-vh5j A Reflected Cross-Site Scripting (XSS) vulnerability in the index.php login-portal webpage of SourceCodester Tailor Management System v1.0 allows remote attackers to harvest keys pressed by an unauthenticated victim who clicks on a malicious URL and begins typing. | CVSS3: 6.1 | 2% Низкий | больше 4 лет назад | |
GHSA-3mpv-g3cv-rx7h Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a security bypass vulnerability. Successful exploitation could lead to arbitrary folder creation. | CVSS3: 5.3 | 6% Низкий | больше 4 лет назад | |
GHSA-3mpv-3cfr-mgjj With MariaDB running on Windows, when local clients connect to the server over named pipes, it's possible for an unprivileged user with an ability to run code on the server machine to intercept the named pipe connection and act as a man-in-the-middle, gaining access to all the data passed between the client and the server, and getting the ability to run SQL commands on behalf of the connected user. This occurs because of an incorrect security descriptor. This affects MariaDB Server before 10.1.48, 10.2.x before 10.2.35, 10.3.x before 10.3.26, 10.4.x before 10.4.16, and 10.5.x before 10.5.7. NOTE: this issue exists because certain details of the MariaDB CVE-2019-2503 fix did not comprehensively address attack variants against MariaDB. This situation is specific to MariaDB, and thus CVE-2020-28912 does NOT apply to other vendors that were originally affected by CVE-2019-2503. | 0% Низкий | больше 4 лет назад | ||
GHSA-3mpr-vw5v-hq89 In JetBrains YouTrack before 2021.2.16363, system user passwords were hashed with SHA-256. | CVSS3: 5.3 | 1% Низкий | больше 4 лет назад | |
GHSA-3mpr-qj98-wfp9 The UberMedia UberSocial (com.twidroid) application 7.x before 7.2.4 for Android does not properly protect data, which allows remote attackers to read or modify Twitter information via a crafted application. | 1% Низкий | больше 4 лет назад | ||
GHSA-3mpr-hq3p-49h9 Prototype Pollution in mixin-deep | CVSS3: 8.8 | 2% Низкий | около 8 лет назад | |
GHSA-3mpr-9r86-mfv2 Employee Managment System v1.0 was discovered to contain a SQL injection vulnerability via the pwd parameter at /aprocess.php. | CVSS3: 9.8 | 1% Низкий | больше 2 лет назад | |
GHSA-3mpq-x397-f3cg FreeBit ServersMan 3.1.5 on Apple iPhone OS 3.1.2, and iPhone OS for iPod touch, allows remote attackers to cause a denial of service (daemon crash) via a HEAD request for the / URI. | 6% Низкий | больше 4 лет назад | ||
GHSA-3mpq-f59x-83gx Array index error in gd_gif_in.c in the GD Graphics Library (libgd) before 2.0.35 allows user-assisted remote attackers to cause a denial of service (crash and heap corruption) via large color index values in crafted image data, which results in a segmentation fault. | 2% Низкий | больше 4 лет назад | ||
GHSA-3mpq-55rm-gc7g SQL injection vulnerability in post.php for MercuryBoard 1.1.1 allows remote attackers to execute arbitrary SQL commands via a reply post action for index.php with (1) the t parameter or (2) the qu parameter. | 1% Низкий | больше 4 лет назад | ||
GHSA-3mpp-xhfx-rv7h Adobe Substance 3D Stager version 2.0.1 (and earlier) is affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-3mpp-xh9p-vf59 Cisco VPN 3000 Concentrator 2.2.x, 3.6(Rel), and 3.x before 3.5.5, allows remote attackers to cause a denial of service via a long user name. | 3% Низкий | больше 4 лет назад | ||
GHSA-3mpp-xfvh-qh37 node-ipc behavior change | больше 4 лет назад | |||
GHSA-3mpm-jx38-9m8w sassdoc-extras vulnerable to prototype pollution | 0% Низкий | 12 месяцев назад | ||
GHSA-3mpm-5q2w-wr7w HCL Commerce Remote Store server could allow a remote attacker, using a specially-crafted URL, to read arbitrary files on the system. | CVSS3: 5.8 | 1% Низкий | почти 3 года назад | |
GHSA-3mpj-wgvw-fw9v SQL Injection vulnerability in HiPresta "Gift Wrapping Pro" (hiadvancedgiftwrapping) module for PrestaShop before version 1.4.1, allows remote attackers to escalate privileges and obtain sensitive information via the HiAdvancedGiftWrappingGiftWrappingModuleFrontController::addGiftWrappingCartValue() method. | CVSS3: 9.8 | 1% Низкий | больше 2 лет назад | |
GHSA-3mpj-h64q-x7gf In CODESYS EtherNetIP before 4.1.0.0, specific EtherNet/IP requests may cause a null pointer dereference in the downloaded vulnerable EtherNet/IP stack that is executed by the CODESYS Control runtime system. | 1% Низкий | больше 4 лет назад | ||
GHSA-3mpj-g9cw-f3hj A null pointer dereference issue was discovered in fs/io_uring.c in the Linux kernel before 5.15.62. A local user could use this flaw to crash the system or potentially cause a denial of service. | CVSS3: 5.5 | 0% Низкий | около 4 лет назад | |
GHSA-3mpj-92q9-pvw2 Unknown vulnerability in the PKINIT Protocol for Microsoft Windows 2000, Windows XP, and Windows Server 2003 could allow a local user to obtain information and spoof a server via a man-in-the-middle (MITM) attack between a client and a domain controller when PKINIT smart card authentication is being used. | 2% Низкий | больше 4 лет назад |
Уязвимостей на страницу