Количество 376 080
Количество 376 080
GHSA-3mjq-qmqc-xrrv
Microsoft Windows Media Player 7 executes scripts in custom skin (.WMS) files, which could allow remote attackers to gain privileges via a skin that contains a malicious script, aka the ".WMS Script Execution" vulnerability.
GHSA-3mjq-gr7r-h6x3
An XML External Entity (XXE) vulnerability in the Import object and Translation Memory import functionalities of WorldServer v11.8.2 to access sensitive information and execute arbitrary commands via supplying a crafted .tmx file.
GHSA-3mjq-8c52-rc5f
A vulnerability was found in SourceCodester Car Driving School Management System 1.0. It has been declared as problematic. Affected by this vulnerability is the function update_settings_info of the file /classes/SystemSettings.php?f=update_settings. The manipulation of the argument contact/address leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
GHSA-3mjp-p938-4329
Apache Tomcat vulnerable to SecurityManager bypass
GHSA-3mjp-86xg-ff9v
Improper Restriction of XML External Entity Reference vulnerability in DLP Endpoint for Windows prior to 11.9.100 and 11.6.600 allows a remote attacker to cause the DLP Agent to access a local service that the attacker wouldn't usually have access to via a carefully constructed XML file, which the DLP Agent doesn't parse correctly.
GHSA-3mjm-x6gw-2x42
@grackle-ai/server has Missing Content-Security-Policy and X-Frame-Options Headers
GHSA-3mjj-mr4f-qxmx
Mercurial mishandles integer addition and subtraction
GHSA-3mjj-j5cv-mf5p
Cross-site request forgery (CSRF) vulnerability in admin/conf_users_edit.php in PHP Link Directory (phpLD) 4.1.0 allows remote attackers to hijack the authentication of administrators for requests that add an administrator via the N action.
GHSA-3mjj-g5w8-p3gp
In the Linux kernel, the following vulnerability has been resolved: xsk: require at least 16 bytes of TX metadata AF_XDP accepts a TX metadata length as small as eight bytes, but every supported request needs the flags plus at least one eight-byte request field. Such short metadata also lets the kernel read beyond the registered area. Require 16 bytes rather than sizeof(struct xsk_tx_metadata) to preserve compatibility with applications that do not use launch-time metadata.
GHSA-3mjj-cjvr-532f
Unspecified vulnerability in Reservation.class.php for phpScheduleIt 1.01 and earlier allows attackers to modify or delete reservations.
GHSA-3mjj-7mcj-gxwq
Inappropriate implementation in Autofill in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
GHSA-3mjh-xq7h-qg2x
The SureRank SEO WordPress plugin before 1.10.1 does not exclude users' registered account email addresses from the structured data it outputs on public pages by default, allowing unauthenticated visitors to obtain the email address of any user who has published content.
GHSA-3mjh-87v6-2677
Unspecified vulnerability in McAfee Encrypted USB Manager 3.1.0.0, when the Re-use Threshold for passwords is nonzero, allows remote attackers to conduct offline brute force attacks via unknown vectors.
GHSA-3mjh-34gx-h2r7
Symantec Endpoint Protection Manager, prior to 14.3, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program.
GHSA-3mjg-gvfx-f783
Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 allow remote attackers to execute arbitrary code by changing an element's style from position:relative to position:static, which causes Gecko to operate on freed memory.
GHSA-3mjg-59rv-9hm8
In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can use the `printf` SPL function to perform a denial of service (DoS) against the Splunk Enterprise instance.
GHSA-3mjg-24q2-wgh5
In InputMethodInfo of InputMethodInfo.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
GHSA-3mjf-x8rp-5rcp
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of input size.
GHSA-3mjf-7c4r-qw77
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
GHSA-3mjc-mr9p-3j4r
Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3mjq-qmqc-xrrv Microsoft Windows Media Player 7 executes scripts in custom skin (.WMS) files, which could allow remote attackers to gain privileges via a skin that contains a malicious script, aka the ".WMS Script Execution" vulnerability. | 14% Средний | больше 4 лет назад | ||
GHSA-3mjq-gr7r-h6x3 An XML External Entity (XXE) vulnerability in the Import object and Translation Memory import functionalities of WorldServer v11.8.2 to access sensitive information and execute arbitrary commands via supplying a crafted .tmx file. | CVSS3: 6.5 | 1% Низкий | почти 2 года назад | |
GHSA-3mjq-8c52-rc5f A vulnerability was found in SourceCodester Car Driving School Management System 1.0. It has been declared as problematic. Affected by this vulnerability is the function update_settings_info of the file /classes/SystemSettings.php?f=update_settings. The manipulation of the argument contact/address leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 3.5 | 0% Низкий | около 2 лет назад | |
GHSA-3mjp-p938-4329 Apache Tomcat vulnerable to SecurityManager bypass | CVSS3: 7.5 | 8% Низкий | больше 4 лет назад | |
GHSA-3mjp-86xg-ff9v Improper Restriction of XML External Entity Reference vulnerability in DLP Endpoint for Windows prior to 11.9.100 and 11.6.600 allows a remote attacker to cause the DLP Agent to access a local service that the attacker wouldn't usually have access to via a carefully constructed XML file, which the DLP Agent doesn't parse correctly. | CVSS3: 6.5 | 1% Низкий | около 4 лет назад | |
GHSA-3mjm-x6gw-2x42 @grackle-ai/server has Missing Content-Security-Policy and X-Frame-Options Headers | 6 месяцев назад | |||
GHSA-3mjj-mr4f-qxmx Mercurial mishandles integer addition and subtraction | CVSS3: 9.8 | 3% Низкий | больше 4 лет назад | |
GHSA-3mjj-j5cv-mf5p Cross-site request forgery (CSRF) vulnerability in admin/conf_users_edit.php in PHP Link Directory (phpLD) 4.1.0 allows remote attackers to hijack the authentication of administrators for requests that add an administrator via the N action. | 1% Низкий | больше 4 лет назад | ||
GHSA-3mjj-g5w8-p3gp In the Linux kernel, the following vulnerability has been resolved: xsk: require at least 16 bytes of TX metadata AF_XDP accepts a TX metadata length as small as eight bytes, but every supported request needs the flags plus at least one eight-byte request field. Such short metadata also lets the kernel read beyond the registered area. Require 16 bytes rather than sizeof(struct xsk_tx_metadata) to preserve compatibility with applications that do not use launch-time metadata. | CVSS3: 7.8 | 0% Низкий | около 1 месяца назад | |
GHSA-3mjj-cjvr-532f Unspecified vulnerability in Reservation.class.php for phpScheduleIt 1.01 and earlier allows attackers to modify or delete reservations. | 1% Низкий | больше 4 лет назад | ||
GHSA-3mjj-7mcj-gxwq Inappropriate implementation in Autofill in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: High) | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
GHSA-3mjh-xq7h-qg2x The SureRank SEO WordPress plugin before 1.10.1 does not exclude users' registered account email addresses from the structured data it outputs on public pages by default, allowing unauthenticated visitors to obtain the email address of any user who has published content. | CVSS3: 5.3 | 0% Низкий | 12 дней назад | |
GHSA-3mjh-87v6-2677 Unspecified vulnerability in McAfee Encrypted USB Manager 3.1.0.0, when the Re-use Threshold for passwords is nonzero, allows remote attackers to conduct offline brute force attacks via unknown vectors. | 1% Низкий | больше 4 лет назад | ||
GHSA-3mjh-34gx-h2r7 Symantec Endpoint Protection Manager, prior to 14.3, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program. | 0% Низкий | больше 4 лет назад | ||
GHSA-3mjg-gvfx-f783 Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 allow remote attackers to execute arbitrary code by changing an element's style from position:relative to position:static, which causes Gecko to operate on freed memory. | 5% Низкий | больше 4 лет назад | ||
GHSA-3mjg-59rv-9hm8 In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can use the `printf` SPL function to perform a denial of service (DoS) against the Splunk Enterprise instance. | CVSS3: 6.5 | 0% Низкий | около 3 лет назад | |
GHSA-3mjg-24q2-wgh5 In InputMethodInfo of InputMethodInfo.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. | CVSS3: 5.5 | 0% Низкий | 10 месяцев назад | |
GHSA-3mjf-x8rp-5rcp IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of input size. | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
GHSA-3mjf-7c4r-qw77 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | CVSS3: 5.5 | 1% Низкий | около 3 лет назад | |
GHSA-3mjc-mr9p-3j4r Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure. | 9 месяцев назад |
Уязвимостей на страницу