Количество 353 269
Количество 353 269
GHSA-2f2h-563c-rxj9
WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1.
GHSA-2f2h-3f83-3qq7
In asf extractor, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05489178; Issue ID: ALPS05585817.
GHSA-2f2g-f3rf-qmx3
The Ping and Traceroute features on TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 180119 Rel.65243n devices allow authenticated blind Command Injection.
GHSA-2f2f-rjcq-rw8r
Buffer overflow in FreeBSD lpd through long DNS hostnames.
GHSA-2f2c-9gcx-q39v
A cross-site request forgery (CSRF) vulnerability in Indexhibit 2.1.5 allows attackers to arbitrarily reset account passwords.
GHSA-2f29-v4g5-53hv
Uncontrolled search path for the FPGA Support Package for the Intel(R) oneAPI DPC++/C++ Compiler software for Windows before version 2024.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
GHSA-2f29-rcr5-p2xm
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pixobe Pixobe Cartography allows DOM-Based XSS.This issue affects Pixobe Cartography: from n/a through 1.0.1.
GHSA-2f29-qx45-3v8j
An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to execute arbitrary code by using a crafted HTML document to obtain control of a function pointer.
GHSA-2f29-pmpx-vj62
Directory Traversal in serverwg
GHSA-2f29-j8f8-fmjg
Cryptocat before 2.0.22 Chrome Extension 'img/keygen.gif' has Information Disclosure
GHSA-2f29-hqcf-xx8j
Unspecified vulnerability in DirectShow in DirectX in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted media file, related to Quartz.dll, Qdvd.dll, closed captioning, and the Line21 DirectShow filter, aka "DirectShow Remote Code Execution Vulnerability."
GHSA-2f29-75qf-r6xg
A vulnerability was found in SourceCodester Simple Cold Storage Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /csms/admin/?page=system_info of the component Setting Handler. The manipulation of the argument System Name/System Short Name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-211047.
GHSA-2f29-629x-3r89
An issue was discovered in Zammad before 3.5.1. A REST API call allows an attacker to change Ticket Article data in a way that defeats auditing.
GHSA-2f28-fj6q-q44h
Octech Oempro 4.7 through 4.11 allow stored XSS by an authenticated user. The FolderName parameter of the Media.CreateFolder command is vulnerable.
GHSA-2f28-f6j6-pc52
Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application, aka "Win32k Use After Free Vulnerability."
GHSA-2f28-c6gf-w62p
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
GHSA-2f28-7x9r-f2vq
A missing protection against path traversal allows to access any file on the server.
GHSA-2f28-69j7-85hf
Easy!Appointments SQL injection vulnerability
GHSA-2f28-6595-fhpf
A potentially exploitable crash in "EnumerateSubDocuments" while adding or removing sub-documents. This vulnerability affects Firefox ESR < 45.6 and Thunderbird < 45.6.
GHSA-2f28-2fwm-699f
The web interface on the Cisco Scientific Atlanta WebSTAR DPC2100R2 cable modem with firmware 2.0.2r1256-060303 allows remote attackers to bypass authentication, and reset the modem or replace the firmware, via a direct request to an unspecified page.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2f2h-563c-rxj9 WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1. | 4% Низкий | около 4 лет назад | ||
GHSA-2f2h-3f83-3qq7 In asf extractor, there is a possible out of bounds read due to an integer overflow. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS05489178; Issue ID: ALPS05585817. | 0% Низкий | около 4 лет назад | ||
GHSA-2f2g-f3rf-qmx3 The Ping and Traceroute features on TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 180119 Rel.65243n devices allow authenticated blind Command Injection. | CVSS3: 8.8 | 3% Низкий | около 4 лет назад | |
GHSA-2f2f-rjcq-rw8r Buffer overflow in FreeBSD lpd through long DNS hostnames. | 1% Низкий | больше 4 лет назад | ||
GHSA-2f2c-9gcx-q39v A cross-site request forgery (CSRF) vulnerability in Indexhibit 2.1.5 allows attackers to arbitrarily reset account passwords. | 0% Низкий | около 4 лет назад | ||
GHSA-2f29-v4g5-53hv Uncontrolled search path for the FPGA Support Package for the Intel(R) oneAPI DPC++/C++ Compiler software for Windows before version 2024.2 may allow an authenticated user to potentially enable escalation of privilege via local access. | CVSS3: 6.7 | 0% Низкий | больше 1 года назад | |
GHSA-2f29-rcr5-p2xm Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pixobe Pixobe Cartography allows DOM-Based XSS.This issue affects Pixobe Cartography: from n/a through 1.0.1. | CVSS3: 6.5 | 0% Низкий | больше 1 года назад | |
GHSA-2f29-qx45-3v8j An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows remote attackers to execute arbitrary code by using a crafted HTML document to obtain control of a function pointer. | 6% Низкий | около 4 лет назад | ||
GHSA-2f29-pmpx-vj62 Directory Traversal in serverwg | CVSS3: 7.5 | 2% Низкий | почти 6 лет назад | |
GHSA-2f29-j8f8-fmjg Cryptocat before 2.0.22 Chrome Extension 'img/keygen.gif' has Information Disclosure | CVSS3: 7.5 | 12% Средний | около 4 лет назад | |
GHSA-2f29-hqcf-xx8j Unspecified vulnerability in DirectShow in DirectX in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code via a crafted media file, related to Quartz.dll, Qdvd.dll, closed captioning, and the Line21 DirectShow filter, aka "DirectShow Remote Code Execution Vulnerability." | 23% Средний | около 4 лет назад | ||
GHSA-2f29-75qf-r6xg A vulnerability was found in SourceCodester Simple Cold Storage Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /csms/admin/?page=system_info of the component Setting Handler. The manipulation of the argument System Name/System Short Name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-211047. | CVSS3: 4.8 | 1% Низкий | почти 4 года назад | |
GHSA-2f29-629x-3r89 An issue was discovered in Zammad before 3.5.1. A REST API call allows an attacker to change Ticket Article data in a way that defeats auditing. | 1% Низкий | около 4 лет назад | ||
GHSA-2f28-fj6q-q44h Octech Oempro 4.7 through 4.11 allow stored XSS by an authenticated user. The FolderName parameter of the Media.CreateFolder command is vulnerable. | 1% Низкий | около 4 лет назад | ||
GHSA-2f28-f6j6-pc52 Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application, aka "Win32k Use After Free Vulnerability." | 2% Низкий | около 4 лет назад | ||
GHSA-2f28-c6gf-w62p An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | CVSS3: 9.8 | 7% Низкий | больше 2 лет назад | |
GHSA-2f28-7x9r-f2vq A missing protection against path traversal allows to access any file on the server. | CVSS3: 9.8 | 1% Низкий | около 1 года назад | |
GHSA-2f28-69j7-85hf Easy!Appointments SQL injection vulnerability | 0% Низкий | 11 месяцев назад | ||
GHSA-2f28-6595-fhpf A potentially exploitable crash in "EnumerateSubDocuments" while adding or removing sub-documents. This vulnerability affects Firefox ESR < 45.6 and Thunderbird < 45.6. | CVSS3: 8.8 | 2% Низкий | около 4 лет назад | |
GHSA-2f28-2fwm-699f The web interface on the Cisco Scientific Atlanta WebSTAR DPC2100R2 cable modem with firmware 2.0.2r1256-060303 allows remote attackers to bypass authentication, and reset the modem or replace the firmware, via a direct request to an unspecified page. | 2% Низкий | около 4 лет назад |
Уязвимостей на страницу