Количество 353 489
Количество 353 489
GHSA-2cjm-p78p-rjpj
Adobe Animate version 21.0.9 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious .psd file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability.
GHSA-2cjm-j72p-vj2q
Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
GHSA-2cjm-f4h6-vv39
Out-of-bounds Write vulnerability in WujekFoliarz DualSenseY-v2.This issue affects DualSenseY-v2: before 54.
GHSA-2cjm-cj9v-8j23
Cross-site scripting (XSS) vulnerability in index.php in phpLinks 2.1.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the term parameter.
GHSA-2cjm-39g8-5fv8
In Shanda MapleStory Online V160, the SdoKeyCrypt.sys driver allows privilege escalation to NT AUTHORITY\SYSTEM because of not validating the IOCtl 0x8000c01c input value, leading to an integer signedness error and a heap-based buffer underflow.
GHSA-2cjm-2gwv-m892
Parse Server's OAuth2 adapter shares mutable state across providers via singleton instance
GHSA-2cjj-vh62-f62h
IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 through 6.0.6) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 145509.
GHSA-2cjj-7rx5-5hhq
STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, related to a "Read Access Violation on Control Flow starting at Unknown Symbol @ 0x0000000003aa7cef called from Unknown Symbol @ 0x0000000004aa024d."
GHSA-2cjh-75gp-34gc
livewire Cross-Site Request Forgery vulnerability
GHSA-2cjg-pfcc-g8hr
In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the ASN.1 BER and related dissectors could crash. This was addressed in epan/dissectors/packet-ber.c by preventing a buffer overflow associated with excessive digits in time values.
GHSA-2cjg-6xm9-4wh6
IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 could allow remote attackers to bypass authentication via a direct request or forced browsing to a page other than URL intended. IBM X-Force ID: 142561.
GHSA-2cjg-466r-p8w4
A vulnerability has been found in Ettercap 0.8.4-Garofalo. Affected by this vulnerability is the function add_data_segment of the file src/ettercap/utils/etterfilter/ef_output.c of the component etterfilter. The manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
GHSA-2cjf-w7c4-fhf6
Cross-site Scripting in Beanstalk console
GHSA-2cjf-q722-7gc5
SQL injection vulnerability in search_results.php in ABK-Soft AbleDating 2.4 allows remote attackers to execute arbitrary SQL commands via the keyword parameter.
GHSA-2cjf-4qjm-hh7v
An issue was discovered in Open Ticket Request System (OTRS) 6.0.x before 6.0.12. An attacker could send an e-mail message with a malicious link to an OTRS system or an agent. If a logged-in agent opens this link, it could cause the execution of JavaScript in the context of OTRS.
GHSA-2cjc-rgmp-x649
Traefik Missing Authentication
GHSA-2cjc-6xrh-7w5q
Missing Authorization vulnerability in ThemeSupport Hide Category by User Role for WooCommerce.This issue affects Hide Category by User Role for WooCommerce: from n/a through 2.1.1.
GHSA-2cjc-543p-gpj8
admin/default.php in PHPMyWind v5.5 has XSS via an HTTP Host header.
GHSA-2cj9-wjmr-5w57
An off-by-one error flaw was found in the udevListInterfacesByStatus() function in libvirt when the number of interfaces exceeds the size of the `names` array. This issue can be reproduced by sending specially crafted data to the libvirt daemon, allowing an unprivileged client to perform a denial of service attack by causing the libvirt daemon to crash.
GHSA-2cj9-r6h5-6jwg
ServerDocs Server in Apple OS X Server before 5.2 supports the RC4 cipher, which might allow remote attackers to defeat cryptographic protection mechanisms via unspecified vectors.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2cjm-p78p-rjpj Adobe Animate version 21.0.9 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious .psd file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability. | CVSS3: 7.8 | 3% Низкий | больше 4 лет назад | |
GHSA-2cjm-j72p-vj2q Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | CVSS3: 5.5 | 2% Низкий | больше 2 лет назад | |
GHSA-2cjm-f4h6-vv39 Out-of-bounds Write vulnerability in WujekFoliarz DualSenseY-v2.This issue affects DualSenseY-v2: before 54. | CVSS3: 7.8 | 0% Низкий | 4 месяца назад | |
GHSA-2cjm-cj9v-8j23 Cross-site scripting (XSS) vulnerability in index.php in phpLinks 2.1.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the term parameter. | 2% Низкий | около 4 лет назад | ||
GHSA-2cjm-39g8-5fv8 In Shanda MapleStory Online V160, the SdoKeyCrypt.sys driver allows privilege escalation to NT AUTHORITY\SYSTEM because of not validating the IOCtl 0x8000c01c input value, leading to an integer signedness error and a heap-based buffer underflow. | CVSS3: 7.8 | 1% Низкий | около 4 лет назад | |
GHSA-2cjm-2gwv-m892 Parse Server's OAuth2 adapter shares mutable state across providers via singleton instance | 0% Низкий | 5 месяцев назад | ||
GHSA-2cjj-vh62-f62h IBM Jazz Foundation (IBM Rational Collaborative Lifecycle Management 5.0 through 6.0.6) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 145509. | CVSS3: 5.4 | 1% Низкий | около 4 лет назад | |
GHSA-2cjj-7rx5-5hhq STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, related to a "Read Access Violation on Control Flow starting at Unknown Symbol @ 0x0000000003aa7cef called from Unknown Symbol @ 0x0000000004aa024d." | CVSS3: 7.8 | 0% Низкий | около 4 лет назад | |
GHSA-2cjh-75gp-34gc livewire Cross-Site Request Forgery vulnerability | CVSS3: 8.8 | 0% Низкий | больше 2 лет назад | |
GHSA-2cjg-pfcc-g8hr In Wireshark 2.4.0 to 2.4.12 and 2.6.0 to 2.6.6, the ASN.1 BER and related dissectors could crash. This was addressed in epan/dissectors/packet-ber.c by preventing a buffer overflow associated with excessive digits in time values. | CVSS3: 5.5 | 1% Низкий | около 4 лет назад | |
GHSA-2cjg-6xm9-4wh6 IBM Rational Engineering Lifecycle Manager 5.0 through 5.02 and 6.0 through 6.0.6 could allow remote attackers to bypass authentication via a direct request or forced browsing to a page other than URL intended. IBM X-Force ID: 142561. | CVSS3: 6.5 | 1% Низкий | около 4 лет назад | |
GHSA-2cjg-466r-p8w4 A vulnerability has been found in Ettercap 0.8.4-Garofalo. Affected by this vulnerability is the function add_data_segment of the file src/ettercap/utils/etterfilter/ef_output.c of the component etterfilter. The manipulation leads to out-of-bounds read. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet. | CVSS3: 3.3 | 0% Низкий | 5 месяцев назад | |
GHSA-2cjf-w7c4-fhf6 Cross-site Scripting in Beanstalk console | CVSS3: 6.3 | 1% Низкий | больше 4 лет назад | |
GHSA-2cjf-q722-7gc5 SQL injection vulnerability in search_results.php in ABK-Soft AbleDating 2.4 allows remote attackers to execute arbitrary SQL commands via the keyword parameter. | 1% Низкий | около 4 лет назад | ||
GHSA-2cjf-4qjm-hh7v An issue was discovered in Open Ticket Request System (OTRS) 6.0.x before 6.0.12. An attacker could send an e-mail message with a malicious link to an OTRS system or an agent. If a logged-in agent opens this link, it could cause the execution of JavaScript in the context of OTRS. | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-2cjc-rgmp-x649 Traefik Missing Authentication | CVSS3: 7.5 | 3% Низкий | около 4 лет назад | |
GHSA-2cjc-6xrh-7w5q Missing Authorization vulnerability in ThemeSupport Hide Category by User Role for WooCommerce.This issue affects Hide Category by User Role for WooCommerce: from n/a through 2.1.1. | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
GHSA-2cjc-543p-gpj8 admin/default.php in PHPMyWind v5.5 has XSS via an HTTP Host header. | CVSS3: 4.8 | 1% Низкий | около 4 лет назад | |
GHSA-2cj9-wjmr-5w57 An off-by-one error flaw was found in the udevListInterfacesByStatus() function in libvirt when the number of interfaces exceeds the size of the `names` array. This issue can be reproduced by sending specially crafted data to the libvirt daemon, allowing an unprivileged client to perform a denial of service attack by causing the libvirt daemon to crash. | CVSS3: 5.5 | 0% Низкий | больше 2 лет назад | |
GHSA-2cj9-r6h5-6jwg ServerDocs Server in Apple OS X Server before 5.2 supports the RC4 cipher, which might allow remote attackers to defeat cryptographic protection mechanisms via unspecified vectors. | CVSS3: 7.5 | 2% Низкий | около 4 лет назад |
Уязвимостей на страницу