Количество 353 489
Количество 353 489
GHSA-2c9q-p5rf-5vp8
The JSON_parser function (ext/json/JSON_parser.c) in PHP 5.2.x before 5.2.9 allows remote attackers to cause a denial of service (segmentation fault) via a malformed string to the json_decode API function.
GHSA-2c9q-jgx6-2qx7
QuickJS before c4cdd61 has a build_for_in_iterator NULL pointer dereference because of an erroneous lexical scope of "this" with eval.
GHSA-2c9q-7wm6-r5xc
Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm-core prior to 8.3.0.
GHSA-2c9q-4475-49j3
Control By Web X-400 devices are vulnerable to a cross-site scripting attack, which could result in private and session information being transferred to the attacker.
GHSA-2c9p-4x2v-863c
An interaction between the Perl MD5 module (perl-Digest-MD5) and Perl could produce incorrect MD5 checksums for UTF-8 data, which could prevent a system from properly verifying the integrity of the data.
GHSA-2c9m-w3h6-q5pr
Dell Pair Installer version prior to 1.2.1 contains an elevation of privilege vulnerability. A low privilege user with local access to the system could potentially exploit this vulnerability to delete arbitrary files and result in Denial of Service.
GHSA-2c9m-w27f-53rm
Apache Tomcat vulnerable to Unprotected Transport of Credentials
GHSA-2c9m-q8q2-rjjx
Premiere Pro versions 26.0.2, 25.6.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
GHSA-2c9m-9m4q-pf59
Heap-based buffer overflow in the xioscan_readline function in xio-readline.c in socat 1.4.0.0 through 1.7.2.0 and 2.0.0-b1 through 2.0.0-b4 allows local users to execute arbitrary code via the READLINE address.
GHSA-2c9h-c498-472c
The Manager in Eye-Fi 1.1.2 generates predictable snonce values based on the time of day, which allows remote attackers to bypass authentication and upload arbitrary images by guessing the snonce.
GHSA-2c9g-xf8g-mf89
InDesign Desktop versions ID19.5, ID18.5.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
GHSA-2c9f-m8c9-p33j
Online Pet Shop We App v1.0 by oretnom23 is vulnerable to SQL injection via /pet_shop/classes/Master.php?f=delete_order,id.
GHSA-2c9f-95gh-crpj
Brocade SANnav before Brocade SANvav v. 2.2.0.2 and Brocade SANanv v.2.1.1.8 logs the Brocade Fabric OS switch password in plain text in asyncjobscheduler-manager.log
GHSA-2c9f-7jg2-vp9c
Inadequate input validation leads to XSS vulnerabilities in the accessiblemedia field.
GHSA-2c9f-5m92-rwqm
cPanel before 68.0.15 allows use of an unreserved e-mail address in DNS zone SOA records (SEC-306).
GHSA-2c9f-4h7m-wqr9
In the Linux kernel, the following vulnerability has been resolved: EDAC/igen6: Avoid segmentation fault on module unload The segmentation fault happens because: During modprobe: 1. In igen6_probe(), igen6_pvt will be allocated with kzalloc() 2. In igen6_register_mci(), mci->pvt_info will point to &igen6_pvt->imc[mc] During rmmod: 1. In mci_release() in edac_mc.c, it will kfree(mci->pvt_info) 2. In igen6_remove(), it will kfree(igen6_pvt); Fix this issue by setting mci->pvt_info to NULL to avoid the double kfree.
GHSA-2c9f-3x4j-7qjc
PHP remote file inclusion vulnerability in admin/configset.php in Sphider 1.3 and earlier, when register_globals is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the settings_dir parameter.
GHSA-2c9c-945f-4jg3
Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/cells/view_cell.php:4
GHSA-2c9c-5m3c-vxqg
SSH Tectia Client and Server before 6.4.19 on Windows allow local privilege escalation in nonstandard conditions. ConnectSecure on Windows is affected.
GHSA-2c99-hrrc-j3vh
Floating point exception in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via get_slope function.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2c9q-p5rf-5vp8 The JSON_parser function (ext/json/JSON_parser.c) in PHP 5.2.x before 5.2.9 allows remote attackers to cause a denial of service (segmentation fault) via a malformed string to the json_decode API function. | 2% Низкий | около 4 лет назад | ||
GHSA-2c9q-jgx6-2qx7 QuickJS before c4cdd61 has a build_for_in_iterator NULL pointer dereference because of an erroneous lexical scope of "this" with eval. | CVSS3: 7.5 | 1% Низкий | больше 2 лет назад | |
GHSA-2c9q-7wm6-r5xc Cross-site Scripting (XSS) - Stored in GitHub repository salesagility/suitecrm-core prior to 8.3.0. | CVSS3: 7.6 | 1% Низкий | около 3 лет назад | |
GHSA-2c9q-4475-49j3 Control By Web X-400 devices are vulnerable to a cross-site scripting attack, which could result in private and session information being transferred to the attacker. | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-2c9p-4x2v-863c An interaction between the Perl MD5 module (perl-Digest-MD5) and Perl could produce incorrect MD5 checksums for UTF-8 data, which could prevent a system from properly verifying the integrity of the data. | 1% Низкий | больше 4 лет назад | ||
GHSA-2c9m-w3h6-q5pr Dell Pair Installer version prior to 1.2.1 contains an elevation of privilege vulnerability. A low privilege user with local access to the system could potentially exploit this vulnerability to delete arbitrary files and result in Denial of Service. | CVSS3: 6.6 | 0% Низкий | больше 2 лет назад | |
GHSA-2c9m-w27f-53rm Apache Tomcat vulnerable to Unprotected Transport of Credentials | CVSS3: 4.3 | 2% Низкий | больше 3 лет назад | |
GHSA-2c9m-q8q2-rjjx Premiere Pro versions 26.0.2, 25.6.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | CVSS3: 7.8 | 0% Низкий | 3 месяца назад | |
GHSA-2c9m-9m4q-pf59 Heap-based buffer overflow in the xioscan_readline function in xio-readline.c in socat 1.4.0.0 through 1.7.2.0 and 2.0.0-b1 through 2.0.0-b4 allows local users to execute arbitrary code via the READLINE address. | 0% Низкий | около 4 лет назад | ||
GHSA-2c9h-c498-472c The Manager in Eye-Fi 1.1.2 generates predictable snonce values based on the time of day, which allows remote attackers to bypass authentication and upload arbitrary images by guessing the snonce. | 1% Низкий | около 4 лет назад | ||
GHSA-2c9g-xf8g-mf89 InDesign Desktop versions ID19.5, ID18.5.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | CVSS3: 5.5 | 0% Низкий | больше 1 года назад | |
GHSA-2c9f-m8c9-p33j Online Pet Shop We App v1.0 by oretnom23 is vulnerable to SQL injection via /pet_shop/classes/Master.php?f=delete_order,id. | CVSS3: 7.2 | 1% Низкий | почти 4 года назад | |
GHSA-2c9f-95gh-crpj Brocade SANnav before Brocade SANvav v. 2.2.0.2 and Brocade SANanv v.2.1.1.8 logs the Brocade Fabric OS switch password in plain text in asyncjobscheduler-manager.log | CVSS3: 6.5 | 1% Низкий | около 4 лет назад | |
GHSA-2c9f-7jg2-vp9c Inadequate input validation leads to XSS vulnerabilities in the accessiblemedia field. | CVSS3: 6.1 | 0% Низкий | около 2 лет назад | |
GHSA-2c9f-5m92-rwqm cPanel before 68.0.15 allows use of an unreserved e-mail address in DNS zone SOA records (SEC-306). | CVSS3: 2.7 | 1% Низкий | около 4 лет назад | |
GHSA-2c9f-4h7m-wqr9 In the Linux kernel, the following vulnerability has been resolved: EDAC/igen6: Avoid segmentation fault on module unload The segmentation fault happens because: During modprobe: 1. In igen6_probe(), igen6_pvt will be allocated with kzalloc() 2. In igen6_register_mci(), mci->pvt_info will point to &igen6_pvt->imc[mc] During rmmod: 1. In mci_release() in edac_mc.c, it will kfree(mci->pvt_info) 2. In igen6_remove(), it will kfree(igen6_pvt); Fix this issue by setting mci->pvt_info to NULL to avoid the double kfree. | CVSS3: 7.8 | 0% Низкий | больше 1 года назад | |
GHSA-2c9f-3x4j-7qjc PHP remote file inclusion vulnerability in admin/configset.php in Sphider 1.3 and earlier, when register_globals is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the settings_dir parameter. | 8% Низкий | около 4 лет назад | ||
GHSA-2c9c-945f-4jg3 Prison Management System v1.0 was discovered to contain a SQL injection vulnerability via the 'id' parameter at /pms/admin/cells/view_cell.php:4 | CVSS3: 8.8 | 1% Низкий | около 4 лет назад | |
GHSA-2c9c-5m3c-vxqg SSH Tectia Client and Server before 6.4.19 on Windows allow local privilege escalation in nonstandard conditions. ConnectSecure on Windows is affected. | CVSS3: 7 | 0% Низкий | около 4 лет назад | |
GHSA-2c99-hrrc-j3vh Floating point exception in fig2dev in version 3.2.9a allows an attacker to availability via local input manipulation via get_slope function. | CVSS3: 6.6 | 0% Низкий | больше 1 года назад |
Уязвимостей на страницу