Количество 353 269
Количество 353 269
GHSA-29vc-jwh6-m84c
A vulnerability was found in CodePhiliaX Chat2DB up to 0.3.7. This affects an unknown function of the file ai/chat2db/server/web/api/controller/data/source/DataSourceController.java of the component JDBC Connection Handler. The manipulation results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way.
GHSA-29v9-x79c-6xjf
Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8 operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system.
GHSA-29v9-mcvr-88rv
A cross-site scripting (XSS) vulnerability in resource view in PayAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to inject arbitrary web script or HTML via the index.php/Pay/passcodeAuth passcode parameter.
GHSA-29v9-m8r8-v85x
An issue was discovered in PopojiCMS v2.0.1. It has CSRF via the po-admin/route.php?mod=component&act=addnew URI, as demonstrated by adding a level=1 account.
GHSA-29v9-frvh-c426
monetr: Server-side request forgery in Lunch Flow link creation and refresh
GHSA-29v9-2fpx-j5g9
CSV Injection vulnerability with exported contact lists in Mautic
GHSA-29v8-q543-pf5w
Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network.
GHSA-29v8-gqqm-8c25
Cross-Site Request Forgery (CSRF) vulnerability in WP Corner Quick Event Calendar allows Stored XSS. This issue affects Quick Event Calendar: from n/a through 1.4.9.
GHSA-29v7-3v4c-gf38
Data races in parc
GHSA-29v6-j9p2-6qxc
The packet-storing feature on Cisco 9900 phones with firmware 9.3(2) does not properly support the RTP protocol, which allows remote attackers to cause a denial of service (device hang) by sending malformed RTP packets after a call is answered, aka Bug ID CSCur39976.
GHSA-29v6-6hr2-37cw
Deserialization of Untrusted Data vulnerability in YITHEMES YITH WooCommerce Compare yith-woocommerce-compare allows Object Injection.This issue affects YITH WooCommerce Compare: from n/a through <= 3.6.0.
GHSA-29v5-v73g-x3cp
Multiple issues exist that allow files to be uploaded and executed on the WebAccess/NMS (versions prior to 3.0.2).
GHSA-29v4-89fg-g7q9
In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: sof_sdw: Prevent jump to NULL add_sidecar callback In create_sdw_dailink() check that sof_end->codec_info->add_sidecar is not NULL before calling it. The original code assumed that if include_sidecar is true, the codec on that link has an add_sidecar callback. But there could be other codecs on the same link that do not have an add_sidecar callback.
GHSA-29v4-3v34-f922
libZetta.rs through 0.1.2 has an integer overflow in the zpool parser (for error stats) that leads to a panic.
GHSA-29v4-2xqc-8q79
Heap-based buffer overflow in the logi_dj_ll_raw_request function in drivers/hid/hid-logitech-dj.c in the Linux kernel before 3.16.2 allows physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a crafted device that specifies a large report size for an LED report.
GHSA-29v3-r4gm-9j2f
An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9, and 10 software. The network_management service does not properly restrict configuration changes. The LG ID is LVE-SMP-200012 (July 2020).
GHSA-29v3-g4cx-hr4v
RPM Package Manager 4.0.x through 4.0.2.x allows an attacker to execute arbitrary code via corrupted data in the RPM file when the file is queried.
GHSA-29v2-2jwv-8mvr
The LLTD Mapper in Microsoft Windows Vista allows remote attackers to spoof hosts, and nonexistent bridge relationships, into the network topology map by using a MAC address that differs from the MAC address provided in the Real Source field of the LLTD BASE header of a HELLO packet, aka the "Spoof on Bridge" attack.
GHSA-29rx-mvcf-24fj
An issue was discovered on Samsung mobile devices with N(7.1), O(8.x), and P(9.0) (released in China) software. The Firewall application mishandles the PermissionWhiteLists protection mechanism. The Samsung ID is SVE-2019-14299 (November 2019).
GHSA-29rx-6x28-gmg7
Stack-based buffer overflow in the IMAP service in NetWin SurgeMail 38k4-4 and earlier allows remote authenticated users to execute arbitrary code via long arguments to the LSUB command.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-29vc-jwh6-m84c A vulnerability was found in CodePhiliaX Chat2DB up to 0.3.7. This affects an unknown function of the file ai/chat2db/server/web/api/controller/data/source/DataSourceController.java of the component JDBC Connection Handler. The manipulation results in sql injection. The attack can be executed remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 6.3 | 0% Низкий | 12 месяцев назад | |
GHSA-29v9-x79c-6xjf Authenticated command injection vulnerabilities exist in the web-based management interface of mobility conductors running AOS-8 operating system. Successful exploitation could allow an authenticated malicious actor to execute arbitrary commands as a privileged user on the underlying operating system. | CVSS3: 7.2 | 1% Низкий | 7 месяцев назад | |
GHSA-29v9-mcvr-88rv A cross-site scripting (XSS) vulnerability in resource view in PayAction.class.php in D-Link Central WiFi Manager CWM(100) before v1.03R0100_BETA6 allows remote attackers to inject arbitrary web script or HTML via the index.php/Pay/passcodeAuth passcode parameter. | CVSS3: 6.1 | 2% Низкий | около 4 лет назад | |
GHSA-29v9-m8r8-v85x An issue was discovered in PopojiCMS v2.0.1. It has CSRF via the po-admin/route.php?mod=component&act=addnew URI, as demonstrated by adding a level=1 account. | CVSS3: 8.8 | 1% Низкий | около 4 лет назад | |
GHSA-29v9-frvh-c426 monetr: Server-side request forgery in Lunch Flow link creation and refresh | 0% Низкий | 3 месяца назад | ||
GHSA-29v9-2fpx-j5g9 CSV Injection vulnerability with exported contact lists in Mautic | CVSS3: 9.8 | 2% Низкий | больше 5 лет назад | |
GHSA-29v8-q543-pf5w Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a network. | CVSS3: 9.9 | 1% Низкий | 28 дней назад | |
GHSA-29v8-gqqm-8c25 Cross-Site Request Forgery (CSRF) vulnerability in WP Corner Quick Event Calendar allows Stored XSS. This issue affects Quick Event Calendar: from n/a through 1.4.9. | CVSS3: 7.1 | 0% Низкий | 11 месяцев назад | |
GHSA-29v7-3v4c-gf38 Data races in parc | CVSS3: 8.1 | 1% Низкий | почти 5 лет назад | |
GHSA-29v6-j9p2-6qxc The packet-storing feature on Cisco 9900 phones with firmware 9.3(2) does not properly support the RTP protocol, which allows remote attackers to cause a denial of service (device hang) by sending malformed RTP packets after a call is answered, aka Bug ID CSCur39976. | 3% Низкий | около 4 лет назад | ||
GHSA-29v6-6hr2-37cw Deserialization of Untrusted Data vulnerability in YITHEMES YITH WooCommerce Compare yith-woocommerce-compare allows Object Injection.This issue affects YITH WooCommerce Compare: from n/a through <= 3.6.0. | CVSS3: 7.2 | 0% Низкий | 5 месяцев назад | |
GHSA-29v5-v73g-x3cp Multiple issues exist that allow files to be uploaded and executed on the WebAccess/NMS (versions prior to 3.0.2). | 2% Низкий | около 4 лет назад | ||
GHSA-29v4-89fg-g7q9 In the Linux kernel, the following vulnerability has been resolved: ASoC: Intel: sof_sdw: Prevent jump to NULL add_sidecar callback In create_sdw_dailink() check that sof_end->codec_info->add_sidecar is not NULL before calling it. The original code assumed that if include_sidecar is true, the codec on that link has an add_sidecar callback. But there could be other codecs on the same link that do not have an add_sidecar callback. | 0% Низкий | 9 месяцев назад | ||
GHSA-29v4-3v34-f922 libZetta.rs through 0.1.2 has an integer overflow in the zpool parser (for error stats) that leads to a panic. | CVSS3: 7.5 | 1% Низкий | около 4 лет назад | |
GHSA-29v4-2xqc-8q79 Heap-based buffer overflow in the logi_dj_ll_raw_request function in drivers/hid/hid-logitech-dj.c in the Linux kernel before 3.16.2 allows physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a crafted device that specifies a large report size for an LED report. | 0% Низкий | около 4 лет назад | ||
GHSA-29v3-r4gm-9j2f An issue was discovered on LG mobile devices with Android OS 8.0, 8.1, 9, and 10 software. The network_management service does not properly restrict configuration changes. The LG ID is LVE-SMP-200012 (July 2020). | 0% Низкий | около 4 лет назад | ||
GHSA-29v3-g4cx-hr4v RPM Package Manager 4.0.x through 4.0.2.x allows an attacker to execute arbitrary code via corrupted data in the RPM file when the file is queried. | 1% Низкий | больше 4 лет назад | ||
GHSA-29v2-2jwv-8mvr The LLTD Mapper in Microsoft Windows Vista allows remote attackers to spoof hosts, and nonexistent bridge relationships, into the network topology map by using a MAC address that differs from the MAC address provided in the Real Source field of the LLTD BASE header of a HELLO packet, aka the "Spoof on Bridge" attack. | 11% Средний | около 4 лет назад | ||
GHSA-29rx-mvcf-24fj An issue was discovered on Samsung mobile devices with N(7.1), O(8.x), and P(9.0) (released in China) software. The Firewall application mishandles the PermissionWhiteLists protection mechanism. The Samsung ID is SVE-2019-14299 (November 2019). | 0% Низкий | около 4 лет назад | ||
GHSA-29rx-6x28-gmg7 Stack-based buffer overflow in the IMAP service in NetWin SurgeMail 38k4-4 and earlier allows remote authenticated users to execute arbitrary code via long arguments to the LSUB command. | 6% Низкий | около 4 лет назад |
Уязвимостей на страницу