Количество 351 612
Количество 351 612
GHSA-27qm-xvmj-53q7
Multiple directory traversal vulnerabilities in cpCommerce 1.1.0 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the language parameter in a language action to the default URI, which is not properly handled in actions/language.act.php, or (2) the action parameter to category.php.
GHSA-27qm-rh9r-32fx
Cross-site scripting vulnerability in HOTELDRUID 3.0.5 and earlier allows a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the product.
GHSA-27qm-jwxp-8whw
The WP-Polls WordPress plugin before 2.76.0 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based limitations to vote in certain situations.
GHSA-27qm-738j-qww9
In the Linux kernel, the following vulnerability has been resolved: HID: prodikeys: Check presence of pm->input_ep82 Fake USB devices can send their own report descriptors for which the input_mapping() hook does not get called. In this case, pm->input_ep82 stays NULL, which leads to a crash later. This does not happen with the real device, but can be provoked by imposing as one.
GHSA-27qj-9gvp-8rh9
Packetbeat does not properly validate an array index in multiple protocol parser components
GHSA-27qj-3j3m-fj5v
Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same liblumidevsdk.so) uses hard-coded cryptographic keys, which is an instance of "CWE-321: Use of Hard-coded Cryptographic Key" and has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N (9.1 Critical).
GHSA-27qh-whg4-7h58
A buffer overflow vulnerability exists in the setParentalRules interface of TOTOLINK A950RG V4.1.2cu.5204_B20210112. The urlKeyword parameter is not properly validated, and the function concatenates multiple user-controlled fields into a fixed-size stack buffer without performing boundary checks. A remote attacker can exploit this flaw to cause denial of service or potentially achieve arbitrary code execution.
GHSA-27qh-h38r-jf2v
Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the login.php resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL.
GHSA-27qh-8cxx-2cr5
AWS SDK for PHP has CloudFront Policy Document Injection via Special Characters
GHSA-27qh-4m42-f89x
Unknown vulnerability in the eflags checking in the 32-bit ptrace emulation for the Linux kernel on AMD64 systems allows local users to gain privileges.
GHSA-27qg-h9vp-x2xp
HCL DRYiCE MyXalytics product is impacted by unauthenticated file upload vulnerability. The web application permits the upload of a certain file without requiring user authentication.
GHSA-27qg-f2r7-8953
Improper input validation for some Intel(R) PROSet/Wireless WiFi in multiple operating systems and Killer(TM) WiFi in Windows 10 and 11 may allow an authenticated user to potentially enable denial of service via adjacent access.
GHSA-27qf-jwm8-g7f3
FPE in LSH in TFLite
GHSA-27qc-m5gf-jv5r
SiYuan Bazaar marketplace renders unescaped package `name` and `version` metadata, allowing stored XSS and Electron code execution
GHSA-27qc-c946-g657
CUPS on Mandriva Linux 2008.0, 2008.1, 2009.0, Corporate Server (CS) 3.0 and 4.0, and Multi Network Firewall (MNF) 2.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pdf.log temporary file.
GHSA-27qc-3h99-8rcj
Parallels H-Sphere 3.6.2 allows XSS via the index_en.php from parameter.
GHSA-27qc-3c4c-hwfw
Mate 9 with software MHA-AL00AC00B125 has a denial of service (DoS) vulnerability. An attacker tricks a user into installing a malicious application. Since the system does not verify the broadcasting message from the application, it could be exploited to cause some functions of system unavailable.
GHSA-27q9-h529-q4g3
OpenSSH through 9.6, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) because the integer value of authenticated in mm_answer_authpassword does not resist flips of a single bit. NOTE: this is applicable to a certain threat model of attacker-victim co-location in which the attacker has user privileges.
GHSA-27q9-g54w-g6cm
msxlsview.sh in xlsview for catdoc 0.91 and earlier allows local users to overwrite arbitrary files via a symlink attack on predictable temporary file names ("word$$.html").
GHSA-27q8-8p72-c44c
Trend Micro Security (Consumer) 2020 (v16.x) is affected by a vulnerability in where null pointer dereference errors result in the crash of application, which could potentially lead to possible unsigned code execution under certain circumstances.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-27qm-xvmj-53q7 Multiple directory traversal vulnerabilities in cpCommerce 1.1.0 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the language parameter in a language action to the default URI, which is not properly handled in actions/language.act.php, or (2) the action parameter to category.php. | 3% Низкий | около 4 лет назад | ||
GHSA-27qm-rh9r-32fx Cross-site scripting vulnerability in HOTELDRUID 3.0.5 and earlier allows a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the product. | CVSS3: 6.1 | 1% Низкий | больше 2 лет назад | |
GHSA-27qm-jwxp-8whw The WP-Polls WordPress plugin before 2.76.0 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based limitations to vote in certain situations. | CVSS3: 5.3 | 1% Низкий | больше 3 лет назад | |
GHSA-27qm-738j-qww9 In the Linux kernel, the following vulnerability has been resolved: HID: prodikeys: Check presence of pm->input_ep82 Fake USB devices can send their own report descriptors for which the input_mapping() hook does not get called. In this case, pm->input_ep82 stays NULL, which leads to a crash later. This does not happen with the real device, but can be provoked by imposing as one. | CVSS3: 5.5 | 0% Низкий | 3 месяца назад | |
GHSA-27qj-9gvp-8rh9 Packetbeat does not properly validate an array index in multiple protocol parser components | CVSS3: 5.7 | 0% Низкий | 4 месяца назад | |
GHSA-27qj-3j3m-fj5v Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same liblumidevsdk.so) uses hard-coded cryptographic keys, which is an instance of "CWE-321: Use of Hard-coded Cryptographic Key" and has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N (9.1 Critical). | CVSS3: 9.1 | 0% Низкий | около 2 месяцев назад | |
GHSA-27qh-whg4-7h58 A buffer overflow vulnerability exists in the setParentalRules interface of TOTOLINK A950RG V4.1.2cu.5204_B20210112. The urlKeyword parameter is not properly validated, and the function concatenates multiple user-controlled fields into a fixed-size stack buffer without performing boundary checks. A remote attacker can exploit this flaw to cause denial of service or potentially achieve arbitrary code execution. | CVSS3: 9.8 | 0% Низкий | 6 месяцев назад | |
GHSA-27qh-h38r-jf2v Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the login.php resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL. | CVSS3: 6.1 | 0% Низкий | больше 2 лет назад | |
GHSA-27qh-8cxx-2cr5 AWS SDK for PHP has CloudFront Policy Document Injection via Special Characters | 4 месяца назад | |||
GHSA-27qh-4m42-f89x Unknown vulnerability in the eflags checking in the 32-bit ptrace emulation for the Linux kernel on AMD64 systems allows local users to gain privileges. | 0% Низкий | больше 4 лет назад | ||
GHSA-27qg-h9vp-x2xp HCL DRYiCE MyXalytics product is impacted by unauthenticated file upload vulnerability. The web application permits the upload of a certain file without requiring user authentication. | CVSS3: 8.2 | 1% Низкий | больше 2 лет назад | |
GHSA-27qg-f2r7-8953 Improper input validation for some Intel(R) PROSet/Wireless WiFi in multiple operating systems and Killer(TM) WiFi in Windows 10 and 11 may allow an authenticated user to potentially enable denial of service via adjacent access. | CVSS3: 5.7 | 0% Низкий | больше 4 лет назад | |
GHSA-27qf-jwm8-g7f3 FPE in LSH in TFLite | CVSS3: 5.5 | 0% Низкий | почти 5 лет назад | |
GHSA-27qc-m5gf-jv5r SiYuan Bazaar marketplace renders unescaped package `name` and `version` metadata, allowing stored XSS and Electron code execution | CVSS3: 9 | 0% Низкий | 3 месяца назад | |
GHSA-27qc-c946-g657 CUPS on Mandriva Linux 2008.0, 2008.1, 2009.0, Corporate Server (CS) 3.0 and 4.0, and Multi Network Firewall (MNF) 2.0 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pdf.log temporary file. | 0% Низкий | около 4 лет назад | ||
GHSA-27qc-3h99-8rcj Parallels H-Sphere 3.6.2 allows XSS via the index_en.php from parameter. | CVSS3: 6.1 | 2% Низкий | около 4 лет назад | |
GHSA-27qc-3c4c-hwfw Mate 9 with software MHA-AL00AC00B125 has a denial of service (DoS) vulnerability. An attacker tricks a user into installing a malicious application. Since the system does not verify the broadcasting message from the application, it could be exploited to cause some functions of system unavailable. | CVSS3: 3.3 | 0% Низкий | около 4 лет назад | |
GHSA-27q9-h529-q4g3 OpenSSH through 9.6, when common types of DRAM are used, might allow row hammer attacks (for authentication bypass) because the integer value of authenticated in mm_answer_authpassword does not resist flips of a single bit. NOTE: this is applicable to a certain threat model of attacker-victim co-location in which the attacker has user privileges. | CVSS3: 7 | 1% Низкий | больше 2 лет назад | |
GHSA-27q9-g54w-g6cm msxlsview.sh in xlsview for catdoc 0.91 and earlier allows local users to overwrite arbitrary files via a symlink attack on predictable temporary file names ("word$$.html"). | 0% Низкий | больше 4 лет назад | ||
GHSA-27q8-8p72-c44c Trend Micro Security (Consumer) 2020 (v16.x) is affected by a vulnerability in where null pointer dereference errors result in the crash of application, which could potentially lead to possible unsigned code execution under certain circumstances. | 3% Низкий | около 4 лет назад |
Уязвимостей на страницу