Количество 353 269
Количество 353 269
GHSA-26qq-9jw6-r5h4
Intesync Solismed 3.3sp has Incorrect Access Control.
GHSA-26qp-ffjh-2x4v
ImageMagick has an integer overflow in despeckle operation causing a heap buffer overflow on 32-bit builds
GHSA-26qp-7xwg-8f45
Cross-site scripting (XSS) vulnerability in PHP-Fusion 9.
GHSA-26qm-jcfr-w44c
Double free vulnerability in Microsoft Word 2002 SP3 allows remote attackers to execute arbitrary code via a Word document with crafted List Format Override (LFO) records, aka "Word Pointer Vulnerability."
GHSA-26qm-2594-mccv
Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert (RTC) 2.0.0.x allows remote authenticated users to inject arbitrary web script or HTML via the name of a shared report.
GHSA-26qj-cr27-r5c4
Octopoller gem published with world-writable files
GHSA-26qj-5g3c-qwm4
Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier). If this vulnerability is exploited, arbitrary files may be viewed by a remote unauthenticated attacker.
GHSA-26qh-mgjw-5hg7
D-link DIR-816 A2 v1.10 is affected by a remote code injection vulnerability. An HTTP request parameter can be used in command string construction in the handler function of the /goform/dir_setWanWifi, which can lead to command injection via shell metacharacters in the statuscheckpppoeuser parameter.
GHSA-26qg-wc7f-8867
net/ipv4/tcp_input.c in the Linux kernel before 4.7 does not properly determine the rate of challenge ACK segments, which makes it easier for remote attackers to hijack TCP sessions via a blind in-window attack.
GHSA-26qg-4hpq-vwx9
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 131853.
GHSA-26qf-c8f8-mrg9
In vcu, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07203500; Issue ID: ALPS07203500.
GHSA-26qf-34q8-32jq
Multiple cross-site scripting (XSS) vulnerabilities in the Virtual War (VWar) 1.5.0 R15 and earlier module for PHP-Nuke, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) memberlist parameter to extra/login.php and the (2) title parameter to extra/today.php.
GHSA-26qf-2r89-746r
Unrestricted Upload of File with Dangerous Type vulnerability in Shafiq Digital Lottery allows Upload a Web Shell to a Web Server.This issue affects Digital Lottery: from n/a through 3.0.5.
GHSA-26qc-f6w8-8qqq
Untrusted search path vulnerability in Adobe On Location CS4 Build 315 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse ibfs32.dll that is located in the same folder as an OLPROJ file.
GHSA-26qc-7vc3-c96r
The next parameter in the /accounts/login endpoint of Seafile 9.0.6 allows attackers to redirect users to arbitrary sites.
GHSA-26q9-c8pg-577f
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop 16.6.3.84. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DWF files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-12717.
GHSA-26q9-4p72-922v
Unspecified vulnerability in the Mobile Server component in Oracle Database Mobile/Lite Server (formerly Oracle Database Lite) 10.3.0.3 and 11.1.0.0 allows remote attackers to affect confidentiality via unknown vectors, a different vulnerability than CVE-2013-0363 and CVE-2013-0364.
GHSA-26q9-378g-g2f7
Improper Certificate Validation in FotaAgent prior to SMR Nov-2023 Release1 allows remote attacker to intercept the network traffic including Firmware information.
GHSA-26q8-whgc-65w9
gpu/blink/webgraphicscontext3d_impl.cc in the WebGL implementation in Google Chrome before 42.0.2311.90 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WebGL program that triggers a state inconsistency.
GHSA-26q8-4547-5jf2
Buffer overflow in the XDMCP parsing code of GNOME gdm, KDE kdm, and wdm allows remote attackers to execute arbitrary commands or cause a denial of service via a long FORWARD_QUERY request.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-26qq-9jw6-r5h4 Intesync Solismed 3.3sp has Incorrect Access Control. | 2% Низкий | около 4 лет назад | ||
GHSA-26qp-ffjh-2x4v ImageMagick has an integer overflow in despeckle operation causing a heap buffer overflow on 32-bit builds | CVSS3: 5.1 | 0% Низкий | 4 месяца назад | |
GHSA-26qp-7xwg-8f45 Cross-site scripting (XSS) vulnerability in PHP-Fusion 9. | CVSS3: 5.4 | 1% Низкий | около 4 лет назад | |
GHSA-26qm-jcfr-w44c Double free vulnerability in Microsoft Word 2002 SP3 allows remote attackers to execute arbitrary code via a Word document with crafted List Format Override (LFO) records, aka "Word Pointer Vulnerability." | 40% Средний | около 4 лет назад | ||
GHSA-26qm-2594-mccv Cross-site scripting (XSS) vulnerability in IBM Rational Team Concert (RTC) 2.0.0.x allows remote authenticated users to inject arbitrary web script or HTML via the name of a shared report. | 1% Низкий | около 4 лет назад | ||
GHSA-26qj-cr27-r5c4 Octopoller gem published with world-writable files | CVSS3: 2.5 | 0% Низкий | около 4 лет назад | |
GHSA-26qj-5g3c-qwm4 Improper limitation of a pathname to a restricted directory ('Path Traversal') issue exists in SS1 Ver.16.0.0.10 and earlier (Media version:16.0.0a and earlier). If this vulnerability is exploited, arbitrary files may be viewed by a remote unauthenticated attacker. | CVSS3: 7.5 | 1% Низкий | 11 месяцев назад | |
GHSA-26qh-mgjw-5hg7 D-link DIR-816 A2 v1.10 is affected by a remote code injection vulnerability. An HTTP request parameter can be used in command string construction in the handler function of the /goform/dir_setWanWifi, which can lead to command injection via shell metacharacters in the statuscheckpppoeuser parameter. | CVSS3: 9.8 | 5% Низкий | около 4 лет назад | |
GHSA-26qg-wc7f-8867 net/ipv4/tcp_input.c in the Linux kernel before 4.7 does not properly determine the rate of challenge ACK segments, which makes it easier for remote attackers to hijack TCP sessions via a blind in-window attack. | CVSS3: 4.8 | 15% Средний | около 4 лет назад | |
GHSA-26qg-4hpq-vwx9 IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 131853. | CVSS3: 5.5 | 0% Низкий | около 4 лет назад | |
GHSA-26qf-c8f8-mrg9 In vcu, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07203500; Issue ID: ALPS07203500. | CVSS3: 6.4 | 0% Низкий | больше 3 лет назад | |
GHSA-26qf-34q8-32jq Multiple cross-site scripting (XSS) vulnerabilities in the Virtual War (VWar) 1.5.0 R15 and earlier module for PHP-Nuke, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) memberlist parameter to extra/login.php and the (2) title parameter to extra/today.php. | 1% Низкий | около 4 лет назад | ||
GHSA-26qf-2r89-746r Unrestricted Upload of File with Dangerous Type vulnerability in Shafiq Digital Lottery allows Upload a Web Shell to a Web Server.This issue affects Digital Lottery: from n/a through 3.0.5. | CVSS3: 10 | 1% Низкий | почти 2 года назад | |
GHSA-26qc-f6w8-8qqq Untrusted search path vulnerability in Adobe On Location CS4 Build 315 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse ibfs32.dll that is located in the same folder as an OLPROJ file. | 15% Средний | около 4 лет назад | ||
GHSA-26qc-7vc3-c96r The next parameter in the /accounts/login endpoint of Seafile 9.0.6 allows attackers to redirect users to arbitrary sites. | CVSS3: 6.1 | 0% Низкий | больше 2 лет назад | |
GHSA-26q9-c8pg-577f This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenText Brava! Desktop 16.6.3.84. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DWF files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-12717. | CVSS3: 7.8 | 1% Низкий | около 4 лет назад | |
GHSA-26q9-4p72-922v Unspecified vulnerability in the Mobile Server component in Oracle Database Mobile/Lite Server (formerly Oracle Database Lite) 10.3.0.3 and 11.1.0.0 allows remote attackers to affect confidentiality via unknown vectors, a different vulnerability than CVE-2013-0363 and CVE-2013-0364. | 1% Низкий | около 4 лет назад | ||
GHSA-26q9-378g-g2f7 Improper Certificate Validation in FotaAgent prior to SMR Nov-2023 Release1 allows remote attacker to intercept the network traffic including Firmware information. | CVSS3: 7.5 | 0% Низкий | больше 2 лет назад | |
GHSA-26q8-whgc-65w9 gpu/blink/webgraphicscontext3d_impl.cc in the WebGL implementation in Google Chrome before 42.0.2311.90 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted WebGL program that triggers a state inconsistency. | 1% Низкий | около 4 лет назад | ||
GHSA-26q8-4547-5jf2 Buffer overflow in the XDMCP parsing code of GNOME gdm, KDE kdm, and wdm allows remote attackers to execute arbitrary commands or cause a denial of service via a long FORWARD_QUERY request. | 18% Средний | около 4 лет назад |
Уязвимостей на страницу