Количество 353 269
Количество 353 269
GHSA-2563-r73r-7cq9
Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function setUploadSetting, via the FileName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
GHSA-2563-fp9c-mgm8
Moodle Session Fixation vulnerability
GHSA-2563-9f8c-7cw3
PHP remote file inclusion vulnerability in includes/functions_portal.php in IntegraMOD Portal 2.x and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.
GHSA-2563-83p7-f34p
Malicious Package in requestt
GHSA-255x-mvhm-3947
The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<math xlink:href=" attack.
GHSA-255w-8g7g-qmg6
In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix race condition during IPSec ESN update In IPSec full offload mode, the device reports an ESN (Extended Sequence Number) wrap event to the driver. The driver validates this event by querying the IPSec ASO and checking that the esn_event_arm field is 0x0, which indicates an event has occurred. After handling the event, the driver must re-arm the context by setting esn_event_arm back to 0x1. A race condition exists in this handling path. After validating the event, the driver calls mlx5_accel_esp_modify_xfrm() to update the kernel's xfrm state. This function temporarily releases and re-acquires the xfrm state lock. So, need to acknowledge the event first by setting esn_event_arm to 0x1. This prevents the driver from reprocessing the same ESN update if the hardware sends events for other reason. Since the next ESN update only occurs after nearly 2^31 packets are received, there's no risk of missing an...
GHSA-255w-87rh-rg44
Cross-site Scripting via uploaded SVG
GHSA-255w-3rfx-h4rv
Inappropriate implementation in V8 in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)
GHSA-255v-qv84-29p5
DragonFly's manager generates mTLS certificates for arbitrary IP addresses
GHSA-255v-qpcm-wc95
Multiple stored cross site scripting (XSS) vulnerabilities in the "Register" module of House Rental and Property Listing 1.0 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads in all text fields except for Phone Number and Alternate Phone Number.
GHSA-255v-hc9m-54wv
Missing Authorization vulnerability in merkulove Laser laser allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Laser: from n/a through <= 1.1.1.
GHSA-255v-grg6-24pg
MotoCMS Version 3.4.3 Store Category Template was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the keyword parameter.
GHSA-255v-ffqg-5w87
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/?page=appointments/view_appointment.
GHSA-255r-pghp-r5wh
Malicious Package in hdeky
GHSA-255r-f4p7-p9r5
Hacksoft The Hacker 6.3.1.2.174 and possibly 6.3.0.9.081, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
GHSA-255r-96jc-w7r6
DVP80ES300T with Improper Validation of Array Index Vulnerability
GHSA-255r-3prx-mf99
`rmp-serde` `Raw` and `RawRef` may crash when receiving invalid UTF-8
GHSA-255q-f9p7-jxj6
Microsoft SharePoint Server Spoofing Vulnerability
GHSA-255p-hfwr-9qm4
This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.4. An app with root privileges may be able to access private information.
GHSA-255p-hfc6-whjx
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14021.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2563-r73r-7cq9 Totolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.5185_B20201128, and A810R V4.1.2cu.5182_B20201026 were discovered to contain a command injection vulnerability in the function setUploadSetting, via the FileName parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request. | CVSS3: 9.8 | 2% Низкий | больше 4 лет назад | |
GHSA-2563-fp9c-mgm8 Moodle Session Fixation vulnerability | CVSS3: 9.8 | 7% Низкий | больше 3 лет назад | |
GHSA-2563-9f8c-7cw3 PHP remote file inclusion vulnerability in includes/functions_portal.php in IntegraMOD Portal 2.x and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | 3% Низкий | около 4 лет назад | ||
GHSA-2563-83p7-f34p Malicious Package in requestt | CVSS3: 9.8 | почти 6 лет назад | ||
GHSA-255x-mvhm-3947 The mail message display page in SquirrelMail through 1.4.22 has XSS via a "<math xlink:href=" attack. | CVSS3: 6.1 | 1% Низкий | около 4 лет назад | |
GHSA-255w-8g7g-qmg6 In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: Fix race condition during IPSec ESN update In IPSec full offload mode, the device reports an ESN (Extended Sequence Number) wrap event to the driver. The driver validates this event by querying the IPSec ASO and checking that the esn_event_arm field is 0x0, which indicates an event has occurred. After handling the event, the driver must re-arm the context by setting esn_event_arm back to 0x1. A race condition exists in this handling path. After validating the event, the driver calls mlx5_accel_esp_modify_xfrm() to update the kernel's xfrm state. This function temporarily releases and re-acquires the xfrm state lock. So, need to acknowledge the event first by setting esn_event_arm to 0x1. This prevents the driver from reprocessing the same ESN update if the hardware sends events for other reason. Since the next ESN update only occurs after nearly 2^31 packets are received, there's no risk of missing an... | CVSS3: 4.7 | 0% Низкий | 4 месяца назад | |
GHSA-255w-87rh-rg44 Cross-site Scripting via uploaded SVG | CVSS3: 6.1 | 0% Низкий | почти 2 года назад | |
GHSA-255w-3rfx-h4rv Inappropriate implementation in V8 in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low) | CVSS3: 4.3 | 0% Низкий | 3 месяца назад | |
GHSA-255v-qv84-29p5 DragonFly's manager generates mTLS certificates for arbitrary IP addresses | 0% Низкий | 11 месяцев назад | ||
GHSA-255v-qpcm-wc95 Multiple stored cross site scripting (XSS) vulnerabilities in the "Register" module of House Rental and Property Listing 1.0 allows authenticated attackers to execute arbitrary web scripts or HTML via crafted payloads in all text fields except for Phone Number and Alternate Phone Number. | 1% Низкий | около 4 лет назад | ||
GHSA-255v-hc9m-54wv Missing Authorization vulnerability in merkulove Laser laser allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Laser: from n/a through <= 1.1.1. | CVSS3: 5.4 | 0% Низкий | 8 месяцев назад | |
GHSA-255v-grg6-24pg MotoCMS Version 3.4.3 Store Category Template was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the keyword parameter. | CVSS3: 9.8 | 29% Средний | почти 3 года назад | |
GHSA-255v-ffqg-5w87 Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/?page=appointments/view_appointment. | CVSS3: 8.8 | 1% Низкий | больше 3 лет назад | |
GHSA-255r-pghp-r5wh Malicious Package in hdeky | CVSS3: 9.1 | почти 6 лет назад | ||
GHSA-255r-f4p7-p9r5 Hacksoft The Hacker 6.3.1.2.174 and possibly 6.3.0.9.081, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit. | 2% Низкий | около 4 лет назад | ||
GHSA-255r-96jc-w7r6 DVP80ES300T with Improper Validation of Array Index Vulnerability | CVSS3: 7.5 | 0% Низкий | 30 дней назад | |
GHSA-255r-3prx-mf99 `rmp-serde` `Raw` and `RawRef` may crash when receiving invalid UTF-8 | больше 3 лет назад | |||
GHSA-255q-f9p7-jxj6 Microsoft SharePoint Server Spoofing Vulnerability | CVSS3: 8 | 2% Низкий | почти 3 года назад | |
GHSA-255p-hfwr-9qm4 This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.4. An app with root privileges may be able to access private information. | CVSS3: 4.4 | 0% Низкий | почти 4 года назад | |
GHSA-255p-hfc6-whjx This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14021. | 4% Низкий | около 4 лет назад |
Уязвимостей на страницу