Количество 353 269
Количество 353 269
GHSA-254j-mmc5-qhpx
Smashing Cross-site Scripting vulnerability
GHSA-254j-3m2w-23xr
Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to install arbitrary extensions by using interactive events to manipulate the XPInstall Security dialog box.
GHSA-254h-gvgq-x2xg
An issue was discovered in GitLab-EE starting with version 13.3 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2 that would allow an attacker to modify an on-demand DAST scan without permissions and leak variables.
GHSA-254g-wcpq-w26f
HCL Aftermarket DPC is affected by Cross-Origin Resource Sharing vulnerability. CORS misconfigurations includes the exposure of sensitive user information to attackers, unauthorized access to APIs, and possible data manipulation or leakage. If an attacker to exploit CORS misconfiguration, they could steal sensitive data, perform actions on behalf of a legitimate user.
GHSA-254g-h6q6-4fxv
Abuse 2.00 and earlier allows local users to gain privileges via command line arguments that specify alternate Lisp scripts that run at escalated privileges, which can contain functions that execute commands or modify files.
GHSA-254f-jwvx-j47x
Multiple cross-site scripting (XSS) vulnerabilities in index_search.php in 2daybiz Polls (aka Advanced Poll) Script allow remote attackers to inject arbitrary web script or HTML via the (1) category parameter or (2) search field.
GHSA-254f-c2wq-r664
IBM Security Guardium 11.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 195569.
GHSA-254c-893v-cfqr
Integer overflow or wraparound in HID class driver allows an authorized attacker to elevate privileges locally.
GHSA-254c-2j77-4hhm
IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14 could allow a remote attacker to gain details of the database, such as type and version, by sending a specially-crafted HTTP request. This information could then be used in future attacks. IBM X-Force ID: 226940.
GHSA-2549-xh72-qrpm
Mattermost Improper Validation of Specified Type of Input vulnerability
GHSA-2549-r7rv-9g8p
Information disclosure
GHSA-2549-f94w-jg6h
Cross-site scripting (XSS) vulnerability in Telerik.ReportViewer.WebForms.dll in Telerik Reporting for ASP.NET WebForms Report Viewer control before R1 2017 SP2 (11.0.17.406) allows remote attackers to inject arbitrary web script or HTML via the bgColor parameter to Telerik.ReportViewer.axd.
GHSA-2548-xwx6-3r34
A stack-based buffer overflow vulnerability exists in the LXT2 lxt2_rd_expand_integer_to_bits function of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability.
GHSA-2548-q746-x5x6
Code injection in port-killer
GHSA-2548-2rfq-335j
An issue was discovered in prog.cgi on D-Link DIR-878 1.30B08 devices. Because strcat is misused, there is a stack-based buffer overflow that does not require authentication.
GHSA-2547-59jc-hhfr
Deserialization of untrusted data issue exists in BizRobo! all versions. If this vulnerability is exploited, an arbitrary code is executed on the Management Console. The vendor provides the workaround information and recommends to apply it to the deployment environment.
GHSA-2546-h2cp-j8x8
An elevation of privilege vulnerability in the MediaTek thermal driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: N/A. Android ID: A-28175767. References: M-ALPS02696445.
GHSA-2546-c9vw-hgfw
A missing cryptographic steps vulnerability [CWE-325] in the functions that encrypt the keytab files in FortiOS version 7.2.0, 7.0.0 through 7.0.5 and below 7.0.0 may allow an attacker in possession of the encrypted file to decipher it.
GHSA-2546-8f75-8pq5
An issue was discovered in the Linux kernel before 5.0.9. There is a use-after-free in atalk_proc_exit, related to net/appletalk/atalk_proc.c, net/appletalk/ddp.c, and net/appletalk/sysctl_net_atalk.c.
GHSA-2546-6vr9-845q
PHP remote file inclusion vulnerability in usercp_menu.php in AR Memberscript allows remote attackers to execute arbitrary PHP code via a URL in the script_folder parameter.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-254j-mmc5-qhpx Smashing Cross-site Scripting vulnerability | CVSS3: 6.1 | 1% Низкий | около 4 лет назад | |
GHSA-254j-3m2w-23xr Mozilla before 1.7, Firefox before 0.9, and Thunderbird before 0.7, allow remote web sites to install arbitrary extensions by using interactive events to manipulate the XPInstall Security dialog box. | 2% Низкий | около 4 лет назад | ||
GHSA-254h-gvgq-x2xg An issue was discovered in GitLab-EE starting with version 13.3 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2 that would allow an attacker to modify an on-demand DAST scan without permissions and leak variables. | CVSS3: 5.3 | 0% Низкий | почти 2 года назад | |
GHSA-254g-wcpq-w26f HCL Aftermarket DPC is affected by Cross-Origin Resource Sharing vulnerability. CORS misconfigurations includes the exposure of sensitive user information to attackers, unauthorized access to APIs, and possible data manipulation or leakage. If an attacker to exploit CORS misconfiguration, they could steal sensitive data, perform actions on behalf of a legitimate user. | CVSS3: 2.6 | 0% Низкий | 4 месяца назад | |
GHSA-254g-h6q6-4fxv Abuse 2.00 and earlier allows local users to gain privileges via command line arguments that specify alternate Lisp scripts that run at escalated privileges, which can contain functions that execute commands or modify files. | 1% Низкий | больше 4 лет назад | ||
GHSA-254f-jwvx-j47x Multiple cross-site scripting (XSS) vulnerabilities in index_search.php in 2daybiz Polls (aka Advanced Poll) Script allow remote attackers to inject arbitrary web script or HTML via the (1) category parameter or (2) search field. | 2% Низкий | около 4 лет назад | ||
GHSA-254f-c2wq-r664 IBM Security Guardium 11.3 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 195569. | 1% Низкий | около 4 лет назад | ||
GHSA-254c-893v-cfqr Integer overflow or wraparound in HID class driver allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | около 1 года назад | |
GHSA-254c-2j77-4hhm IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14 could allow a remote attacker to gain details of the database, such as type and version, by sending a specially-crafted HTTP request. This information could then be used in future attacks. IBM X-Force ID: 226940. | CVSS3: 5.3 | 1% Низкий | около 4 лет назад | |
GHSA-2549-xh72-qrpm Mattermost Improper Validation of Specified Type of Input vulnerability | CVSS3: 4.3 | 1% Низкий | больше 1 года назад | |
GHSA-2549-r7rv-9g8p Information disclosure | CVSS3: 7.5 | 0% Низкий | больше 2 лет назад | |
GHSA-2549-f94w-jg6h Cross-site scripting (XSS) vulnerability in Telerik.ReportViewer.WebForms.dll in Telerik Reporting for ASP.NET WebForms Report Viewer control before R1 2017 SP2 (11.0.17.406) allows remote attackers to inject arbitrary web script or HTML via the bgColor parameter to Telerik.ReportViewer.axd. | CVSS3: 6.1 | 10% Низкий | около 4 лет назад | |
GHSA-2548-xwx6-3r34 A stack-based buffer overflow vulnerability exists in the LXT2 lxt2_rd_expand_integer_to_bits function of GTKWave 3.3.115. A specially crafted .lxt2 file can lead to arbitrary code execution. A victim would need to open a malicious file to trigger this vulnerability. | CVSS3: 7.8 | 0% Низкий | больше 2 лет назад | |
GHSA-2548-q746-x5x6 Code injection in port-killer | CVSS3: 7.5 | 2% Низкий | больше 5 лет назад | |
GHSA-2548-2rfq-335j An issue was discovered in prog.cgi on D-Link DIR-878 1.30B08 devices. Because strcat is misused, there is a stack-based buffer overflow that does not require authentication. | 1% Низкий | около 4 лет назад | ||
GHSA-2547-59jc-hhfr Deserialization of untrusted data issue exists in BizRobo! all versions. If this vulnerability is exploited, an arbitrary code is executed on the Management Console. The vendor provides the workaround information and recommends to apply it to the deployment environment. | CVSS3: 8.8 | 1% Низкий | больше 1 года назад | |
GHSA-2546-h2cp-j8x8 An elevation of privilege vulnerability in the MediaTek thermal driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: N/A. Android ID: A-28175767. References: M-ALPS02696445. | CVSS3: 7 | 1% Низкий | около 4 лет назад | |
GHSA-2546-c9vw-hgfw A missing cryptographic steps vulnerability [CWE-325] in the functions that encrypt the keytab files in FortiOS version 7.2.0, 7.0.0 through 7.0.5 and below 7.0.0 may allow an attacker in possession of the encrypted file to decipher it. | CVSS3: 3.3 | 0% Низкий | почти 4 года назад | |
GHSA-2546-8f75-8pq5 An issue was discovered in the Linux kernel before 5.0.9. There is a use-after-free in atalk_proc_exit, related to net/appletalk/atalk_proc.c, net/appletalk/ddp.c, and net/appletalk/sysctl_net_atalk.c. | CVSS3: 9.8 | 3% Низкий | около 4 лет назад | |
GHSA-2546-6vr9-845q PHP remote file inclusion vulnerability in usercp_menu.php in AR Memberscript allows remote attackers to execute arbitrary PHP code via a URL in the script_folder parameter. | 2% Низкий | около 4 лет назад |
Уязвимостей на страницу