Количество 375 727
Количество 375 727
GHSA-38fr-qxq2-m645
In Keysight Geolocation Server v2.4.2 and prior, an attacker could upload a specially crafted malicious file or delete any file or directory with SYSTEM privileges due to an improper path validation, which could result in local privilege escalation or a denial-of-service condition.
GHSA-38fr-fpg3-22rf
ATEN Unizon RpcProvider Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of ATEN Unizon. Authentication is not required to exploit this vulnerability. The specific flaw exists within the RpcProvider class. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-29041.
GHSA-38fr-2xrg-mwqm
The Reolink Desktop Application 8.18.12 contains hardcoded credentials as the Initialization Vector (IV) in its AES-CFB encryption implementation allowing attackers with access to the application environment to reliably decrypt encrypted configuration data.
GHSA-38fq-h5hc-gwv8
Microsoft Security Advisory CVE-2023-36794: .NET Remote Code Execution Vulnerability
GHSA-38fq-722f-5mfp
In the parseURL function of URLStreamHandler, there is improper input validation of the host field. This could lead to a remote elevation of privilege that could enable bypassing user interaction requirements with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68341964.
GHSA-38fp-9j49-g4gm
Attacker is able craft an article with a link to the customer address book with malicious content (JavaScript). When agent opens the link, JavaScript code is executed due to the missing parameter encoding. This issue affects: ((OTRS)) Community Edition: 6.0.26 and prior versions. OTRS: 7.0.15 and prior versions.
GHSA-38fm-xc5v-hgc5
This vulnerability happens in the web client versions 15.3.0 to Serv-U 15.3.1. This vulnerability affects the directory creation function.
GHSA-38fm-hvrq-g6g6
The Woo Custom Emails for WordPress is vulnerable to Reflected Cross-Site Scripting via the wcemails_edit parameter in versions up to, and including, 2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
GHSA-38fm-2h4v-3qf4
Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
GHSA-38fj-36m5-783c
Duplicate Advisory: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access
GHSA-38fh-px4j-r2wx
Mantis 1.0.0rc3 and earlier discloses private bugs via public RSS feeds, which allows remote attackers to obtain sensitive information.
GHSA-38fh-mgpv-6gjj
BadBlue 2.72b and earlier allows remote attackers to obtain sensitive information via an invalid browse parameter, which reveals the installation path in an error message.
GHSA-38fh-7j8c-5f2w
Unspecified vulnerability in the Oracle OLAP component in Oracle Database Server 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, 11.1.0.7, and 11.2.0.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.
GHSA-38fh-5rpq-pxq2
Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
GHSA-38fg-rh2c-fh5c
Unspecified vulnerability in libpng before 1.6.20, as used in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01, allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 23265085.
GHSA-38fc-wpqx-33j7
Uncontrolled Resource Consumption in trim-off-newlines
GHSA-38fc-w9g8-x254
An issue was discovered in GPAC version 0.8.0. There is a NULL pointer dereference in the function gf_isom_get_media_data_size() in isomedia/isom_read.c.
GHSA-38fc-cmwf-cfvc
Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's "href" to the malicious Javascript, then calling execCommand("Refresh") to refresh the page, aka BodyRefreshLoadsJPU or the "ExecCommand Cross Domain" vulnerability.
GHSA-38fc-9xqv-7f7q
SQLAlchemy is vulnerable to SQL Injection via group_by parameter
GHSA-38f9-m297-6q9g
DoS via malicious record IDs in WatermelonDB
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-38fr-qxq2-m645 In Keysight Geolocation Server v2.4.2 and prior, an attacker could upload a specially crafted malicious file or delete any file or directory with SYSTEM privileges due to an improper path validation, which could result in local privilege escalation or a denial-of-service condition. | CVSS3: 7.8 | 0% Низкий | около 3 лет назад | |
GHSA-38fr-fpg3-22rf ATEN Unizon RpcProvider Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of ATEN Unizon. Authentication is not required to exploit this vulnerability. The specific flaw exists within the RpcProvider class. The issue results from the lack of authentication prior to allowing access to functionality. An attacker can leverage this vulnerability to create a denial-of-service condition on the system. Was ZDI-CAN-29041. | CVSS3: 7.5 | 0% Низкий | около 2 месяцев назад | |
GHSA-38fr-2xrg-mwqm The Reolink Desktop Application 8.18.12 contains hardcoded credentials as the Initialization Vector (IV) in its AES-CFB encryption implementation allowing attackers with access to the application environment to reliably decrypt encrypted configuration data. | CVSS3: 5.1 | 0% Низкий | 11 месяцев назад | |
GHSA-38fq-h5hc-gwv8 Microsoft Security Advisory CVE-2023-36794: .NET Remote Code Execution Vulnerability | CVSS3: 7.8 | 1% Низкий | около 3 лет назад | |
GHSA-38fq-722f-5mfp In the parseURL function of URLStreamHandler, there is improper input validation of the host field. This could lead to a remote elevation of privilege that could enable bypassing user interaction requirements with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-68341964. | CVSS3: 8.8 | 1% Низкий | больше 4 лет назад | |
GHSA-38fp-9j49-g4gm Attacker is able craft an article with a link to the customer address book with malicious content (JavaScript). When agent opens the link, JavaScript code is executed due to the missing parameter encoding. This issue affects: ((OTRS)) Community Edition: 6.0.26 and prior versions. OTRS: 7.0.15 and prior versions. | CVSS3: 5.4 | 1% Низкий | больше 4 лет назад | |
GHSA-38fm-xc5v-hgc5 This vulnerability happens in the web client versions 15.3.0 to Serv-U 15.3.1. This vulnerability affects the directory creation function. | CVSS3: 5.4 | 1% Низкий | почти 4 года назад | |
GHSA-38fm-hvrq-g6g6 The Woo Custom Emails for WordPress is vulnerable to Reflected Cross-Site Scripting via the wcemails_edit parameter in versions up to, and including, 2.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. | CVSS3: 6.1 | 0% Низкий | около 3 лет назад | |
GHSA-38fm-2h4v-3qf4 Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability | CVSS3: 6.2 | 1% Низкий | почти 3 года назад | |
GHSA-38fj-36m5-783c Duplicate Advisory: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access | 2 месяца назад | |||
GHSA-38fh-px4j-r2wx Mantis 1.0.0rc3 and earlier discloses private bugs via public RSS feeds, which allows remote attackers to obtain sensitive information. | 2% Низкий | больше 4 лет назад | ||
GHSA-38fh-mgpv-6gjj BadBlue 2.72b and earlier allows remote attackers to obtain sensitive information via an invalid browse parameter, which reveals the installation path in an error message. | 3% Низкий | больше 4 лет назад | ||
GHSA-38fh-7j8c-5f2w Unspecified vulnerability in the Oracle OLAP component in Oracle Database Server 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, 11.1.0.7, and 11.2.0.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors. | 1% Низкий | больше 4 лет назад | ||
GHSA-38fh-5rpq-pxq2 Buffer over-read can happen while parsing received SDP values due to lack of NULL termination check on SDP in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables | 1% Низкий | больше 4 лет назад | ||
GHSA-38fg-rh2c-fh5c Unspecified vulnerability in libpng before 1.6.20, as used in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01, allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 23265085. | CVSS3: 7.8 | 1% Низкий | больше 4 лет назад | |
GHSA-38fc-wpqx-33j7 Uncontrolled Resource Consumption in trim-off-newlines | CVSS3: 5.3 | 2% Низкий | около 5 лет назад | |
GHSA-38fc-w9g8-x254 An issue was discovered in GPAC version 0.8.0. There is a NULL pointer dereference in the function gf_isom_get_media_data_size() in isomedia/isom_read.c. | 1% Низкий | больше 4 лет назад | ||
GHSA-38fc-cmwf-cfvc Internet Explorer 6 SP1 and earlier allows remote attackers to bypass zone restrictions and execute Javascript by setting the window's "href" to the malicious Javascript, then calling execCommand("Refresh") to refresh the page, aka BodyRefreshLoadsJPU or the "ExecCommand Cross Domain" vulnerability. | 28% Средний | больше 4 лет назад | ||
GHSA-38fc-9xqv-7f7q SQLAlchemy is vulnerable to SQL Injection via group_by parameter | CVSS3: 7.8 | 2% Низкий | больше 7 лет назад | |
GHSA-38f9-m297-6q9g DoS via malicious record IDs in WatermelonDB | CVSS3: 5.9 | 1% Низкий | больше 6 лет назад |
Уязвимостей на страницу