Количество 353 290
Количество 353 290
GHSA-2452-xqvj-2c63
In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way to trick the victim to grant notification access to the wrong app due to improper input validation. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-228178437
GHSA-2452-6xj8-jh47
Opening a malicious website while running a Nuxt dev server could allow read-only access to code
GHSA-2452-3rwv-x89c
Out-of-bounds write
GHSA-244x-f55f-vxmr
IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 240454.
GHSA-244x-c938-j3qj
Use of hardcoded cryptographic key in BlowFish.cpp in hMailServer 5.8.6 and 5.6.9-beta allows attacker to decrypt passwords used in database connections from hMailServer.ini config file.
GHSA-244w-wm8j-4mcg
An issue in sanTas mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.
GHSA-244w-g82v-mjgw
U-Boot vulnerability resulting in persistent Code Execution
GHSA-244w-39h6-2f5r
Microsoft Message Queuing Denial of Service Vulnerability
GHSA-244v-xghf-wq26
MuPDF through 1.18.1 has an out-of-bounds write because the cached color converter does not properly consider the maximum key size of a hash table. This can, for example, be seen with crafted "mutool draw" input.
GHSA-244v-h48v-v63v
In ihevcd_parse_slice_header of ihevcd_parse_slice_header.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-143826590
GHSA-244r-jx38-mgcg
Adobe After Effects version 18.4.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious WAV file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required in that the victim must open a specially crafted file to exploit this vulnerability.
GHSA-244r-fcj3-ghjq
Exposure of class information in RESTEasy
GHSA-244r-55j9-vqgp
In Progress WS_FTP Server prior to version 8.7.3, multiple reflected cross-site scripting (XSS) vulnerabilities exist in the administrative web interface. It is possible for a remote attacker to inject arbitrary JavaScript into a WS_FTP administrator's web session. This would allow the attacker to execute code within the context of the victim's browser.
GHSA-244r-4cqf-v63r
Improper input validation in UEFI firmware CseVariableStorageSmm for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
GHSA-244q-c67c-j2h7
DLL preloading vulnerability in Autodesk Design Review versions 2011, 2012, 2013, and 2018. An attacker may trick a user into opening a malicious DWF file that may leverage a DLL preloading vulnerability, which may result in code execution.
GHSA-244q-6gfm-pphc
Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect availability, related to Kernel/KSSL.
GHSA-244m-v8jg-hv24
A low privileged local attacker can abuse the affected service by using a hardcoded cryptographic key.
GHSA-244m-98g9-4pg8
The WOOEXIM WordPress plugin through 5.0.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make an unauthenticated user vulnerable to reflected XSS via a CSRF attack.
GHSA-244j-xp9p-xr45
IBM Security Guardium Insights 3.0 could allow an authenticated user to obtain sensitive information due to insufficient session expiration. IBM X-Force ID: 205256.
GHSA-244j-w9pq-ggxp
Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2452-xqvj-2c63 In onCreate of NotificationAccessConfirmationActivity.java, there is a possible way to trick the victim to grant notification access to the wrong app due to improper input validation. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-228178437 | CVSS3: 5.5 | 0% Низкий | почти 4 года назад | |
GHSA-2452-6xj8-jh47 Opening a malicious website while running a Nuxt dev server could allow read-only access to code | CVSS3: 5.3 | 1% Низкий | больше 1 года назад | |
GHSA-2452-3rwv-x89c Out-of-bounds write | CVSS3: 7.5 | 9% Низкий | больше 5 лет назад | |
GHSA-244x-f55f-vxmr IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 240454. | CVSS3: 2.7 | 1% Низкий | почти 3 года назад | |
GHSA-244x-c938-j3qj Use of hardcoded cryptographic key in BlowFish.cpp in hMailServer 5.8.6 and 5.6.9-beta allows attacker to decrypt passwords used in database connections from hMailServer.ini config file. | CVSS3: 4.6 | 0% Низкий | около 1 года назад | |
GHSA-244w-wm8j-4mcg An issue in sanTas mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token. | CVSS3: 5.3 | 1% Низкий | больше 2 лет назад | |
GHSA-244w-g82v-mjgw U-Boot vulnerability resulting in persistent Code Execution | CVSS3: 9.8 | 0% Низкий | больше 2 лет назад | |
GHSA-244w-39h6-2f5r Microsoft Message Queuing Denial of Service Vulnerability | CVSS3: 7.5 | 2% Низкий | почти 3 года назад | |
GHSA-244v-xghf-wq26 MuPDF through 1.18.1 has an out-of-bounds write because the cached color converter does not properly consider the maximum key size of a hash table. This can, for example, be seen with crafted "mutool draw" input. | 1% Низкий | около 4 лет назад | ||
GHSA-244v-h48v-v63v In ihevcd_parse_slice_header of ihevcd_parse_slice_header.c, there is a possible out of bounds write due to an integer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-143826590 | 1% Низкий | около 4 лет назад | ||
GHSA-244r-jx38-mgcg Adobe After Effects version 18.4.1 (and earlier) is affected by a memory corruption vulnerability due to insecure handling of a malicious WAV file, potentially resulting in arbitrary code execution in the context of the current user. User interaction is required in that the victim must open a specially crafted file to exploit this vulnerability. | CVSS3: 7.8 | 2% Низкий | больше 4 лет назад | |
GHSA-244r-fcj3-ghjq Exposure of class information in RESTEasy | CVSS3: 5.3 | 1% Низкий | больше 5 лет назад | |
GHSA-244r-55j9-vqgp In Progress WS_FTP Server prior to version 8.7.3, multiple reflected cross-site scripting (XSS) vulnerabilities exist in the administrative web interface. It is possible for a remote attacker to inject arbitrary JavaScript into a WS_FTP administrator's web session. This would allow the attacker to execute code within the context of the victim's browser. | CVSS3: 6.1 | 1% Низкий | почти 4 года назад | |
GHSA-244r-4cqf-v63r Improper input validation in UEFI firmware CseVariableStorageSmm for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. | CVSS3: 7.5 | 0% Низкий | больше 1 года назад | |
GHSA-244q-c67c-j2h7 DLL preloading vulnerability in Autodesk Design Review versions 2011, 2012, 2013, and 2018. An attacker may trick a user into opening a malicious DWF file that may leverage a DLL preloading vulnerability, which may result in code execution. | 1% Низкий | около 4 лет назад | ||
GHSA-244q-6gfm-pphc Unspecified vulnerability in Oracle Sun Solaris 10 allows remote attackers to affect availability, related to Kernel/KSSL. | 2% Низкий | около 4 лет назад | ||
GHSA-244m-v8jg-hv24 A low privileged local attacker can abuse the affected service by using a hardcoded cryptographic key. | CVSS3: 5.5 | 0% Низкий | 12 месяцев назад | |
GHSA-244m-98g9-4pg8 The WOOEXIM WordPress plugin through 5.0.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make an unauthenticated user vulnerable to reflected XSS via a CSRF attack. | CVSS3: 6.1 | 0% Низкий | около 1 года назад | |
GHSA-244j-xp9p-xr45 IBM Security Guardium Insights 3.0 could allow an authenticated user to obtain sensitive information due to insufficient session expiration. IBM X-Force ID: 205256. | CVSS3: 2.7 | 1% Низкий | больше 4 лет назад | |
GHSA-244j-w9pq-ggxp Heap-based buffer overflow in Microsoft Input Method Editor (IME) allows an authorized attacker to elevate privileges locally. | CVSS3: 8.8 | 0% Низкий | 17 дней назад |
Уязвимостей на страницу