Количество 375 453
Количество 375 453
GHSA-3725-x3x8-r7jq
The Platform Service Process (asampsp) in Fan-Out Driver Platform Services for Novell Identity Manager (IDM) 3.5.1 allows remote attackers to cause a denial of service (daemon crash) via unspecified network traffic that triggers a syslog message containing invalid format string specifiers, as demonstrated by a Nessus scan.
GHSA-3724-xmqw-2wwv
Zulip Server before 2.1.3 allows XSS via the modal_link feature in the Markdown functionality.
GHSA-3724-qc3c-8gr9
In all Android releases from CAF using the Linux kernel, a kernel driver has an off-by-one buffer over-read vulnerability.
GHSA-3724-q3rh-j82p
A Path Traversal issue was discovered in Advantech WebAccess/SCADA versions prior to V8.2_20170817. An attacker has read access to files within the directory structure of the target device.
GHSA-3724-jcfq-mvfc
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Miguel Peixe WP Feature Box allows Stored XSS.This issue affects WP Feature Box: from n/a through 0.1.3.
GHSA-3724-4mmc-j59x
NoMachine Enterprise Desktop is affected by Buffer Overflow. IOCTL Handler 0x22001B in the NoMachine Enterprise Desktop above 4.0.346 and below 7.7.4 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet.
GHSA-3723-f7xr-2xgj
WeGIA < 3.2.0 is vulnerable to Incorrect Access Control in controle/control.php. The application does not validate the value of the old password, so it is possible to change the password by placing any value in the senha_antiga field.
GHSA-36xx-949x-639g
In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw-edma: Initialize IRQ data before requesting IRQs dw_edma_irq_request() passes struct dw_edma_irq to request_irq() before dw_edma_channel_setup() fills the back pointer. A shared interrupt can therefore enter the handler with dw_irq->dw still NULL, leading to a NULL pointer dereference. Set the back pointer before installing each handler.
GHSA-36xx-7vf6-7mv3
Silverstripe Framework: Members with no password can be created and bypass custom login forms
GHSA-36xw-xp2j-w52g
Directory traversal vulnerability in index.php in BNCwi 1.04 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the newlanguage parameter.
GHSA-36xw-wj35-w3q4
A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data.
GHSA-36xw-hgfv-jwm7
Multiple security issues including data race, buffer overflow, and uninitialized memory drop in arr
GHSA-36xw-fx78-c5r4
containerd-shim API Exposed to Host Network Containers
GHSA-36xv-rp4j-w277
Memory leak in eServ 2.9x allows remote attackers to cause a denial of service (memory exhaustion) via a large number of connections, whose memory is not freed when the connection is terminated.
GHSA-36xv-jgw5-4q75
@nestjs/core Improperly Neutralizes Special Elements in Output Used by a Downstream Component ('Injection')
GHSA-36xv-45pm-m623
Microsoft Publisher 2003 SP3, and 2007 SP2 and SP3, does not properly manage memory allocations for function pointers, which allows user-assisted remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Function Pointer Overwrite Vulnerability."
GHSA-36xv-3m2q-wwfm
The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'width' Shortcode Attribute in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
GHSA-36xr-hxmp-hqwm
Mutt mail client allows a remote attacker to execute commands via shell metacharacters.
GHSA-36xr-8q52-r359
A vulnerability was found in xujeff tianti 天梯 up to 2.3. It has been rated as problematic. This issue affects the function exportOrder of the file /tianti-module-admin/user/ajax/save of the component com.jeff.tianti.controller. The manipulation leads to csv injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
GHSA-36xr-52f8-hmpq
Gadu-Gadu build 155 and earlier allows remote attackers to cause a denial of service (infinite loop) via a message that contains an image whose filename does not start with restricted characters.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3725-x3x8-r7jq The Platform Service Process (asampsp) in Fan-Out Driver Platform Services for Novell Identity Manager (IDM) 3.5.1 allows remote attackers to cause a denial of service (daemon crash) via unspecified network traffic that triggers a syslog message containing invalid format string specifiers, as demonstrated by a Nessus scan. | 2% Низкий | больше 4 лет назад | ||
GHSA-3724-xmqw-2wwv Zulip Server before 2.1.3 allows XSS via the modal_link feature in the Markdown functionality. | 1% Низкий | больше 4 лет назад | ||
GHSA-3724-qc3c-8gr9 In all Android releases from CAF using the Linux kernel, a kernel driver has an off-by-one buffer over-read vulnerability. | CVSS3: 7.8 | 1% Низкий | больше 4 лет назад | |
GHSA-3724-q3rh-j82p A Path Traversal issue was discovered in Advantech WebAccess/SCADA versions prior to V8.2_20170817. An attacker has read access to files within the directory structure of the target device. | CVSS3: 5.3 | 2% Низкий | больше 4 лет назад | |
GHSA-3724-jcfq-mvfc Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Miguel Peixe WP Feature Box allows Stored XSS.This issue affects WP Feature Box: from n/a through 0.1.3. | CVSS3: 6.5 | 0% Низкий | почти 2 года назад | |
GHSA-3724-4mmc-j59x NoMachine Enterprise Desktop is affected by Buffer Overflow. IOCTL Handler 0x22001B in the NoMachine Enterprise Desktop above 4.0.346 and below 7.7.4 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet. | 0% Низкий | почти 5 лет назад | ||
GHSA-3723-f7xr-2xgj WeGIA < 3.2.0 is vulnerable to Incorrect Access Control in controle/control.php. The application does not validate the value of the old password, so it is possible to change the password by placing any value in the senha_antiga field. | CVSS3: 9.8 | 1% Низкий | больше 1 года назад | |
GHSA-36xx-949x-639g In the Linux kernel, the following vulnerability has been resolved: dmaengine: dw-edma: Initialize IRQ data before requesting IRQs dw_edma_irq_request() passes struct dw_edma_irq to request_irq() before dw_edma_channel_setup() fills the back pointer. A shared interrupt can therefore enter the handler with dw_irq->dw still NULL, leading to a NULL pointer dereference. Set the back pointer before installing each handler. | 0% Низкий | 5 дней назад | ||
GHSA-36xx-7vf6-7mv3 Silverstripe Framework: Members with no password can be created and bypass custom login forms | около 3 лет назад | |||
GHSA-36xw-xp2j-w52g Directory traversal vulnerability in index.php in BNCwi 1.04 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the newlanguage parameter. | 2% Низкий | больше 4 лет назад | ||
GHSA-36xw-wj35-w3q4 A logging issue was addressed with improved data redaction. This issue is fixed in macOS Tahoe 26.1. An app may be able to access sensitive user data. | CVSS3: 5.5 | 0% Низкий | 3 месяца назад | |
GHSA-36xw-hgfv-jwm7 Multiple security issues including data race, buffer overflow, and uninitialized memory drop in arr | CVSS3: 9.8 | 2% Низкий | около 5 лет назад | |
GHSA-36xw-fx78-c5r4 containerd-shim API Exposed to Host Network Containers | CVSS3: 5.2 | 3% Низкий | больше 5 лет назад | |
GHSA-36xv-rp4j-w277 Memory leak in eServ 2.9x allows remote attackers to cause a denial of service (memory exhaustion) via a large number of connections, whose memory is not freed when the connection is terminated. | 8% Низкий | больше 4 лет назад | ||
GHSA-36xv-jgw5-4q75 @nestjs/core Improperly Neutralizes Special Elements in Output Used by a Downstream Component ('Injection') | CVSS3: 6.1 | 0% Низкий | 6 месяцев назад | |
GHSA-36xv-45pm-m623 Microsoft Publisher 2003 SP3, and 2007 SP2 and SP3, does not properly manage memory allocations for function pointers, which allows user-assisted remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Function Pointer Overwrite Vulnerability." | 14% Средний | больше 4 лет назад | ||
GHSA-36xv-3m2q-wwfm The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'width' Shortcode Attribute in all versions up to, and including, 3.8.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | CVSS3: 6.4 | 0% Низкий | около 2 месяцев назад | |
GHSA-36xr-hxmp-hqwm Mutt mail client allows a remote attacker to execute commands via shell metacharacters. | 2% Низкий | больше 4 лет назад | ||
GHSA-36xr-8q52-r359 A vulnerability was found in xujeff tianti 天梯 up to 2.3. It has been rated as problematic. This issue affects the function exportOrder of the file /tianti-module-admin/user/ajax/save of the component com.jeff.tianti.controller. The manipulation leads to csv injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 4.3 | 0% Низкий | около 1 года назад | |
GHSA-36xr-52f8-hmpq Gadu-Gadu build 155 and earlier allows remote attackers to cause a denial of service (infinite loop) via a message that contains an image whose filename does not start with restricted characters. | 1% Низкий | больше 4 лет назад |
Уязвимостей на страницу