Количество 375 356
Количество 375 356
GHSA-36p3-3fqr-h7j4
Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to execute code locally.
GHSA-36p3-3fj3-g9p5
SmartRobot from INTUMIT does not properly validate a specific page parameter, allowing unautheticated remote attackers to inject JavaScript code to the parameter for Reflected Cross-site Scripting attacks.
GHSA-36p2-p85p-3g3q
onedcu in IBM Informix Dynamic Server (IDS) 10.x before 10.00.xC8 allows local users to create arbitrary files via the Trace file argument.
GHSA-36p2-cfmm-wp8w
The Supreme Modules Lite plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 2.5.62. This is due to insufficient file type validation detecting JSON files, allowing double extension files to bypass sanitization while being accepted as a valid JSON file. This makes it possible for authenticated attackers, with author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible.
GHSA-36p2-8879-3c27
A deserialization vulnerability exists in how the LogService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre.
GHSA-36p2-8566-7frq
The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability.
GHSA-36p2-3xmm-mxrv
WebChess through 0.9.0 and 1.0.0.rc2 allows SQL injection: mainmenu.php, chess.php, and opponentspassword.php (txtFirstName, txtLastName).
GHSA-36mx-gp2g-xh52
Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the internal representation of raster data. Successful exploitation could lead to arbitrary code execution.
GHSA-36mw-gq75-9mwg
IBM Security Guardium 10.0 and 10.1 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM X-Force ID: 124685
GHSA-36mv-7364-j7gh
InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
GHSA-36mr-q5jp-rfp3
A flaw was found in ImageMagick in MagickCore/quantum-export.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type `unsigned long long` as well as a shift exponent that is too large for 64-bit type. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undefined behavior. This flaw affects ImageMagick versions prior to 7.0.9-0.
GHSA-36mr-3fcp-m422
VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'.
GHSA-36mq-qwm2-6rpp
Out-of-bounds Write vulnerability in TCP stack of Apache NuttX (incubating) versions up to and including 9.1.0 and 10.0.0 allows attacker to corrupt memory by supplying arbitrary urgent data pointer offsets within TCP packets including beyond the length of the packet.
GHSA-36mq-q7hj-fg2m
Insufficient data validation in dialogs in Google Chrome on OS X prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensitive information from disk via a crafted HTML page.
GHSA-36mq-mcj7-pggv
The Droit Elementor Addons – Widgets, Blocks, Templates Library For Elementor Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 3.1.5 due to insufficient input sanitization and output escaping on user supplied attributes such as URL. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
GHSA-36mq-j57w-rh2g
An arbitrary file upload vulnerability in the nccloud.web.arcp.taskmonitor.action.ArcpUploadAction.doAction() method of YonBIP v3_23.05 allows attackers to execute arbitrary code via uploading a crafted file.
GHSA-36mq-h5r6-m2x4
SQL injection vulnerability in questions.php in EsFaq 2.0 allows remote attackers to execute arbitrary SQL commands via the cid parameter, a different vector than CVE-2008-3952. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
GHSA-36mm-w85j-3q2j
veraPDF Validation XXE via XFA
GHSA-36mj-xjpp-v7p2
SWFTools commit 772e55a2 was discovered to contain a segmentation violation via extractFrame at /readers/swf.c.
GHSA-36mj-6r7r-mqhf
User can obtain JWT token even if account is disabled
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-36p3-3fqr-h7j4 Heap-based buffer overflow in Windows Win32K - GRFX allows an authorized attacker to execute code locally. | CVSS3: 8.8 | 0% Низкий | 4 месяца назад | |
GHSA-36p3-3fj3-g9p5 SmartRobot from INTUMIT does not properly validate a specific page parameter, allowing unautheticated remote attackers to inject JavaScript code to the parameter for Reflected Cross-site Scripting attacks. | CVSS3: 6.1 | 0% Низкий | около 2 лет назад | |
GHSA-36p2-p85p-3g3q onedcu in IBM Informix Dynamic Server (IDS) 10.x before 10.00.xC8 allows local users to create arbitrary files via the Trace file argument. | 0% Низкий | больше 4 лет назад | ||
GHSA-36p2-cfmm-wp8w The Supreme Modules Lite plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and including, 2.5.62. This is due to insufficient file type validation detecting JSON files, allowing double extension files to bypass sanitization while being accepted as a valid JSON file. This makes it possible for authenticated attackers, with author-level access and above, to upload arbitrary files on the affected site's server which may make remote code execution possible. | CVSS3: 8.8 | 1% Низкий | 8 месяцев назад | |
GHSA-36p2-8879-3c27 A deserialization vulnerability exists in how the LogService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre. | CVSS3: 9.8 | 4% Низкий | больше 4 лет назад | |
GHSA-36p2-8566-7frq The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability. | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
GHSA-36p2-3xmm-mxrv WebChess through 0.9.0 and 1.0.0.rc2 allows SQL injection: mainmenu.php, chess.php, and opponentspassword.php (txtFirstName, txtLastName). | CVSS3: 8.8 | 14% Средний | больше 3 лет назад | |
GHSA-36mx-gp2g-xh52 Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the internal representation of raster data. Successful exploitation could lead to arbitrary code execution. | CVSS3: 9.8 | 7% Низкий | больше 4 лет назад | |
GHSA-36mw-gq75-9mwg IBM Security Guardium 10.0 and 10.1 does not perform an authentication check for a critical resource or functionality allowing anonymous users access to protected areas. IBM X-Force ID: 124685 | CVSS3: 6.5 | 1% Низкий | больше 4 лет назад | |
GHSA-36mv-7364-j7gh InDesign Desktop versions 20.4, 19.5.4 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | CVSS3: 5.5 | 0% Низкий | около 1 года назад | |
GHSA-36mr-q5jp-rfp3 A flaw was found in ImageMagick in MagickCore/quantum-export.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type `unsigned long long` as well as a shift exponent that is too large for 64-bit type. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undefined behavior. This flaw affects ImageMagick versions prior to 7.0.9-0. | CVSS3: 3.3 | 1% Низкий | больше 4 лет назад | |
GHSA-36mr-3fcp-m422 VMware Aria Operations contains a local privilege escalation vulnerability. A malicious actor with administrative access to the local system can escalate privileges to 'root'. | CVSS3: 6.7 | 0% Низкий | больше 2 лет назад | |
GHSA-36mq-qwm2-6rpp Out-of-bounds Write vulnerability in TCP stack of Apache NuttX (incubating) versions up to and including 9.1.0 and 10.0.0 allows attacker to corrupt memory by supplying arbitrary urgent data pointer offsets within TCP packets including beyond the length of the packet. | 3% Низкий | больше 4 лет назад | ||
GHSA-36mq-q7hj-fg2m Insufficient data validation in dialogs in Google Chrome on OS X prior to 86.0.4240.75 allowed a remote attacker to obtain potentially sensitive information from disk via a crafted HTML page. | 1% Низкий | больше 4 лет назад | ||
GHSA-36mq-mcj7-pggv The Droit Elementor Addons – Widgets, Blocks, Templates Library For Elementor Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 3.1.5 due to insufficient input sanitization and output escaping on user supplied attributes such as URL. This makes it possible for authenticated attackers with contributor-level and above permissions to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | CVSS3: 5.4 | 0% Низкий | больше 2 лет назад | |
GHSA-36mq-j57w-rh2g An arbitrary file upload vulnerability in the nccloud.web.arcp.taskmonitor.action.ArcpUploadAction.doAction() method of YonBIP v3_23.05 allows attackers to execute arbitrary code via uploading a crafted file. | CVSS3: 9.8 | 1% Низкий | больше 2 лет назад | |
GHSA-36mq-h5r6-m2x4 SQL injection vulnerability in questions.php in EsFaq 2.0 allows remote attackers to execute arbitrary SQL commands via the cid parameter, a different vector than CVE-2008-3952. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 1% Низкий | больше 4 лет назад | ||
GHSA-36mm-w85j-3q2j veraPDF Validation XXE via XFA | 0% Низкий | около 2 месяцев назад | ||
GHSA-36mj-xjpp-v7p2 SWFTools commit 772e55a2 was discovered to contain a segmentation violation via extractFrame at /readers/swf.c. | CVSS3: 5.5 | 0% Низкий | около 4 лет назад | |
GHSA-36mj-6r7r-mqhf User can obtain JWT token even if account is disabled | почти 5 лет назад |
Уязвимостей на страницу