Количество 375 268
Количество 375 268
GHSA-35rc-qr7q-j9jm
Use after free issue due to using of invalidated iterator to delete an object in sensors HAL in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8096AU, MSM8909W, Nicobar, QCS605, SA6155P, SDA845, SDM429W, SDM670, SDM710, SDM845, SM6150, SM8150, SM8250, SXR1130, SXR2130
GHSA-35rc-fmpw-cvfv
An unauthenticated attacker can check the existence of usernames in the system by querying an API.
GHSA-35rc-2vcv-r6q5
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.
GHSA-35r9-gfqf-r6cw
Missing permission check in Jenkins vRealize Orchestrator Plugin
GHSA-35r8-c3gc-mfvr
Leave Management System Project v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'setearnleave' parameter of the admin/setleaves.php resource does not validate the characters received and they are sent unfiltered to the database.
GHSA-35r7-w24m-px2g
A configuration problem in the Ad Server Sample directory (AdSamples) in Microsoft Site Server 3.0 allows an attacker to obtain the SITE.CSC file, which exposes sensitive SQL database information.
GHSA-35r7-vh9q-xpf7
Use after free in Navigation in Google Chrome prior to 119.0.6045.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
GHSA-35r7-4rp8-9885
Multiple stack-based buffer overflows in mathtex.cgi in mathTeX, when downloaded before 20090713, have unspecified impact and remote attack vectors.
GHSA-35r6-wcp2-v9mw
Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
GHSA-35r6-q59h-rp4f
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in snstheme Avaz allows PHP Local File Inclusion. This issue affects Avaz: from n/a through 2.8.
GHSA-35r6-7qjq-22gr
The Enterprise Cloud Database developed by Ragic has an Arbitrary File Read vulnerability. Privileged remote attackers can exploit Relative Path Traversal to download arbitrary system files.
GHSA-35r5-x2r5-c49q
In the Linux kernel, the following vulnerability has been resolved: ksmbd: add bounds check for durable handle context Add missing bounds check for durable handle context.
GHSA-35r5-pw6j-5f37
Unspecified vulnerability in Cisco IOS 12.2 through 12.4, when certificate-based authentication is enabled for IKE, allows remote attackers to cause a denial of service (Phase 1 SA exhaustion) via crafted requests, aka Bug IDs CSCsy07555 and CSCee72997.
GHSA-35r5-j2wv-ff34
Missing Authorization vulnerability in quillforms.com Quill Forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quill Forms: from n/a through 3.3.0.
GHSA-35r4-97wh-88x3
ModernFlow before 1.3.00.208 does not constrain web-page access to members of a security group, as demonstrated by the Search Screen and the Profile Screen.
GHSA-35r4-377q-pc5v
CyberPanel (aka Cyber Panel) before 6778ad1 does not require the FilemanagerAdmin capability for restartMySQL actions.
GHSA-35r3-xfww-vf6j
In the Linux kernel, the following vulnerability has been resolved: ceph: fix cred leak in ceph_mds_check_access() get_current_cred() increments the reference counter, but the put_cred() call was missing.
GHSA-35qx-qjjj-9pfh
OperaMasks SDK ELite Script Engine v0.5.0 was discovered to contain a deserialization vulnerability.
GHSA-35qx-pprw-fwph
A vulnerability was found in SourceCodester Sales Tracker Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /classes/Users.php?f=save. The manipulation of the argument firstname/middlename/lastname/username leads to cross site scripting. The attack may be launched remotely. The identifier of this vulnerability is VDB-231164.
GHSA-35qx-m8hh-rrjv
Race condition in the virNetServerClientStartKeepAlive function in libvirt before 1.2.1 allows remote attackers to cause a denial of service (libvirtd crash) by closing a connection before a keepalive response is sent.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-35rc-qr7q-j9jm Use after free issue due to using of invalidated iterator to delete an object in sensors HAL in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8096AU, MSM8909W, Nicobar, QCS605, SA6155P, SDA845, SDM429W, SDM670, SDM710, SDM845, SM6150, SM8150, SM8250, SXR1130, SXR2130 | 0% Низкий | больше 4 лет назад | ||
GHSA-35rc-fmpw-cvfv An unauthenticated attacker can check the existence of usernames in the system by querying an API. | CVSS3: 5.3 | 0% Низкий | больше 1 года назад | |
GHSA-35rc-2vcv-r6q5 A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location. | CVSS3: 10 | 85% Высокий | 2 месяца назад | |
GHSA-35r9-gfqf-r6cw Missing permission check in Jenkins vRealize Orchestrator Plugin | CVSS3: 4.3 | 1% Низкий | около 4 лет назад | |
GHSA-35r8-c3gc-mfvr Leave Management System Project v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'setearnleave' parameter of the admin/setleaves.php resource does not validate the characters received and they are sent unfiltered to the database. | CVSS3: 8.8 | 1% Низкий | больше 2 лет назад | |
GHSA-35r7-w24m-px2g A configuration problem in the Ad Server Sample directory (AdSamples) in Microsoft Site Server 3.0 allows an attacker to obtain the SITE.CSC file, which exposes sensitive SQL database information. | 12% Средний | больше 4 лет назад | ||
GHSA-35r7-vh9q-xpf7 Use after free in Navigation in Google Chrome prior to 119.0.6045.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | CVSS3: 8.8 | 25% Средний | почти 3 года назад | |
GHSA-35r7-4rp8-9885 Multiple stack-based buffer overflows in mathtex.cgi in mathTeX, when downloaded before 20090713, have unspecified impact and remote attack vectors. | 3% Низкий | больше 4 лет назад | ||
GHSA-35r6-wcp2-v9mw Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | CVSS3: 7.8 | 0% Низкий | 2 месяца назад | |
GHSA-35r6-q59h-rp4f Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in snstheme Avaz allows PHP Local File Inclusion. This issue affects Avaz: from n/a through 2.8. | CVSS3: 8.1 | 1% Низкий | больше 1 года назад | |
GHSA-35r6-7qjq-22gr The Enterprise Cloud Database developed by Ragic has an Arbitrary File Read vulnerability. Privileged remote attackers can exploit Relative Path Traversal to download arbitrary system files. | CVSS3: 4.9 | 0% Низкий | 11 дней назад | |
GHSA-35r5-x2r5-c49q In the Linux kernel, the following vulnerability has been resolved: ksmbd: add bounds check for durable handle context Add missing bounds check for durable handle context. | CVSS3: 5.5 | 0% Низкий | больше 1 года назад | |
GHSA-35r5-pw6j-5f37 Unspecified vulnerability in Cisco IOS 12.2 through 12.4, when certificate-based authentication is enabled for IKE, allows remote attackers to cause a denial of service (Phase 1 SA exhaustion) via crafted requests, aka Bug IDs CSCsy07555 and CSCee72997. | 2% Низкий | больше 4 лет назад | ||
GHSA-35r5-j2wv-ff34 Missing Authorization vulnerability in quillforms.com Quill Forms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Quill Forms: from n/a through 3.3.0. | CVSS3: 6.5 | 0% Низкий | больше 1 года назад | |
GHSA-35r4-97wh-88x3 ModernFlow before 1.3.00.208 does not constrain web-page access to members of a security group, as demonstrated by the Search Screen and the Profile Screen. | 2% Низкий | больше 4 лет назад | ||
GHSA-35r4-377q-pc5v CyberPanel (aka Cyber Panel) before 6778ad1 does not require the FilemanagerAdmin capability for restartMySQL actions. | CVSS3: 4.3 | 1% Низкий | почти 2 года назад | |
GHSA-35r3-xfww-vf6j In the Linux kernel, the following vulnerability has been resolved: ceph: fix cred leak in ceph_mds_check_access() get_current_cred() increments the reference counter, but the put_cred() call was missing. | CVSS3: 5.5 | 0% Низкий | больше 1 года назад | |
GHSA-35qx-qjjj-9pfh OperaMasks SDK ELite Script Engine v0.5.0 was discovered to contain a deserialization vulnerability. | CVSS3: 8.8 | 1% Низкий | около 1 года назад | |
GHSA-35qx-pprw-fwph A vulnerability was found in SourceCodester Sales Tracker Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /classes/Users.php?f=save. The manipulation of the argument firstname/middlename/lastname/username leads to cross site scripting. The attack may be launched remotely. The identifier of this vulnerability is VDB-231164. | CVSS3: 2.4 | 2% Низкий | больше 3 лет назад | |
GHSA-35qx-m8hh-rrjv Race condition in the virNetServerClientStartKeepAlive function in libvirt before 1.2.1 allows remote attackers to cause a denial of service (libvirtd crash) by closing a connection before a keepalive response is sent. | 2% Низкий | больше 4 лет назад |
Уязвимостей на страницу