Количество 374 825
Количество 374 825
GHSA-34jv-w46c-36jr
Money Transfer Management System 1.0 is vulnerable to SQL Injection via /mtms/classes/Users.php?f=delete.
GHSA-34jv-m534-q8qr
mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 allows Account Enumeration by leveraging a Discrepancy between the "HTTP 404 - account is not active" and "HTTP 401 - must authenticate" errors.
GHSA-34jv-9f93-hq2f
Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and SP2; Open XML File Format Converter for Mac; Microsoft Office Excel Viewer 2003 SP3; Microsoft Office Excel Viewer; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allow remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka "Field Sanitization Memory Corruption Vulnerability."
GHSA-34jr-r2pr-95hh
An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24341. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized.
GHSA-34jr-g339-3423
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
GHSA-34jq-f4vw-gcm5
PHP remote file inclusion vulnerability in lib/rs.php in 2le.net Castor PHP Web Builder 1.1.1 allows remote attackers to execute arbitrary PHP code via the rootpath parameter.
GHSA-34jq-548x-m2x9
Improper Resource Shutdown or Release in TYPO3 extension
GHSA-34jq-3228-6mcp
The JavaScript implementation in Google Chrome 4 does not properly restrict the set of values contained in the object returned by the getComputedStyle method, which allows remote attackers to obtain sensitive information about visited web pages by calling this method. NOTE: this may overlap CVE-2010-5070.
GHSA-34jp-w7ww-7cwj
A vulnerability was found in SourceCodester Online Courseware 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file admin/saveedit.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259592.
GHSA-34jp-jwp8-9p5j
HCL Aftermarket EPC is vulnerable to attacks since the server software version used by the application is revealed by the web server. Displaying version information of software could allow an attacker to determine which vulnerabilities are present in the software, particularly if an outdated software version is in use with published vulnerabilities.
GHSA-34jp-8qpg-jfwf
Integer overflow or wraparound in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network.
GHSA-34jm-h6vm-gxqp
DNS cache poisoning via BIND, by predictable query IDs.
GHSA-34jm-9965-j384
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26. An app may be able to read sensitive location information.
GHSA-34jm-95xh-4rx8
A SQL injection vulnerability was discovered in TOPMeeting before version 8.8 (2019/08/19). An attacker can use a union based injection query string though a search meeting room feature to get databases schema and username/password.
GHSA-34jm-85m6-f5hv
In the Linux kernel, the following vulnerability has been resolved: dma-fence: Fix potential tracepoint null pointer dereferences Trace_dma_fence_signaled, trace_dma_fence_wait_end and trace_dma_fence_destroy can all currently dereference a null fence->ops pointer after it has been reset on fence signalling. Lets use the safe string getters for most tracepoints to avoid this class of a problem, while for the signal tracepoint we move it to before ops are cleared to avoid losing the driver and timeline name information. Apart from moving it we also need to add a new tracepoint class to bypass the safe name getters since the signaled bit is already set. For dma_fence_init we also need to use the new tracepoint class since the rcu read lock is not held there, and we can do the same for the enable signaling since there we are certain the fence cannot be signaled while we are holding the lock and have even validated the fence->ops.
GHSA-34jj-j7vv-x8fp
Trend Micro ServerProtect for Linux (SPLX) 1.25, 1.3, and 2.5 before 20070216 allows remote attackers to access arbitrary web pages and reconfigure the product via HTTP requests with the splx_2376_info cookie to the web interface port (14942/tcp).
GHSA-34jj-27w8-h7cm
Easy US Sales Taxes Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg().
GHSA-34jh-p97f-mpxf
urllib3's Proxy-Authorization request header isn't stripped during cross-origin redirects
GHSA-34jg-44wj-8r3p
SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_comment_news.php.
GHSA-34jf-wc5v-9rcm
The WP Custom HTML Page WordPress plugin through 0.6.2 does not sanitise HTML stored through one of its custom page handlers, nor restrict it to users allowed to post unfiltered HTML, allowing users with the Author role to store JavaScript that is served unescaped at a public URL and executes for any visitor, including administrators.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-34jv-w46c-36jr Money Transfer Management System 1.0 is vulnerable to SQL Injection via /mtms/classes/Users.php?f=delete. | CVSS3: 9.8 | 1% Низкий | больше 4 лет назад | |
GHSA-34jv-m534-q8qr mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 allows Account Enumeration by leveraging a Discrepancy between the "HTTP 404 - account is not active" and "HTTP 401 - must authenticate" errors. | CVSS3: 5.3 | 2% Низкий | больше 4 лет назад | |
GHSA-34jv-9f93-hq2f Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and SP2; Open XML File Format Converter for Mac; Microsoft Office Excel Viewer 2003 SP3; Microsoft Office Excel Viewer; and Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and SP2 allow remote attackers to execute arbitrary code via a crafted Excel file with a malformed record object, aka "Field Sanitization Memory Corruption Vulnerability." | 28% Средний | больше 4 лет назад | ||
GHSA-34jr-r2pr-95hh An issue was discovered in the server in Veritas Enterprise Vault before 15.2, ZDI-CAN-24341. It allows remote attackers to execute arbitrary code because untrusted data, received on a .NET Remoting TCP port, is deserialized. | CVSS3: 9.8 | 1% Низкий | почти 2 года назад | |
GHSA-34jr-g339-3423 Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. | CVSS3: 6.5 | 1% Низкий | 2 месяца назад | |
GHSA-34jq-f4vw-gcm5 PHP remote file inclusion vulnerability in lib/rs.php in 2le.net Castor PHP Web Builder 1.1.1 allows remote attackers to execute arbitrary PHP code via the rootpath parameter. | 3% Низкий | больше 4 лет назад | ||
GHSA-34jq-548x-m2x9 Improper Resource Shutdown or Release in TYPO3 extension | CVSS3: 7.5 | 1% Низкий | около 5 лет назад | |
GHSA-34jq-3228-6mcp The JavaScript implementation in Google Chrome 4 does not properly restrict the set of values contained in the object returned by the getComputedStyle method, which allows remote attackers to obtain sensitive information about visited web pages by calling this method. NOTE: this may overlap CVE-2010-5070. | 1% Низкий | больше 4 лет назад | ||
GHSA-34jp-w7ww-7cwj A vulnerability was found in SourceCodester Online Courseware 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file admin/saveedit.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-259592. | CVSS3: 6.3 | 1% Низкий | больше 2 лет назад | |
GHSA-34jp-jwp8-9p5j HCL Aftermarket EPC is vulnerable to attacks since the server software version used by the application is revealed by the web server. Displaying version information of software could allow an attacker to determine which vulnerabilities are present in the software, particularly if an outdated software version is in use with published vulnerabilities. | CVSS3: 5.3 | 0% Низкий | 2 месяца назад | |
GHSA-34jp-8qpg-jfwf Integer overflow or wraparound in Microsoft Windows Media Foundation allows an unauthorized attacker to execute code over a network. | CVSS3: 9.8 | 1% Низкий | 10 дней назад | |
GHSA-34jm-h6vm-gxqp DNS cache poisoning via BIND, by predictable query IDs. | 5% Низкий | больше 4 лет назад | ||
GHSA-34jm-9965-j384 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Tahoe 26. An app may be able to read sensitive location information. | CVSS3: 5.5 | 0% Низкий | около 1 года назад | |
GHSA-34jm-95xh-4rx8 A SQL injection vulnerability was discovered in TOPMeeting before version 8.8 (2019/08/19). An attacker can use a union based injection query string though a search meeting room feature to get databases schema and username/password. | CVSS3: 9.8 | 1% Низкий | больше 4 лет назад | |
GHSA-34jm-85m6-f5hv In the Linux kernel, the following vulnerability has been resolved: dma-fence: Fix potential tracepoint null pointer dereferences Trace_dma_fence_signaled, trace_dma_fence_wait_end and trace_dma_fence_destroy can all currently dereference a null fence->ops pointer after it has been reset on fence signalling. Lets use the safe string getters for most tracepoints to avoid this class of a problem, while for the signal tracepoint we move it to before ops are cleared to avoid losing the driver and timeline name information. Apart from moving it we also need to add a new tracepoint class to bypass the safe name getters since the signaled bit is already set. For dma_fence_init we also need to use the new tracepoint class since the rcu read lock is not held there, and we can do the same for the enable signaling since there we are certain the fence cannot be signaled while we are holding the lock and have even validated the fence->ops. | 0% Низкий | около 1 месяца назад | ||
GHSA-34jj-j7vv-x8fp Trend Micro ServerProtect for Linux (SPLX) 1.25, 1.3, and 2.5 before 20070216 allows remote attackers to access arbitrary web pages and reconfigure the product via HTTP requests with the splx_2376_info cookie to the web interface port (14942/tcp). | 2% Низкий | больше 4 лет назад | ||
GHSA-34jj-27w8-h7cm Easy US Sales Taxes Add-on for iThemes Exchange before 1.1.0 for WordPress has XSS via add_query_arg() and remove_query_arg(). | CVSS3: 6.1 | 1% Низкий | больше 4 лет назад | |
GHSA-34jh-p97f-mpxf urllib3's Proxy-Authorization request header isn't stripped during cross-origin redirects | CVSS3: 4.4 | 1% Низкий | больше 2 лет назад | |
GHSA-34jg-44wj-8r3p SeaCMS v13.3 was discovered to contain a SQL injection vulnerability via the component admin_comment_news.php. | CVSS3: 9.8 | 0% Низкий | больше 1 года назад | |
GHSA-34jf-wc5v-9rcm The WP Custom HTML Page WordPress plugin through 0.6.2 does not sanitise HTML stored through one of its custom page handlers, nor restrict it to users allowed to post unfiltered HTML, allowing users with the Author role to store JavaScript that is served unescaped at a public URL and executes for any visitor, including administrators. | CVSS3: 5.4 | 0% Низкий | около 1 месяца назад |
Уязвимостей на страницу