Количество 373 892
Количество 373 892
GHSA-33f2-544v-wh7x
Qt through 5.15.8 and 6.x through 6.2.3 can load system library files from an unintended working directory.
GHSA-33cx-2vvq-mf52
Vulnerability in Best Practical Solutions, LLC's Request Tracker v5.0.7, where the Triple DES (3DES) cryptographic algorithm is used within SMIME code to encrypt S/MIME emails. Triple DES is considered obsolete and insecure due to its susceptibility to birthday attacks, which could compromise the confidentiality of encrypted messages.
GHSA-33cw-rfhq-85q4
Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the security_5g parameter at /goform/WifiBasicSet.
GHSA-33cw-f6c5-2rv7
A vulnerability classified as critical was found in code-projects Simple Car Rental System 1.0. Affected by this vulnerability is an unknown functionality of the file /login.php. The manipulation of the argument uname leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
GHSA-33cw-2rgg-pqmh
SQL injection vulnerability in intouch.lib.php in inTouch 0.5.1 Alpha allows remote attackers to execute arbitrary SQL commands via the user parameter.
GHSA-33cv-rf7v-r5m4
The Windows font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT Gold and 8.1; Office 2007 SP3; Office 2010 SP2; Word Viewer; .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6; Skype for Business 2016; Lync 2010; Lync 2013 SP1; Live Meeting 2007 Console; and Silverlight 5 allows remote attackers to execute arbitrary code via a crafted embedded font, aka "Graphics Memory Corruption Vulnerability."
GHSA-33cv-ffrg-w682
Unauthenticated Cross Site Scripting (XSS) in Link Whisper Free <= 0.9.4 versions.
GHSA-33cr-xf9m-fqqr
Use after free in PDF in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.
GHSA-33cr-m232-xqch
cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement
GHSA-33cr-5mgj-3gg9
An issue was discovered in Xen through 4.9.x allowing HVM guest OS users to gain privileges on the host OS, obtain sensitive information, or cause a denial of service (BUG and host OS crash) by leveraging the mishandling of Populate on Demand (PoD) Physical-to-Machine (P2M) errors.
GHSA-33cr-4p77-f2mf
Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Rename Allowing Arbitrary File Rename in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 - The media rename task applied neither of the directory boundary checks used by the folder operations in the same controller, and its validation guard required only that either a media record exist for the supplied identifier or that the supplied path be present in #__spmedia, rather than both. The identifier and the path were consequently never checked against one another, so any valid media identifier could be paired with an unrelated filesystem path, and the STR input filter left traversal sequences intact. An attacker could rename files elsewhere in the installation, including renaming configuration.php to take the site offline.
GHSA-33cr-4mvf-fj5r
IBM QRadar Network Security 5.4 supports interaction between multiple actors and allows those actors to negotiate which algorithm should be used as a protection mechanism such as encryption or authentication, but it does not select the strongest algorithm that is available to both parties. IBM X-Force ID: 128689.
GHSA-33cp-wjp9-mgp2
In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00421149; Issue ID: MSV-3728.
GHSA-33cp-qrcq-xvp4
Format string vulnerability in Novell Modular Authentication Services (NMAS) in the Novell Client 4.91 SP2 and SP3 allows users with physical access to read stack and memory contents via format string specifiers in the Username field of the logon window.
GHSA-33cj-w75f-49m2
Magento 2 Community Edition Server-Side Request Forgery vulnerability
GHSA-33cj-qgm7-jr34
Missing Authorization vulnerability in Azzaroco WP SuperBackup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP SuperBackup: from n/a through 2.3.3.
GHSA-33cj-hx68-hxx3
Multiple Cross-Site Scripting (XSS) issues were discovered in webpagetest 3.0. The vulnerabilities exist due to insufficient filtration of user-supplied data (benchmark, url) passed to the webpagetest-master/www/benchmarks/trendurl.php URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.
GHSA-33cj-4m4m-jhxc
A NULL pointer dereference was discovered in ic_predict of libfaad/ic_predict.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.
GHSA-33cg-gxv8-3p8g
vLLM denial of service via prompt embeds on M-RoPE models
GHSA-33cg-9xrv-3cmx
Insufficient validation of untrusted input in InterestGroups in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-33f2-544v-wh7x Qt through 5.15.8 and 6.x through 6.2.3 can load system library files from an unintended working directory. | CVSS3: 7.5 | 2% Низкий | больше 4 лет назад | |
GHSA-33cx-2vvq-mf52 Vulnerability in Best Practical Solutions, LLC's Request Tracker v5.0.7, where the Triple DES (3DES) cryptographic algorithm is used within SMIME code to encrypt S/MIME emails. Triple DES is considered obsolete and insecure due to its susceptibility to birthday attacks, which could compromise the confidentiality of encrypted messages. | 0% Низкий | больше 1 года назад | ||
GHSA-33cw-rfhq-85q4 Tenda A15 V15.13.07.13 was discovered to contain a stack overflow via the security_5g parameter at /goform/WifiBasicSet. | CVSS3: 9.8 | 1% Низкий | больше 3 лет назад | |
GHSA-33cw-f6c5-2rv7 A vulnerability classified as critical was found in code-projects Simple Car Rental System 1.0. Affected by this vulnerability is an unknown functionality of the file /login.php. The manipulation of the argument uname leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 7.3 | 1% Низкий | почти 2 года назад | |
GHSA-33cw-2rgg-pqmh SQL injection vulnerability in intouch.lib.php in inTouch 0.5.1 Alpha allows remote attackers to execute arbitrary SQL commands via the user parameter. | 1% Низкий | больше 4 лет назад | ||
GHSA-33cv-rf7v-r5m4 The Windows font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT Gold and 8.1; Office 2007 SP3; Office 2010 SP2; Word Viewer; .NET Framework 3.0 SP2, 3.5, 3.5.1, 4, 4.5, 4.5.1, 4.5.2, and 4.6; Skype for Business 2016; Lync 2010; Lync 2013 SP1; Live Meeting 2007 Console; and Silverlight 5 allows remote attackers to execute arbitrary code via a crafted embedded font, aka "Graphics Memory Corruption Vulnerability." | 26% Средний | больше 4 лет назад | ||
GHSA-33cv-ffrg-w682 Unauthenticated Cross Site Scripting (XSS) in Link Whisper Free <= 0.9.4 versions. | CVSS3: 7.1 | 0% Низкий | 3 месяца назад | |
GHSA-33cr-xf9m-fqqr Use after free in PDF in Google Chrome prior to 105.0.5195.125 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. | CVSS3: 8.8 | 1% Низкий | почти 4 года назад | |
GHSA-33cr-m232-xqch cheqd-node affected by Non-deterministic JSON Unmarshalling of IBC Acknowledgement | больше 1 года назад | |||
GHSA-33cr-5mgj-3gg9 An issue was discovered in Xen through 4.9.x allowing HVM guest OS users to gain privileges on the host OS, obtain sensitive information, or cause a denial of service (BUG and host OS crash) by leveraging the mishandling of Populate on Demand (PoD) Physical-to-Machine (P2M) errors. | CVSS3: 8.8 | 0% Низкий | больше 4 лет назад | |
GHSA-33cr-4p77-f2mf Joomla Extension - joomshaper.com - Missing Directory Confinement in Media Rename Allowing Arbitrary File Rename in SP Page Builder (Free and Pro) 4.0.0 - 6.9.0 - The media rename task applied neither of the directory boundary checks used by the folder operations in the same controller, and its validation guard required only that either a media record exist for the supplied identifier or that the supplied path be present in #__spmedia, rather than both. The identifier and the path were consequently never checked against one another, so any valid media identifier could be paired with an unrelated filesystem path, and the STR input filter left traversal sequences intact. An attacker could rename files elsewhere in the installation, including renaming configuration.php to take the site offline. | 0% Низкий | 4 дня назад | ||
GHSA-33cr-4mvf-fj5r IBM QRadar Network Security 5.4 supports interaction between multiple actors and allows those actors to negotiate which algorithm should be used as a protection mechanism such as encryption or authentication, but it does not select the strongest algorithm that is available to both parties. IBM X-Force ID: 128689. | CVSS3: 7.5 | 1% Низкий | больше 4 лет назад | |
GHSA-33cp-wjp9-mgp2 In wlan AP driver, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: WCNCR00421149; Issue ID: MSV-3728. | CVSS3: 7.8 | 0% Низкий | 11 месяцев назад | |
GHSA-33cp-qrcq-xvp4 Format string vulnerability in Novell Modular Authentication Services (NMAS) in the Novell Client 4.91 SP2 and SP3 allows users with physical access to read stack and memory contents via format string specifiers in the Username field of the logon window. | 0% Низкий | больше 4 лет назад | ||
GHSA-33cj-w75f-49m2 Magento 2 Community Edition Server-Side Request Forgery vulnerability | CVSS3: 7.2 | 1% Низкий | больше 4 лет назад | |
GHSA-33cj-qgm7-jr34 Missing Authorization vulnerability in Azzaroco WP SuperBackup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP SuperBackup: from n/a through 2.3.3. | CVSS3: 7.4 | 0% Низкий | больше 1 года назад | |
GHSA-33cj-hx68-hxx3 Multiple Cross-Site Scripting (XSS) issues were discovered in webpagetest 3.0. The vulnerabilities exist due to insufficient filtration of user-supplied data (benchmark, url) passed to the webpagetest-master/www/benchmarks/trendurl.php URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website. | CVSS3: 6.1 | 1% Низкий | больше 4 лет назад | |
GHSA-33cj-4m4m-jhxc A NULL pointer dereference was discovered in ic_predict of libfaad/ic_predict.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash, which leads to denial of service. | CVSS3: 5.5 | 1% Низкий | больше 4 лет назад | |
GHSA-33cg-gxv8-3p8g vLLM denial of service via prompt embeds on M-RoPE models | 1% Низкий | около 2 месяцев назад | ||
GHSA-33cg-9xrv-3cmx Insufficient validation of untrusted input in InterestGroups in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) | CVSS3: 8.3 | 0% Низкий | 4 месяца назад |
Уязвимостей на страницу