Количество 364 543
Количество 364 543
GHSA-22wc-c9wj-6q2v
VVE-2021-0001: Memory corruption using function calls within arrays
GHSA-22wc-8hcq-634h
In the Linux kernel, the following vulnerability has been resolved: ext4: fix deadlock due to mbcache entry corruption When manipulating xattr blocks, we can deadlock infinitely looping inside ext4_xattr_block_set() where we constantly keep finding xattr block for reuse in mbcache but we are unable to reuse it because its reference count is too big. This happens because cache entry for the xattr block is marked as reusable (e_reusable set) although its reference count is too big. When this inconsistency happens, this inconsistent state is kept indefinitely and so ext4_xattr_block_set() keeps retrying indefinitely. The inconsistent state is caused by non-atomic update of e_reusable bit. e_reusable is part of a bitfield and e_reusable update can race with update of e_referenced bit in the same bitfield resulting in loss of one of the updates. Fix the problem by using atomic bitops instead. This bug has been around for many years, but it became *much* easier to hit after commit 65f...
GHSA-22wc-7wmm-v4cc
Liferay Portal and Liferay DXP does not properly check user permission
GHSA-22w9-x8p2-69rp
SQL injection vulnerability in admin.php in CloudNine Interactive Links Manager 2006-06-12, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the nick parameter.
GHSA-22w9-j288-8p9w
OpenStack Nova Router metadata queries are not restricted by tenant
GHSA-22w9-2h5w-c9pv
The Duplicate Page and Post Plugin WordPress plugin through 2.7 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
GHSA-22w8-qmw3-m9gr
The if_clone_list function in NetBSD-current before 20061027, NetBSD 3.0 and 3.0.1 before 20061027, and NetBSD 2.x before 20061119 allows local users to read potentially sensitive, uninitialized stack memory via unspecified vectors.
GHSA-22w8-2mrr-vh7h
A security vulnerability has been detected in OWASP DefectDojo up to 2.55.4. This vulnerability affects the function input_zip.read of the file parser.py of the component SonarQubeParser/MSDefenderParser. The manipulation leads to denial of service. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 2.56.0 is able to resolve this issue. The identifier of the patch is e8f1e5131535b8fd80a7b1b3085d676295fdcd41. Upgrading the affected component is recommended.
GHSA-22w8-27w2-f55c
Heap-based buffer overflow in the EscapeParenthesis function in GraphicsMagick before 1.3.25 allows remote attackers to have unspecified impact via unknown vectors.
GHSA-22w7-m5f8-87vh
Liferay Portal and Liferay DXP Vulnerable to Open Redirect via the Layout Module
GHSA-22w7-gmrw-m5qp
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. A malicious application may be able to elevate privileges.
GHSA-22w7-7694-298f
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to disclose sensitive informatoin on affected installations.
GHSA-22w6-gp78-84rc
The Red Hat mkdumprd script for kexec-tools, as distributed in the kexec-tools 1.x before 1.102pre-154 and 2.x before 2.0.0-209 packages in Red Hat Enterprise Linux, includes all of root's SSH private keys within a vmcore file, which allows context-dependent attackers to obtain sensitive information by inspecting the file content.
GHSA-22w6-c8h9-6mx7
NVIDIA Jetson Linux has a vulnerability in initrd, where the nvluks trusted application is not disabled. A successful exploit of this vulnerability might lead to information disclosure.
GHSA-22w5-vw2x-wqp3
Cross-site scripting (XSS) vulnerability in index.php in the PhotoSmash plugin 1.0.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the action parameter.
GHSA-22w5-2fxg-vrwx
OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers
GHSA-22w4-vm3c-6x82
DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_pic_view.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters.
GHSA-22w3-693w-x895
webauthn-rs-core/webauthn-authenticator-rs: Origin validation mismatch possible when subdomains are allowed
GHSA-22w2-qhqg-5898
Multiple unspecified vulnerabilities in Google Chrome before 44.0.2403.89 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.
GHSA-22vx-vmhj-v8m6
Windows SmartScreen Security Feature Bypass Vulnerability.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-22wc-c9wj-6q2v VVE-2021-0001: Memory corruption using function calls within arrays | больше 5 лет назад | |||
GHSA-22wc-8hcq-634h In the Linux kernel, the following vulnerability has been resolved: ext4: fix deadlock due to mbcache entry corruption When manipulating xattr blocks, we can deadlock infinitely looping inside ext4_xattr_block_set() where we constantly keep finding xattr block for reuse in mbcache but we are unable to reuse it because its reference count is too big. This happens because cache entry for the xattr block is marked as reusable (e_reusable set) although its reference count is too big. When this inconsistency happens, this inconsistent state is kept indefinitely and so ext4_xattr_block_set() keeps retrying indefinitely. The inconsistent state is caused by non-atomic update of e_reusable bit. e_reusable is part of a bitfield and e_reusable update can race with update of e_referenced bit in the same bitfield resulting in loss of one of the updates. Fix the problem by using atomic bitops instead. This bug has been around for many years, but it became *much* easier to hit after commit 65f... | CVSS3: 7.5 | 1% Низкий | 9 месяцев назад | |
GHSA-22wc-7wmm-v4cc Liferay Portal and Liferay DXP does not properly check user permission | CVSS3: 4.3 | 1% Низкий | больше 4 лет назад | |
GHSA-22w9-x8p2-69rp SQL injection vulnerability in admin.php in CloudNine Interactive Links Manager 2006-06-12, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the nick parameter. | 1% Низкий | больше 4 лет назад | ||
GHSA-22w9-j288-8p9w OpenStack Nova Router metadata queries are not restricted by tenant | 2% Низкий | больше 4 лет назад | ||
GHSA-22w9-2h5w-c9pv The Duplicate Page and Post Plugin WordPress plugin through 2.7 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | CVSS3: 4.8 | 1% Низкий | около 4 лет назад | |
GHSA-22w8-qmw3-m9gr The if_clone_list function in NetBSD-current before 20061027, NetBSD 3.0 and 3.0.1 before 20061027, and NetBSD 2.x before 20061119 allows local users to read potentially sensitive, uninitialized stack memory via unspecified vectors. | 0% Низкий | больше 4 лет назад | ||
GHSA-22w8-2mrr-vh7h A security vulnerability has been detected in OWASP DefectDojo up to 2.55.4. This vulnerability affects the function input_zip.read of the file parser.py of the component SonarQubeParser/MSDefenderParser. The manipulation leads to denial of service. The attack can be initiated remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 2.56.0 is able to resolve this issue. The identifier of the patch is e8f1e5131535b8fd80a7b1b3085d676295fdcd41. Upgrading the affected component is recommended. | CVSS3: 4.3 | 1% Низкий | 6 месяцев назад | |
GHSA-22w8-27w2-f55c Heap-based buffer overflow in the EscapeParenthesis function in GraphicsMagick before 1.3.25 allows remote attackers to have unspecified impact via unknown vectors. | CVSS3: 9.8 | 4% Низкий | больше 4 лет назад | |
GHSA-22w7-m5f8-87vh Liferay Portal and Liferay DXP Vulnerable to Open Redirect via the Layout Module | CVSS3: 6.1 | 0% Низкий | около 3 лет назад | |
GHSA-22w7-gmrw-m5qp A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 12.2, macOS Mojave 10.14.4, tvOS 12.2, watchOS 5.2, iTunes 12.9.4 for Windows, iCloud for Windows 7.11. A malicious application may be able to elevate privileges. | 1% Низкий | больше 4 лет назад | ||
GHSA-22w7-7694-298f A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to disclose sensitive informatoin on affected installations. | CVSS3: 7.5 | 90% Высокий | больше 4 лет назад | |
GHSA-22w6-gp78-84rc The Red Hat mkdumprd script for kexec-tools, as distributed in the kexec-tools 1.x before 1.102pre-154 and 2.x before 2.0.0-209 packages in Red Hat Enterprise Linux, includes all of root's SSH private keys within a vmcore file, which allows context-dependent attackers to obtain sensitive information by inspecting the file content. | 1% Низкий | больше 4 лет назад | ||
GHSA-22w6-c8h9-6mx7 NVIDIA Jetson Linux has a vulnerability in initrd, where the nvluks trusted application is not disabled. A successful exploit of this vulnerability might lead to information disclosure. | CVSS3: 5.2 | 0% Низкий | 5 месяцев назад | |
GHSA-22w5-vw2x-wqp3 Cross-site scripting (XSS) vulnerability in index.php in the PhotoSmash plugin 1.0.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the action parameter. | 2% Низкий | больше 4 лет назад | ||
GHSA-22w5-2fxg-vrwx OpenTofu has high CPU usage when using K8S remote state backend or when parsing specifically crafted TLS certificates from untrusted or compromised servers | CVSS3: 2.6 | 9 дней назад | ||
GHSA-22w4-vm3c-6x82 DedeCMS v7.5 SP2 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities in the component file_pic_view.php via the `activepath`, `keyword`, `tag`, `fmdo=x&filename`, `CKEditor` and `CKEditorFuncNum` parameters. | 1% Низкий | больше 4 лет назад | ||
GHSA-22w3-693w-x895 webauthn-rs-core/webauthn-authenticator-rs: Origin validation mismatch possible when subdomains are allowed | 4 месяца назад | |||
GHSA-22w2-qhqg-5898 Multiple unspecified vulnerabilities in Google Chrome before 44.0.2403.89 allow attackers to cause a denial of service or possibly have other impact via unknown vectors. | 1% Низкий | больше 4 лет назад | ||
GHSA-22vx-vmhj-v8m6 Windows SmartScreen Security Feature Bypass Vulnerability. | CVSS3: 5.4 | 76% Высокий | больше 3 лет назад |
Уязвимостей на страницу