Количество 370 914
Количество 370 914
GHSA-25c5-9pxc-899f
index.php in WebMplayer before 0.6.1-Alpha allows remote attackers to execute arbitrary code via shell metacharacters in an exec function call. NOTE: some sources have referred to this as eval injection in the param parameter, but CVE source inspection suggests that this is erroneous.
GHSA-25c5-5c5w-53xq
Sophos Anti-Virus before 4.02, 4.5.x before 4.5.9, 4.6.x before 4.6.9, and 5.x before 5.1.4 allow remote attackers to hide arbitrary files and data via crafted ARJ archives, which are not properly scanned.
GHSA-25c5-58xw-hw5q
Jenkins allows Remote Users to Build Arbitrary Jobs
GHSA-25c3-h67j-g2qq
Insufficient data validation in Directory in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass file system restrictions via a crafted HTML page. (Chromium security severity: Medium)
GHSA-25c3-7fvj-v45j
phpMyFAQ Stored Cross-site Scripting vulnerability
GHSA-25c3-4v7x-3hrp
A vulnerability, which was classified as critical, was found in openBI up to 6.0.3. Affected is the function addxinzhi of the file application/controllers/User.php of the component Phar Handler. The manipulation of the argument outimgurl leads to deserialization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252696.
GHSA-25c3-3rg2-gf39
In SweetScape 010 Editor 9.0.1, improper validation of arguments in the internal implementation of the WSubStr function (provided by the scripting engine) allows an attacker to cause a denial of service by crashing the application.
GHSA-259x-xg45-mf97
Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/incoming.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.
GHSA-259x-wgj2-g49m
Unspecified vulnerability in Sun Java System Application Server 7 2004Q2 before Update 6, Web Server 6.1 before SP8, and Web Server 7.0 before Update 1 allows remote attackers to obtain source code of JSP files via unknown vectors.
GHSA-259x-v826-2fcj
IBM SPSS Modeler 16.0 before 16.0.0.1 on UNIX does not properly drop group privileges, which allows local users to bypass intended file-access restrictions by leveraging (1) gid 0 or (2) root's group memberships.
GHSA-259w-fqv8-xvgh
Acronis True Image prior to 2021 Update 4 for Windows allowed local privilege escalation due to improper soft link handling (issue 1 of 2).
GHSA-259w-8hf6-59c2
OCI image importer memory exhaustion in github.com/containerd/containerd
GHSA-259w-3jff-442h
The PixelYourSite WordPress plugin before 11.1.2 does not validate some URL parameters before using them to generate paths passed to function/s, allowing any admins to perform LFI attacks
GHSA-259v-xm34-p7fr
Typo3 Cross-Site Scripting in Language Pack Handling
GHSA-259v-fw35-w989
golang/go in 1.0.2 fixes all.bash on shared machines. dotest() in src/pkg/debug/gosym/pclntab_test.go creates a temporary file with predicable name and executes it as shell script.
GHSA-259r-6293-4g55
SQL injection vulnerability in the Search::setJsonAlert method in OSClass before 3.4.3 allows remote attackers to execute arbitrary SQL commands via the alert parameter in a search alert subscription action.
GHSA-259r-5hvg-4f6x
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application, aka "Win32k Elevation of Privilege Vulnerability."
GHSA-259r-2fr5-87c3
An issue in Daily Habit Tracker v.1.0 allows a remote attacker to manipulate trackers via the home.php, add-tracker.php, delete-tracker.php, update-tracker.php components.
GHSA-259q-pfhc-h3v8
A vulnerability was found in deerwms deer-wms-2 up to 3.3. It has been classified as critical. Affected is an unknown function of the file /system/dept/edit. The manipulation of the argument ancestors leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
GHSA-259q-j44w-v653
An issue was discovered in Atos Eviden IDRA before 2.7.1. A highly trusted role (Config Admin) could leverage a race condition to escalate privileges.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-25c5-9pxc-899f index.php in WebMplayer before 0.6.1-Alpha allows remote attackers to execute arbitrary code via shell metacharacters in an exec function call. NOTE: some sources have referred to this as eval injection in the param parameter, but CVE source inspection suggests that this is erroneous. | 2% Низкий | больше 4 лет назад | ||
GHSA-25c5-5c5w-53xq Sophos Anti-Virus before 4.02, 4.5.x before 4.5.9, 4.6.x before 4.6.9, and 5.x before 5.1.4 allow remote attackers to hide arbitrary files and data via crafted ARJ archives, which are not properly scanned. | 8% Низкий | больше 4 лет назад | ||
GHSA-25c5-58xw-hw5q Jenkins allows Remote Users to Build Arbitrary Jobs | 2% Низкий | больше 4 лет назад | ||
GHSA-25c3-h67j-g2qq Insufficient data validation in Directory in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass file system restrictions via a crafted HTML page. (Chromium security severity: Medium) | CVSS3: 8.8 | 1% Низкий | почти 4 года назад | |
GHSA-25c3-7fvj-v45j phpMyFAQ Stored Cross-site Scripting vulnerability | CVSS3: 5.4 | 0% Низкий | больше 3 лет назад | |
GHSA-25c3-4v7x-3hrp A vulnerability, which was classified as critical, was found in openBI up to 6.0.3. Affected is the function addxinzhi of the file application/controllers/User.php of the component Phar Handler. The manipulation of the argument outimgurl leads to deserialization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252696. | CVSS3: 6.3 | 1% Низкий | больше 2 лет назад | |
GHSA-25c3-3rg2-gf39 In SweetScape 010 Editor 9.0.1, improper validation of arguments in the internal implementation of the WSubStr function (provided by the scripting engine) allows an attacker to cause a denial of service by crashing the application. | 1% Низкий | больше 4 лет назад | ||
GHSA-259x-xg45-mf97 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/incoming.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | CVSS3: 6.4 | 0% Низкий | 5 месяцев назад | |
GHSA-259x-wgj2-g49m Unspecified vulnerability in Sun Java System Application Server 7 2004Q2 before Update 6, Web Server 6.1 before SP8, and Web Server 7.0 before Update 1 allows remote attackers to obtain source code of JSP files via unknown vectors. | 2% Низкий | больше 4 лет назад | ||
GHSA-259x-v826-2fcj IBM SPSS Modeler 16.0 before 16.0.0.1 on UNIX does not properly drop group privileges, which allows local users to bypass intended file-access restrictions by leveraging (1) gid 0 or (2) root's group memberships. | 0% Низкий | больше 4 лет назад | ||
GHSA-259w-fqv8-xvgh Acronis True Image prior to 2021 Update 4 for Windows allowed local privilege escalation due to improper soft link handling (issue 1 of 2). | 0% Низкий | больше 4 лет назад | ||
GHSA-259w-8hf6-59c2 OCI image importer memory exhaustion in github.com/containerd/containerd | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
GHSA-259w-3jff-442h The PixelYourSite WordPress plugin before 11.1.2 does not validate some URL parameters before using them to generate paths passed to function/s, allowing any admins to perform LFI attacks | CVSS3: 2.7 | 0% Низкий | 11 месяцев назад | |
GHSA-259v-xm34-p7fr Typo3 Cross-Site Scripting in Language Pack Handling | больше 2 лет назад | |||
GHSA-259v-fw35-w989 golang/go in 1.0.2 fixes all.bash on shared machines. dotest() in src/pkg/debug/gosym/pclntab_test.go creates a temporary file with predicable name and executes it as shell script. | 2% Низкий | больше 4 лет назад | ||
GHSA-259r-6293-4g55 SQL injection vulnerability in the Search::setJsonAlert method in OSClass before 3.4.3 allows remote attackers to execute arbitrary SQL commands via the alert parameter in a search alert subscription action. | 2% Низкий | больше 4 лет назад | ||
GHSA-259r-5hvg-4f6x win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted application, aka "Win32k Elevation of Privilege Vulnerability." | CVSS3: 8.8 | 15% Средний | больше 4 лет назад | |
GHSA-259r-2fr5-87c3 An issue in Daily Habit Tracker v.1.0 allows a remote attacker to manipulate trackers via the home.php, add-tracker.php, delete-tracker.php, update-tracker.php components. | CVSS3: 9.8 | 20% Средний | больше 2 лет назад | |
GHSA-259q-pfhc-h3v8 A vulnerability was found in deerwms deer-wms-2 up to 3.3. It has been classified as critical. Affected is an unknown function of the file /system/dept/edit. The manipulation of the argument ancestors leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 6.3 | 0% Низкий | около 1 года назад | |
GHSA-259q-j44w-v653 An issue was discovered in Atos Eviden IDRA before 2.7.1. A highly trusted role (Config Admin) could leverage a race condition to escalate privileges. | CVSS3: 8 | 0% Низкий | больше 1 года назад |
Уязвимостей на страницу