Количество 370 841
Количество 370 841
GHSA-252c-7783-4v3h
Unauthenticated Broken Access Control in User Registration <= 5.2.2 versions.
GHSA-252c-46fv-6xqv
ServerManagement master branch as of commit 49491cc6f94980e6be7791d17be947c27071eb56 is affected by a directory traversal vulnerability. This vulnerability can be used to extract credentials which can in turn be used to execute code.
GHSA-252c-3wxj-m4q8
Improper privilege management for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Privileged Process may allow an escalation of privilege. Unprivileged software adversary with an unauthenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (low), integrity (low) and availability (high) impacts.
GHSA-2529-rwp4-75f6
It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e.g. via "View -> Feed article -> Website" or in the standard format of "View -> Feed article -> default format". This vulnerability affects Thunderbird < 52.5.2.
GHSA-2529-cmp4-x7vg
HP-UX aserver program allows local users to gain privileges via a symlink attack.
GHSA-2529-45pr-jcrg
Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized information exposure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a lower-privileged user can cause data from sources they are not authorized to access to be processed using another user's privileges.
GHSA-2528-jw5q-ww88
phpseclib: guardrails needed on isPrime and randomPrime
GHSA-2528-h86j-954v
In JetBrains TeamCity before 2021.1.3, a newly created project could take settings from an already deleted project.
GHSA-2527-g53r-vw26
In HarmfulAppWarningActivity of HarmfulAppWarningActivity.java, there is a possible way to trick victim to install harmful app due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-205595291
GHSA-2526-24jx-77pp
Privilege Escalation vulnerability in McAfee Total Protection (MTP) prior to 16.0.R26 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee delete action to an unintended file. This is achieved through running a malicious script or program on the target machine.
GHSA-2524-6f4r-2jq9
SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious commands with root privileges in SAP Host Agent via SAP Landscape Management.
GHSA-2524-2jp2-r468
SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability
GHSA-2523-xvgc-mmh8
Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability
GHSA-2523-vcxw-6v95
In libhidcommand_jni, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the USB service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111363077
GHSA-2523-v9j2-g44c
Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6) Vulnerable parameters: &post_title, &downloadable_file_version[0].
GHSA-2523-mx65-hm92
NASM 2.16 (development) is vulnerable to 476: Null Pointer Dereference via output/outaout.c.
GHSA-2522-v35m-2r22
jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonController::doUploadAndInstall.
GHSA-2522-mrjc-m688
Apache Airflow: Sensitive configuration for providers displayed when "non-sensitive-only" config used
GHSA-2522-8f97-8gg8
Unspecified vulnerability in Adobe Breeze 5 Licensed Server and Breeze 5.1 Licensed Server allows attackers to read arbitrary files via unknown vectors related to "URL parsing."
GHSA-24xx-mgc5-v24w
The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 67.7.0 via the 'page' parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included. The Local File Inclusion exploit can be chained to include various dashboard view files in the plugin. One in particular reported by the researcher can be leveraged to update the password of Super Administrator accounts in Multisite environments making privilege escalation possible.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-252c-7783-4v3h Unauthenticated Broken Access Control in User Registration <= 5.2.2 versions. | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
GHSA-252c-46fv-6xqv ServerManagement master branch as of commit 49491cc6f94980e6be7791d17be947c27071eb56 is affected by a directory traversal vulnerability. This vulnerability can be used to extract credentials which can in turn be used to execute code. | 2% Низкий | больше 4 лет назад | ||
GHSA-252c-3wxj-m4q8 Improper privilege management for some Intel(R) PROSet/Wireless WiFi Software for Windows within Ring 2: Privileged Process may allow an escalation of privilege. Unprivileged software adversary with an unauthenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (low), integrity (low) and availability (high) impacts. | CVSS3: 7.3 | 0% Низкий | около 1 месяца назад | |
GHSA-2529-rwp4-75f6 It is possible to execute JavaScript in the parsed RSS feed when RSS feed is viewed as a website, e.g. via "View -> Feed article -> Website" or in the standard format of "View -> Feed article -> default format". This vulnerability affects Thunderbird < 52.5.2. | CVSS3: 8.8 | 2% Низкий | больше 4 лет назад | |
GHSA-2529-cmp4-x7vg HP-UX aserver program allows local users to gain privileges via a symlink attack. | 1% Низкий | больше 4 лет назад | ||
GHSA-2529-45pr-jcrg Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized information exposure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a lower-privileged user can cause data from sources they are not authorized to access to be processed using another user's privileges. | CVSS3: 4.3 | 0% Низкий | около 2 месяцев назад | |
GHSA-2528-jw5q-ww88 phpseclib: guardrails needed on isPrime and randomPrime | CVSS3: 7.5 | 1% Низкий | 4 месяца назад | |
GHSA-2528-h86j-954v In JetBrains TeamCity before 2021.1.3, a newly created project could take settings from an already deleted project. | 1% Низкий | больше 4 лет назад | ||
GHSA-2527-g53r-vw26 In HarmfulAppWarningActivity of HarmfulAppWarningActivity.java, there is a possible way to trick victim to install harmful app due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12LAndroid ID: A-205595291 | CVSS3: 7.3 | 0% Низкий | больше 4 лет назад | |
GHSA-2526-24jx-77pp Privilege Escalation vulnerability in McAfee Total Protection (MTP) prior to 16.0.R26 allows local users to delete files the user would otherwise not have access to via manipulating symbolic links to redirect a McAfee delete action to an unintended file. This is achieved through running a malicious script or program on the target machine. | CVSS3: 6.3 | 0% Низкий | больше 4 лет назад | |
GHSA-2524-6f4r-2jq9 SAP Landscape Management, version 3.0, allows an attacker with admin privileges to execute malicious commands with root privileges in SAP Host Agent via SAP Landscape Management. | 2% Низкий | больше 4 лет назад | ||
GHSA-2524-2jp2-r468 SQL Server Native Client OLE DB Provider Remote Code Execution Vulnerability | CVSS3: 8.8 | 2% Низкий | около 2 лет назад | |
GHSA-2523-xvgc-mmh8 Microsoft Windows Storage Port Driver Elevation of Privilege Vulnerability | CVSS3: 7.8 | 4% Низкий | почти 2 года назад | |
GHSA-2523-vcxw-6v95 In libhidcommand_jni, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege in the USB service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: AndroidVersions: Android-10Android ID: A-111363077 | CVSS3: 6.8 | 0% Низкий | больше 4 лет назад | |
GHSA-2523-v9j2-g44c Authenticated (admin+) Persistent Cross-Site Scripting (XSS) vulnerability discovered in Download Monitor WordPress plugin (versions <= 4.4.6) Vulnerable parameters: &post_title, &downloadable_file_version[0]. | CVSS3: 4.8 | 84% Высокий | больше 4 лет назад | |
GHSA-2523-mx65-hm92 NASM 2.16 (development) is vulnerable to 476: Null Pointer Dereference via output/outaout.c. | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
GHSA-2522-v35m-2r22 jpress v4.2.0 is vulnerable to command execution via io.jpress.web.admin._AddonController::doUploadAndInstall. | CVSS3: 9.8 | 2% Низкий | больше 4 лет назад | |
GHSA-2522-mrjc-m688 Apache Airflow: Sensitive configuration for providers displayed when "non-sensitive-only" config used | CVSS3: 4.3 | 1% Низкий | больше 2 лет назад | |
GHSA-2522-8f97-8gg8 Unspecified vulnerability in Adobe Breeze 5 Licensed Server and Breeze 5.1 Licensed Server allows attackers to read arbitrary files via unknown vectors related to "URL parsing." | 3% Низкий | больше 4 лет назад | ||
GHSA-24xx-mgc5-v24w The WPGYM - Wordpress Gym Management System plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 67.7.0 via the 'page' parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included. The Local File Inclusion exploit can be chained to include various dashboard view files in the plugin. One in particular reported by the researcher can be leveraged to update the password of Super Administrator accounts in Multisite environments making privilege escalation possible. | CVSS3: 8.8 | 1% Низкий | около 1 года назад |
Уязвимостей на страницу