Количество 375 268
Количество 375 268
GHSA-25c8-fq6j-8vvf
Memory corruption while processing MFC channel configuration during music playback.
GHSA-25c8-fmh2-q3pg
IBM WebSphere Message Broker 6.1.x before 6.1.0.2 writes a database connection password to the Event Log and System Log during exception handling for a JDBC error, which allows local users to obtain sensitive information by reading these logs.
GHSA-25c8-fc6x-9x37
Insecure deserialization of untrusted input in StellarGroup HPX 1.11.0 under certain conditions may allow attackers to execute arbitrary code or other unspecified impacts.
GHSA-25c7-67gf-gc43
A URL redirection to untrusted site vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow URL redirection to untrusted site.
GHSA-25c7-5442-g7pq
Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.1.10111, does not properly restrict access to memory associated with unmanaged objects, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, (3) a crafted .NET Framework application, or (4) a crafted Silverlight application, aka ".NET Framework Unmanaged Objects Vulnerability."
GHSA-25c7-47pw-x5cf
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
GHSA-25c5-9pxc-899f
index.php in WebMplayer before 0.6.1-Alpha allows remote attackers to execute arbitrary code via shell metacharacters in an exec function call. NOTE: some sources have referred to this as eval injection in the param parameter, but CVE source inspection suggests that this is erroneous.
GHSA-25c5-5c5w-53xq
Sophos Anti-Virus before 4.02, 4.5.x before 4.5.9, 4.6.x before 4.6.9, and 5.x before 5.1.4 allow remote attackers to hide arbitrary files and data via crafted ARJ archives, which are not properly scanned.
GHSA-25c5-58xw-hw5q
Jenkins allows Remote Users to Build Arbitrary Jobs
GHSA-25c3-h67j-g2qq
Insufficient data validation in Directory in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass file system restrictions via a crafted HTML page. (Chromium security severity: Medium)
GHSA-25c3-7fvj-v45j
phpMyFAQ Stored Cross-site Scripting vulnerability
GHSA-25c3-4v7x-3hrp
A vulnerability, which was classified as critical, was found in openBI up to 6.0.3. Affected is the function addxinzhi of the file application/controllers/User.php of the component Phar Handler. The manipulation of the argument outimgurl leads to deserialization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252696.
GHSA-25c3-3rg2-gf39
In SweetScape 010 Editor 9.0.1, improper validation of arguments in the internal implementation of the WSubStr function (provided by the scripting engine) allows an attacker to cause a denial of service by crashing the application.
GHSA-259x-xg45-mf97
Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/incoming.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page.
GHSA-259x-wgj2-g49m
Unspecified vulnerability in Sun Java System Application Server 7 2004Q2 before Update 6, Web Server 6.1 before SP8, and Web Server 7.0 before Update 1 allows remote attackers to obtain source code of JSP files via unknown vectors.
GHSA-259x-v826-2fcj
IBM SPSS Modeler 16.0 before 16.0.0.1 on UNIX does not properly drop group privileges, which allows local users to bypass intended file-access restrictions by leveraging (1) gid 0 or (2) root's group memberships.
GHSA-259w-fqv8-xvgh
Acronis True Image prior to 2021 Update 4 for Windows allowed local privilege escalation due to improper soft link handling (issue 1 of 2).
GHSA-259w-8hf6-59c2
OCI image importer memory exhaustion in github.com/containerd/containerd
GHSA-259w-3jff-442h
The PixelYourSite WordPress plugin before 11.1.2 does not validate some URL parameters before using them to generate paths passed to function/s, allowing any admins to perform LFI attacks
GHSA-259v-xm34-p7fr
Typo3 Cross-Site Scripting in Language Pack Handling
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-25c8-fq6j-8vvf Memory corruption while processing MFC channel configuration during music playback. | CVSS3: 7.8 | 0% Низкий | 9 месяцев назад | |
GHSA-25c8-fmh2-q3pg IBM WebSphere Message Broker 6.1.x before 6.1.0.2 writes a database connection password to the Event Log and System Log during exception handling for a JDBC error, which allows local users to obtain sensitive information by reading these logs. | 0% Низкий | больше 4 лет назад | ||
GHSA-25c8-fc6x-9x37 Insecure deserialization of untrusted input in StellarGroup HPX 1.11.0 under certain conditions may allow attackers to execute arbitrary code or other unspecified impacts. | CVSS3: 9.8 | 0% Низкий | 5 месяцев назад | |
GHSA-25c7-67gf-gc43 A URL redirection to untrusted site vulnerability in HP ArcSight ESM and HP ArcSight ESM Express, in any 6.x version prior to 6.9.1c Patch 4 or 6.11.0 Patch 1. This vulnerability could be exploited remotely to allow URL redirection to untrusted site. | CVSS3: 6.1 | 1% Низкий | больше 4 лет назад | |
GHSA-25c7-5442-g7pq Microsoft .NET Framework 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.1.10111, does not properly restrict access to memory associated with unmanaged objects, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, (3) a crafted .NET Framework application, or (4) a crafted Silverlight application, aka ".NET Framework Unmanaged Objects Vulnerability." | CVSS3: 7.8 | 28% Средний | больше 4 лет назад | |
GHSA-25c7-47pw-x5cf Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | больше 1 года назад | |||
GHSA-25c5-9pxc-899f index.php in WebMplayer before 0.6.1-Alpha allows remote attackers to execute arbitrary code via shell metacharacters in an exec function call. NOTE: some sources have referred to this as eval injection in the param parameter, but CVE source inspection suggests that this is erroneous. | 2% Низкий | больше 4 лет назад | ||
GHSA-25c5-5c5w-53xq Sophos Anti-Virus before 4.02, 4.5.x before 4.5.9, 4.6.x before 4.6.9, and 5.x before 5.1.4 allow remote attackers to hide arbitrary files and data via crafted ARJ archives, which are not properly scanned. | 8% Низкий | больше 4 лет назад | ||
GHSA-25c5-58xw-hw5q Jenkins allows Remote Users to Build Arbitrary Jobs | 2% Низкий | больше 4 лет назад | ||
GHSA-25c3-h67j-g2qq Insufficient data validation in Directory in Google Chrome prior to 108.0.5359.71 allowed a remote attacker to bypass file system restrictions via a crafted HTML page. (Chromium security severity: Medium) | CVSS3: 8.8 | 1% Низкий | почти 4 года назад | |
GHSA-25c3-7fvj-v45j phpMyFAQ Stored Cross-site Scripting vulnerability | CVSS3: 5.4 | 0% Низкий | больше 3 лет назад | |
GHSA-25c3-4v7x-3hrp A vulnerability, which was classified as critical, was found in openBI up to 6.0.3. Affected is the function addxinzhi of the file application/controllers/User.php of the component Phar Handler. The manipulation of the argument outimgurl leads to deserialization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252696. | CVSS3: 6.3 | 1% Низкий | больше 2 лет назад | |
GHSA-25c3-3rg2-gf39 In SweetScape 010 Editor 9.0.1, improper validation of arguments in the internal implementation of the WSubStr function (provided by the scripting engine) allows an attacker to cause a denial of service by crashing the application. | 1% Низкий | больше 4 лет назад | ||
GHSA-259x-xg45-mf97 Endian Firewall version 3.3.25 and prior allow stored cross-site scripting (XSS) via the remark parameter to /cgi-bin/incoming.cgi. An authenticated attacker can inject arbitrary JavaScript that is stored and executed when other users view the affected page. | CVSS3: 6.4 | 0% Низкий | 6 месяцев назад | |
GHSA-259x-wgj2-g49m Unspecified vulnerability in Sun Java System Application Server 7 2004Q2 before Update 6, Web Server 6.1 before SP8, and Web Server 7.0 before Update 1 allows remote attackers to obtain source code of JSP files via unknown vectors. | 2% Низкий | больше 4 лет назад | ||
GHSA-259x-v826-2fcj IBM SPSS Modeler 16.0 before 16.0.0.1 on UNIX does not properly drop group privileges, which allows local users to bypass intended file-access restrictions by leveraging (1) gid 0 or (2) root's group memberships. | 0% Низкий | больше 4 лет назад | ||
GHSA-259w-fqv8-xvgh Acronis True Image prior to 2021 Update 4 for Windows allowed local privilege escalation due to improper soft link handling (issue 1 of 2). | 0% Низкий | больше 4 лет назад | ||
GHSA-259w-8hf6-59c2 OCI image importer memory exhaustion in github.com/containerd/containerd | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
GHSA-259w-3jff-442h The PixelYourSite WordPress plugin before 11.1.2 does not validate some URL parameters before using them to generate paths passed to function/s, allowing any admins to perform LFI attacks | CVSS3: 2.7 | 0% Низкий | 11 месяцев назад | |
GHSA-259v-xm34-p7fr Typo3 Cross-Site Scripting in Language Pack Handling | больше 2 лет назад |
Уязвимостей на страницу