Количество 375 268
Количество 375 268
GHSA-255v-hc9m-54wv
Missing Authorization vulnerability in merkulove Laser laser allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Laser: from n/a through <= 1.1.1.
GHSA-255v-grg6-24pg
MotoCMS Version 3.4.3 Store Category Template was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the keyword parameter.
GHSA-255v-ffqg-5w87
Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/?page=appointments/view_appointment.
GHSA-255v-3pqf-6g77
Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network.
GHSA-255r-pghp-r5wh
Malicious Package in hdeky
GHSA-255r-gqmx-m2jm
A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when repeatedly called by a host application or through deep alias nesting, can lead to corruption of internal program data. This corruption could potentially enable a local attacker to execute arbitrary code if the host application then unsafely processes the altered data.
GHSA-255r-f4p7-p9r5
Hacksoft The Hacker 6.3.1.2.174 and possibly 6.3.0.9.081, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit.
GHSA-255r-96jc-w7r6
DVP80ES300T with Improper Validation of Array Index Vulnerability
GHSA-255r-3prx-mf99
`rmp-serde` `Raw` and `RawRef` may crash when receiving invalid UTF-8
GHSA-255q-f9p7-jxj6
Microsoft SharePoint Server Spoofing Vulnerability
GHSA-255p-hfwr-9qm4
This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.4. An app with root privileges may be able to access private information.
GHSA-255p-hfc6-whjx
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14021.
GHSA-255m-x7w5-9w65
Use of Hard-coded Credentials vulnerability in ABB ASPECT-Enterprise, ABB NEXUS Series, ABB MATRIX Series.This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03.
GHSA-255m-v9ff-ggrc
The doPayouts() function of the smart contract implementation for MegaCryptoPolis, an Ethereum game, has a Denial of Service vulnerability. If a smart contract that has a fallback function always causing exceptions buys a land, users cannot buy lands near that contract's land, because those purchase attempts will not be completed unless the doPayouts() function successfully sends Ether to certain neighbors.
GHSA-255m-r5v7-p5hq
A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software improperly validates Advanced Recording Format (ARF) and Webex Recording Format (WRF) files. An attacker could exploit this vulnerability by sending a user a malicious ARF or WRF file via a link or email attachment and persuading the user to open the file with the affected software on the local system. A successful exploit could allow the attacker to execute arbitrary code on the affected system.
GHSA-255m-8v4r-mcgr
In the Linux kernel, the following vulnerability has been resolved: tls: stop recv() if initial process_rx_list gave us non-DATA If we have a non-DATA record on the rx_list and another record of the same type still on the queue, we will end up merging them: - process_rx_list copies the non-DATA record - we start the loop and process the first available record since it's of the same type - we break out of the loop since the record was not DATA Just check the record type and jump to the end in case process_rx_list did some work.
GHSA-255j-qw47-wjh5
Craft CMS vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior
GHSA-255j-gp8h-r5hh
The documents application in ownCloud Server 6.x before 6.0.6 and 7.x before 7.0.3 allows remote authenticated users to obtain all valid session IDs via an unspecified API method.
GHSA-255j-5m9h-c8jh
The OpenBook Book Data WordPress plugin through 3.5.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping as well
GHSA-255j-56mh-hp3w
IBM UrbanCode Deploy (UCD) 6.1 and 6.2 could allow an authenticated user to edit objects that they should not have access to due to improper access controls. IBM X-Force ID: 128691.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-255v-hc9m-54wv Missing Authorization vulnerability in merkulove Laser laser allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Laser: from n/a through <= 1.1.1. | CVSS3: 5.4 | 0% Низкий | 9 месяцев назад | |
GHSA-255v-grg6-24pg MotoCMS Version 3.4.3 Store Category Template was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the keyword parameter. | CVSS3: 9.8 | 31% Средний | около 3 лет назад | |
GHSA-255v-ffqg-5w87 Online Diagnostic Lab Management System v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at /odlms/?page=appointments/view_appointment. | CVSS3: 8.8 | 1% Низкий | почти 4 года назад | |
GHSA-255v-3pqf-6g77 Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a network. | CVSS3: 6.5 | 0% Низкий | около 1 месяца назад | |
GHSA-255r-pghp-r5wh Malicious Package in hdeky | CVSS3: 9.1 | около 6 лет назад | ||
GHSA-255r-gqmx-m2jm A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when repeatedly called by a host application or through deep alias nesting, can lead to corruption of internal program data. This corruption could potentially enable a local attacker to execute arbitrary code if the host application then unsafely processes the altered data. | CVSS3: 2.5 | 0% Низкий | около 2 месяцев назад | |
GHSA-255r-f4p7-p9r5 Hacksoft The Hacker 6.3.1.2.174 and possibly 6.3.0.9.081, when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an MZ header (aka "EXE info") at the beginning, and modifying the filename to have (1) no extension, (2) a .txt extension, or (3) a .jpg extension, as demonstrated by a document containing a CVE-2006-5745 exploit. | 2% Низкий | больше 4 лет назад | ||
GHSA-255r-96jc-w7r6 DVP80ES300T with Improper Validation of Array Index Vulnerability | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
GHSA-255r-3prx-mf99 `rmp-serde` `Raw` and `RawRef` may crash when receiving invalid UTF-8 | больше 3 лет назад | |||
GHSA-255q-f9p7-jxj6 Microsoft SharePoint Server Spoofing Vulnerability | CVSS3: 8 | 2% Низкий | около 3 лет назад | |
GHSA-255p-hfwr-9qm4 This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Monterey 12.4. An app with root privileges may be able to access private information. | CVSS3: 4.4 | 0% Низкий | почти 4 года назад | |
GHSA-255p-hfc6-whjx This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader 11.0.0.49893. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-14021. | 4% Низкий | больше 4 лет назад | ||
GHSA-255m-x7w5-9w65 Use of Hard-coded Credentials vulnerability in ABB ASPECT-Enterprise, ABB NEXUS Series, ABB MATRIX Series.This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03. | CVSS3: 9.8 | 1% Низкий | больше 1 года назад | |
GHSA-255m-v9ff-ggrc The doPayouts() function of the smart contract implementation for MegaCryptoPolis, an Ethereum game, has a Denial of Service vulnerability. If a smart contract that has a fallback function always causing exceptions buys a land, users cannot buy lands near that contract's land, because those purchase attempts will not be completed unless the doPayouts() function successfully sends Ether to certain neighbors. | CVSS3: 7.5 | 1% Низкий | больше 4 лет назад | |
GHSA-255m-r5v7-p5hq A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected software improperly validates Advanced Recording Format (ARF) and Webex Recording Format (WRF) files. An attacker could exploit this vulnerability by sending a user a malicious ARF or WRF file via a link or email attachment and persuading the user to open the file with the affected software on the local system. A successful exploit could allow the attacker to execute arbitrary code on the affected system. | CVSS3: 7.8 | 2% Низкий | больше 4 лет назад | |
GHSA-255m-8v4r-mcgr In the Linux kernel, the following vulnerability has been resolved: tls: stop recv() if initial process_rx_list gave us non-DATA If we have a non-DATA record on the rx_list and another record of the same type still on the queue, we will end up merging them: - process_rx_list copies the non-DATA record - we start the loop and process the first available record since it's of the same type - we break out of the loop since the record was not DATA Just check the record type and jump to the end in case process_rx_list did some work. | CVSS3: 5.5 | 0% Низкий | около 1 года назад | |
GHSA-255j-qw47-wjh5 Craft CMS vulnerable to potential authenticated Remote Code Execution via malicious attached Behavior | 1% Низкий | 9 месяцев назад | ||
GHSA-255j-gp8h-r5hh The documents application in ownCloud Server 6.x before 6.0.6 and 7.x before 7.0.3 allows remote authenticated users to obtain all valid session IDs via an unspecified API method. | 1% Низкий | больше 4 лет назад | ||
GHSA-255j-5m9h-c8jh The OpenBook Book Data WordPress plugin through 3.5.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack and lead to Stored Cross-Site Scripting due to the lack of sanitisation and escaping as well | CVSS3: 4.3 | 0% Низкий | около 4 лет назад | |
GHSA-255j-56mh-hp3w IBM UrbanCode Deploy (UCD) 6.1 and 6.2 could allow an authenticated user to edit objects that they should not have access to due to improper access controls. IBM X-Force ID: 128691. | CVSS3: 5.4 | 1% Низкий | больше 4 лет назад |
Уязвимостей на страницу