Количество 355 628
Количество 355 628
GHSA-xqmg-px28-29cq
Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.
GHSA-xqmg-8q55-7xxx
The libsecurity library in HP-UX 11.04 (VVOS) allows attackers to cause a denial of service.
GHSA-xqmf-wf6x-2cx6
Improper access control in the Intel(R) NUC HDMI Firmware Update Tool for NUC7i3DN, NUC7i5DN and NUC7i7DN before version 1.78.2.0.7 may allow an authenticated user to potentially enable escalation of privilege via local access.
GHSA-xqmc-wh95-fg2q
Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=result&searchfor=byfunction.
GHSA-xqmc-vc6c-2wmv
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 200966.
GHSA-xqmc-v3x5-h7p2
SAP Manufacturing Execution - versions 15.1, 15.2, 15.3, allows an attacker to exploit insufficient validation of a file path request parameter. The intended file path can be manipulated to allow arbitrary traversal of directories on the remote server. The file content within each directory can be read which may lead to information disclosure.
GHSA-xqmc-g86x-qfxp
Some Honor products are affected by out of bounds read vulnerability, successful exploitation could cause information leak.
GHSA-xqmc-7954-658r
ImageMagick through 7.1.2-18 contains a memory leak vulnerability in the ASHLAR coder when an action fails. Attackers can trigger failed actions to exhaust memory resources and cause denial of service.
GHSA-xqm9-hpfh-qm5m
Cross-site scripting (XSS) vulnerability in display.php in HyperVM 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via an encoded frm_action parameter. NOTE: the vendor disputes this issue, but it is not certain whether the dispute is about the severity of the issue, or its existence.
GHSA-xqm9-g4jx-xvgw
Metamail before 2.7-7.2 allows remote attackers to overwrite arbitrary files via an e-mail message containing a uuencoded attachment that specifies the full pathname for the file to be modified, which is processed by uuencode in Metamail scripts such as sun-audio-file.
GHSA-xqm9-6qmm-xrqh
Feehi CMS has authenticated stored cross-site scripting (XSS) vulnerabilities via the Permissions module
GHSA-xqm9-4fqc-qh7w
On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x, a stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to execute JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
GHSA-xqm9-2mv3-cvx4
A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application lacks sufficient authorization checks. This could allow an attacker to access confidential information, perform administrative functions, or lead to a denial-of-service condition.
GHSA-xqm8-jv67-vcvj
Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'demail' parameter of the update.php resource does not validate the characters received and they are sent unfiltered to the database.
GHSA-xqm8-c3rv-5vpf
FFmpeg n6.1.1 has a vulnerability in the DXA demuxer of the libavformat library allowing for an integer overflow, potentially resulting in a denial-of-service (DoS) condition or other undefined behavior.
GHSA-xqm7-qxfg-5xwm
A vulnerability in TeamViewer DEX Client (former 1E client) - Content Distribution Service (NomadBranch.exe) prior version 25.11 for Windows allows malicious actors to bypass file integrity validation via a crafted request. By providing a valid hash for a malicious file, an attacker can cause the service to incorrectly validate and process the file as trusted, enabling arbitrary code execution under the Nomad Branch service context.
GHSA-xqm7-6qm9-wrqm
The Ninja Forms Google Sheet Connector WordPress plugin before 1.2.7, gsheetconnector-ninja-forms-pro WordPress plugin through 1.2.7 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
GHSA-xqm7-6fmh-f42h
Unspecified vulnerability in Oracle MySQL 5.5.50 and earlier, 5.6.31 and earlier, and 5.7.13 and earlier allows remote authenticated users to affect availability via vectors related to DML.
GHSA-xqm6-6gwm-hwpw
The JPEGWarningHandler function in coders/jpeg.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (memory consumption) via a JPEG image with a crafted sequence of restart markers.
GHSA-xqm5-rpmp-48hp
Session fixation vulnerability in Cybozu Garoon 4.0.0 to 4.2.4 allows remote attackers to perform arbitrary operations via unspecified vectors.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xqmg-px28-29cq Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally. | CVSS3: 7.8 | 1% Низкий | около 1 года назад | |
GHSA-xqmg-8q55-7xxx The libsecurity library in HP-UX 11.04 (VVOS) allows attackers to cause a denial of service. | 1% Низкий | больше 4 лет назад | ||
GHSA-xqmf-wf6x-2cx6 Improper access control in the Intel(R) NUC HDMI Firmware Update Tool for NUC7i3DN, NUC7i5DN and NUC7i7DN before version 1.78.2.0.7 may allow an authenticated user to potentially enable escalation of privilege via local access. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-xqmc-wh95-fg2q Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=result&searchfor=byfunction. | CVSS3: 7.2 | 1% Низкий | около 4 лет назад | |
GHSA-xqmc-vc6c-2wmv IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 200966. | 1% Низкий | около 4 лет назад | ||
GHSA-xqmc-v3x5-h7p2 SAP Manufacturing Execution - versions 15.1, 15.2, 15.3, allows an attacker to exploit insufficient validation of a file path request parameter. The intended file path can be manipulated to allow arbitrary traversal of directories on the remote server. The file content within each directory can be read which may lead to information disclosure. | CVSS3: 7.5 | 7% Низкий | почти 4 года назад | |
GHSA-xqmc-g86x-qfxp Some Honor products are affected by out of bounds read vulnerability, successful exploitation could cause information leak. | CVSS3: 6 | 0% Низкий | больше 2 лет назад | |
GHSA-xqmc-7954-658r ImageMagick through 7.1.2-18 contains a memory leak vulnerability in the ASHLAR coder when an action fails. Attackers can trigger failed actions to exhaust memory resources and cause denial of service. | CVSS3: 3.3 | 0% Низкий | 25 дней назад | |
GHSA-xqm9-hpfh-qm5m Cross-site scripting (XSS) vulnerability in display.php in HyperVM 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via an encoded frm_action parameter. NOTE: the vendor disputes this issue, but it is not certain whether the dispute is about the severity of the issue, or its existence. | 2% Низкий | больше 4 лет назад | ||
GHSA-xqm9-g4jx-xvgw Metamail before 2.7-7.2 allows remote attackers to overwrite arbitrary files via an e-mail message containing a uuencoded attachment that specifies the full pathname for the file to be modified, which is processed by uuencode in Metamail scripts such as sun-audio-file. | 1% Низкий | больше 4 лет назад | ||
GHSA-xqm9-6qmm-xrqh Feehi CMS has authenticated stored cross-site scripting (XSS) vulnerabilities via the Permissions module | CVSS3: 5.4 | 0% Низкий | 4 месяца назад | |
GHSA-xqm9-4fqc-qh7w On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x, a stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to execute JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 1% Низкий | около 4 лет назад | ||
GHSA-xqm9-2mv3-cvx4 A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application lacks sufficient authorization checks. This could allow an attacker to access confidential information, perform administrative functions, or lead to a denial-of-service condition. | CVSS3: 8.8 | 0% Низкий | почти 3 года назад | |
GHSA-xqm8-jv67-vcvj Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'demail' parameter of the update.php resource does not validate the characters received and they are sent unfiltered to the database. | CVSS3: 9.8 | 1% Низкий | больше 2 лет назад | |
GHSA-xqm8-c3rv-5vpf FFmpeg n6.1.1 has a vulnerability in the DXA demuxer of the libavformat library allowing for an integer overflow, potentially resulting in a denial-of-service (DoS) condition or other undefined behavior. | CVSS3: 6.2 | 0% Низкий | больше 1 года назад | |
GHSA-xqm7-qxfg-5xwm A vulnerability in TeamViewer DEX Client (former 1E client) - Content Distribution Service (NomadBranch.exe) prior version 25.11 for Windows allows malicious actors to bypass file integrity validation via a crafted request. By providing a valid hash for a malicious file, an attacker can cause the service to incorrectly validate and process the file as trusted, enabling arbitrary code execution under the Nomad Branch service context. | CVSS3: 8.8 | 0% Низкий | 8 месяцев назад | |
GHSA-xqm7-6qm9-wrqm The Ninja Forms Google Sheet Connector WordPress plugin before 1.2.7, gsheetconnector-ninja-forms-pro WordPress plugin through 1.2.7 does not escape a parameter before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | CVSS3: 6.1 | 1% Низкий | около 3 лет назад | |
GHSA-xqm7-6fmh-f42h Unspecified vulnerability in Oracle MySQL 5.5.50 and earlier, 5.6.31 and earlier, and 5.7.13 and earlier allows remote authenticated users to affect availability via vectors related to DML. | CVSS3: 6.5 | 3% Низкий | около 4 лет назад | |
GHSA-xqm6-6gwm-hwpw The JPEGWarningHandler function in coders/jpeg.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (memory consumption) via a JPEG image with a crafted sequence of restart markers. | CVSS3: 6.5 | 2% Низкий | больше 4 лет назад | |
GHSA-xqm5-rpmp-48hp Session fixation vulnerability in Cybozu Garoon 4.0.0 to 4.2.4 allows remote attackers to perform arbitrary operations via unspecified vectors. | CVSS3: 5.4 | 1% Низкий | около 4 лет назад |
Уязвимостей на страницу