Количество 325 632
Количество 325 632
GHSA-xq4m-cj98-7hg9
Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality, integrity, and availability via vectors related to IPS transfer module, a different vulnerability than CVE-2014-4280.
GHSA-xq4j-x39q-xhqm
A zip-slip path traversal vulnerability in Spring Data Geode's import snapshot functionality allows attackers to write files outside the intended extraction directory. This vulnerability appears to be susceptible on Windows OS only.
GHSA-xq4j-rv6r-ch63
Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the 'view' parameter in '/student/index.php'.
GHSA-xq4j-j5qp-3mfq
Insufficient control flow management in AmdCpmOemSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to an escalation of privileges.
GHSA-xq4h-wqm2-668w
Babylon's BIP322 signature implementation is not fully compliant to the spec
GHSA-xq4h-hmq6-ghrv
Mozilla Firefox 38.0 and Firefox ESR 38.0 allow user-assisted remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges via a crafted web site that is accessed with unspecified mouse and keyboard actions. NOTE: this vulnerability exists because of a CVE-2015-0821 regression.
GHSA-xq4h-8qpv-793q
in OpenHarmony v4.1.1 and prior versions allow a local attacker cause information leak through out-of-bounds Read.
GHSA-xq4h-4mpj-q5jr
Transient DOS while processing TID-to-link mapping IE elements.
GHSA-xq4g-vf85-h54p
EspoCRM version 5.6.4 is vulnerable to stored XSS due to lack of filtration of user-supplied data in the api/v1/Document functionality for storing documents in the account tab. An attacker can upload a crafted file that contains JavaScript code in its name. This code will be executed when a user opens a page of any profile with this.
GHSA-xq4g-5hpc-wfcx
An arbitrary file upload vulnerability in Zhongcheng Kexin Ticketing Management Platform 20.04 allows attackers to execute arbitrary code via uploading a crafted file.
GHSA-xq4f-rq5v-998c
Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk Enterprise 6.1.x before 6.1.3 allows remote attackers to inject arbitrary web script or HTML via the Referer HTTP header.
GHSA-xq4f-j8wj-pf7x
An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in expand_mmacro() in modules/preprocs/nasm/nasm-pp.c.
GHSA-xq4f-f2vc-9hxr
The WebDorado Contact Form plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via directory traversal, because there can be a discrepancy between the $_POST['action'] value and the $_GET['action'] value, and the latter is unsanitized.
GHSA-xq4f-cq2m-g7xp
Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
GHSA-xq4f-9xp4-279p
A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma 14.6, macOS Monterey 12.7.6, macOS Ventura 13.6.8. An app may be able to access information about a user’s contacts.
GHSA-xq4f-3jxp-qv6m
csvjson vulnerable to prototype injection
GHSA-xq4c-v44m-4gw8
Directory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 through 2.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: this vulnerability exists due to an incomplete fix to CVE-2015-4180.
GHSA-xq4c-q7v4-538j
arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel through 3.17.2 does not have an exit handler for the INVVPID instruction, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application.
GHSA-xq4c-4fcc-74mp
There is a Null pointer dereference vulnerability in the camera module in smartphones. Successful exploitation of this vulnerability may affect service integrity.
GHSA-xq49-p575-q243
Quake 2 server 3.13 on Linux does not properly check file permissions for the config.cfg configuration file, which allows local users to read arbitrary files via a symlink from config.cfg to the target file.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xq4m-cj98-7hg9 Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality, integrity, and availability via vectors related to IPS transfer module, a different vulnerability than CVE-2014-4280. | 0% Низкий | почти 4 года назад | ||
GHSA-xq4j-x39q-xhqm A zip-slip path traversal vulnerability in Spring Data Geode's import snapshot functionality allows attackers to write files outside the intended extraction directory. This vulnerability appears to be susceptible on Windows OS only. | CVSS3: 8.2 | 0% Низкий | около 2 месяцев назад | |
GHSA-xq4j-rv6r-ch63 Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the 'view' parameter in '/student/index.php'. | CVSS3: 7.1 | 0% Низкий | больше 1 года назад | |
GHSA-xq4j-j5qp-3mfq Insufficient control flow management in AmdCpmOemSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to an escalation of privileges. | CVSS3: 8.8 | 0% Низкий | около 3 лет назад | |
GHSA-xq4h-wqm2-668w Babylon's BIP322 signature implementation is not fully compliant to the spec | 5 месяцев назад | |||
GHSA-xq4h-hmq6-ghrv Mozilla Firefox 38.0 and Firefox ESR 38.0 allow user-assisted remote attackers to read arbitrary files or execute arbitrary JavaScript code with chrome privileges via a crafted web site that is accessed with unspecified mouse and keyboard actions. NOTE: this vulnerability exists because of a CVE-2015-0821 regression. | 1% Низкий | почти 4 года назад | ||
GHSA-xq4h-8qpv-793q in OpenHarmony v4.1.1 and prior versions allow a local attacker cause information leak through out-of-bounds Read. | CVSS3: 5.5 | 0% Низкий | больше 1 года назад | |
GHSA-xq4h-4mpj-q5jr Transient DOS while processing TID-to-link mapping IE elements. | CVSS3: 7.5 | 0% Низкий | больше 1 года назад | |
GHSA-xq4g-vf85-h54p EspoCRM version 5.6.4 is vulnerable to stored XSS due to lack of filtration of user-supplied data in the api/v1/Document functionality for storing documents in the account tab. An attacker can upload a crafted file that contains JavaScript code in its name. This code will be executed when a user opens a page of any profile with this. | CVSS3: 6.1 | 0% Низкий | почти 4 года назад | |
GHSA-xq4g-5hpc-wfcx An arbitrary file upload vulnerability in Zhongcheng Kexin Ticketing Management Platform 20.04 allows attackers to execute arbitrary code via uploading a crafted file. | CVSS3: 9.8 | 0% Низкий | почти 2 года назад | |
GHSA-xq4f-rq5v-998c Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk Enterprise 6.1.x before 6.1.3 allows remote attackers to inject arbitrary web script or HTML via the Referer HTTP header. | 0% Низкий | почти 4 года назад | ||
GHSA-xq4f-j8wj-pf7x An issue was discovered in yasm version 1.3.0. There is a NULL pointer dereference in expand_mmacro() in modules/preprocs/nasm/nasm-pp.c. | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
GHSA-xq4f-f2vc-9hxr The WebDorado Contact Form plugin before 1.13.5 for WordPress allows CSRF via the wp-admin/admin-ajax.php action parameter, with resultant local file inclusion via directory traversal, because there can be a discrepancy between the $_POST['action'] value and the $_GET['action'] value, and the latter is unsanitized. | CVSS3: 8.8 | 0% Низкий | почти 4 года назад | |
GHSA-xq4f-cq2m-g7xp Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. | CVSS3: 5.4 | 0% Низкий | больше 1 года назад | |
GHSA-xq4f-9xp4-279p A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sonoma 14.6, macOS Monterey 12.7.6, macOS Ventura 13.6.8. An app may be able to access information about a user’s contacts. | CVSS3: 5.3 | 0% Низкий | больше 1 года назад | |
GHSA-xq4f-3jxp-qv6m csvjson vulnerable to prototype injection | CVSS3: 7.5 | 0% Низкий | 7 месяцев назад | |
GHSA-xq4c-v44m-4gw8 Directory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 through 2.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: this vulnerability exists due to an incomplete fix to CVE-2015-4180. | CVSS3: 7.5 | 16% Средний | почти 4 года назад | |
GHSA-xq4c-q7v4-538j arch/x86/kvm/vmx.c in the KVM subsystem in the Linux kernel through 3.17.2 does not have an exit handler for the INVVPID instruction, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application. | CVSS3: 5.5 | 0% Низкий | почти 4 года назад | |
GHSA-xq4c-4fcc-74mp There is a Null pointer dereference vulnerability in the camera module in smartphones. Successful exploitation of this vulnerability may affect service integrity. | 0% Низкий | около 4 лет назад | ||
GHSA-xq49-p575-q243 Quake 2 server 3.13 on Linux does not properly check file permissions for the config.cfg configuration file, which allows local users to read arbitrary files via a symlink from config.cfg to the target file. | 0% Низкий | почти 4 года назад |
Уязвимостей на страницу