Количество 325 632
Количество 325 632
GHSA-xpwv-75x9-38q4
Missing Authorization vulnerability in ilGhera JW Player for WordPress.This issue affects JW Player for WordPress: from n/a through 2.3.3.
GHSA-xpwr-42qv-5j22
Unspecified vulnerability in Database Scheduler component in Oracle Database 10.1.0.3 has unknown impact and remote authenticated attack vectors related to sys.dbms_scheduler, aka Vuln# DB19.
GHSA-xpwq-w665-cf7c
Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Excel file, aka "Excel String Variable Vulnerability."
GHSA-xpwq-r3f8-686w
Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver.
GHSA-xpwq-h27p-5wg9
FPT G-97RG6M R4.2.98.035 and G-97RG3 R4.2.43.078 are vulnerable to Remote Command Execution in the ping function.
GHSA-xpwq-6mfc-rr7g
Remedy Mid Tier in BMC Remedy AR System 9.1 allows XSS via the ATTKey parameter in an arsys/servlet/AttachServlet request.
GHSA-xpwp-rq3x-x6v7
Critical severity vulnerability that affects recurly-api-client
GHSA-xpwp-hgm6-qgh5
Multiple cross-site scripting (XSS) vulnerabilities in TeamSpeak Server 2.0.20.1 allow remote attackers to inject arbitrary web script or HTML via (1) the error_text parameter to error_box.html or (2) the ok_title parameter to ok_box.html.
GHSA-xpwm-vrv5-5mgm
A remote unauthenticated attacker can use the firmware update feature on the LAN interface of the device to reset the password for the predefined, low-privileged user “user-app” to the default password.
GHSA-xpwm-m5cr-whm7
A other vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-70897394.
GHSA-xpwj-fc4j-cfm5
Cross-site request forgery (CSRF) vulnerability in the administration interface in Cisco IronPort Encryption Appliance 6.2.4 before 6.2.4.1.1, 6.2.5, 6.2.6, 6.2.7 before 6.2.7.7, 6.3 before 6.3.0.4, and 6.5 before 6.5.0.2; and Cisco IronPort PostX 6.2.1 before 6.2.1.1 and 6.2.2 before 6.2.2.3; allows remote attackers to execute commands and modify appliance preferences as arbitrary users via a logout action.
GHSA-xpwj-7v8q-mcgj
Deno's static imports inside dynamically imported modules do not adhere to permission checks
GHSA-xpwj-39c3-7v9j
Discuz! DiscuzX through X3.4 has stored XSS via the portal.php?mod=portalcp&ac=article URI, related to mishandling of IMG elements associated with remote images.
GHSA-xpwh-g564-whc7
Affected versions of Jira Server allow remote unauthenticated attackers to enumerate issue keys via a missing permissions check in the ActionsAndOperations resource. The affected versions are before 7.13.18, from version 8.0.0 before 8.5.9, and from version 8.6.0 before version 8.12.2.
GHSA-xpwh-c6wc-qg9f
A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to bypass blocked network recipients.
GHSA-xpwh-4xmj-5wrc
An issue has been discovered in GitLab affecting all versions starting from 10.0 to 15.7.8, 15.8 prior to 15.8.4 and 15.9 prior to 15.9.2. A crafted URL could be used to redirect users to arbitrary sites
GHSA-xpwg-v658-286m
Information disclosure may occur during a video call if a device resets due to a non-conforming RTCP packet that doesn`t adhere to RFC standards.
GHSA-xpwg-9vrv-hq2j
A Plaintext Storage of a Password vulnerability in ebooknote function in Hamastar MeetingHub Paperless Meetings 2021 allows remote attackers to obtain the other users’ credentials and gain access to the product via an XML file.
GHSA-xpwf-qvcr-m7xh
SQL injection vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to execute arbitrary SQL commands via the id_document parameter.
GHSA-xpwf-pw24-jcwf
In the Linux kernel, the following vulnerability has been resolved: drivers: staging: rtl8723bs: Fix deadlock in rtw_surveydone_event_callback() There is a deadlock in rtw_surveydone_event_callback(), which is shown below: (Thread 1) | (Thread 2) | _set_timer() rtw_surveydone_event_callback()| mod_timer() spin_lock_bh() //(1) | (wait a time) ... | rtw_scan_timeout_handler() del_timer_sync() | spin_lock_bh() //(2) (wait timer to stop) | ... We hold pmlmepriv->lock in position (1) of thread 1 and use del_timer_sync() to wait timer to stop, but timer handler also need pmlmepriv->lock in position (2) of thread 2. As a result, rtw_surveydone_event_callback() will block forever. This patch extracts del_timer_sync() from the protection of spin_lock_bh(), which could let timer handler to obtain the needed lock. What`s more, we change spin_lock_bh() in rtw_scan_timeou...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xpwv-75x9-38q4 Missing Authorization vulnerability in ilGhera JW Player for WordPress.This issue affects JW Player for WordPress: from n/a through 2.3.3. | CVSS3: 6.5 | 0% Низкий | почти 2 года назад | |
GHSA-xpwr-42qv-5j22 Unspecified vulnerability in Database Scheduler component in Oracle Database 10.1.0.3 has unknown impact and remote authenticated attack vectors related to sys.dbms_scheduler, aka Vuln# DB19. | 7% Низкий | почти 4 года назад | ||
GHSA-xpwq-w665-cf7c Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary code via a crafted Excel file, aka "Excel String Variable Vulnerability." | 57% Средний | почти 4 года назад | ||
GHSA-xpwq-r3f8-686w Memory Corruption when accessing an output buffer without validating its size during IOCTL processing in a camera sensor driver. | CVSS3: 7.8 | 0% Низкий | 3 дня назад | |
GHSA-xpwq-h27p-5wg9 FPT G-97RG6M R4.2.98.035 and G-97RG3 R4.2.43.078 are vulnerable to Remote Command Execution in the ping function. | CVSS3: 8.8 | 3% Низкий | больше 3 лет назад | |
GHSA-xpwq-6mfc-rr7g Remedy Mid Tier in BMC Remedy AR System 9.1 allows XSS via the ATTKey parameter in an arsys/servlet/AttachServlet request. | CVSS3: 5.4 | 0% Низкий | почти 4 года назад | |
GHSA-xpwp-rq3x-x6v7 Critical severity vulnerability that affects recurly-api-client | 1% Низкий | больше 7 лет назад | ||
GHSA-xpwp-hgm6-qgh5 Multiple cross-site scripting (XSS) vulnerabilities in TeamSpeak Server 2.0.20.1 allow remote attackers to inject arbitrary web script or HTML via (1) the error_text parameter to error_box.html or (2) the ok_title parameter to ok_box.html. | 1% Низкий | почти 4 года назад | ||
GHSA-xpwm-vrv5-5mgm A remote unauthenticated attacker can use the firmware update feature on the LAN interface of the device to reset the password for the predefined, low-privileged user “user-app” to the default password. | CVSS3: 8.6 | 5% Низкий | больше 1 года назад | |
GHSA-xpwm-m5cr-whm7 A other vulnerability in the Android media framework (libavc). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0, 8.1. Android ID: A-70897394. | CVSS3: 7.5 | 0% Низкий | почти 4 года назад | |
GHSA-xpwj-fc4j-cfm5 Cross-site request forgery (CSRF) vulnerability in the administration interface in Cisco IronPort Encryption Appliance 6.2.4 before 6.2.4.1.1, 6.2.5, 6.2.6, 6.2.7 before 6.2.7.7, 6.3 before 6.3.0.4, and 6.5 before 6.5.0.2; and Cisco IronPort PostX 6.2.1 before 6.2.1.1 and 6.2.2 before 6.2.2.3; allows remote attackers to execute commands and modify appliance preferences as arbitrary users via a logout action. | 0% Низкий | почти 4 года назад | ||
GHSA-xpwj-7v8q-mcgj Deno's static imports inside dynamically imported modules do not adhere to permission checks | CVSS3: 9.8 | 0% Низкий | больше 4 лет назад | |
GHSA-xpwj-39c3-7v9j Discuz! DiscuzX through X3.4 has stored XSS via the portal.php?mod=portalcp&ac=article URI, related to mishandling of IMG elements associated with remote images. | CVSS3: 5.4 | 0% Низкий | почти 4 года назад | |
GHSA-xpwh-g564-whc7 Affected versions of Jira Server allow remote unauthenticated attackers to enumerate issue keys via a missing permissions check in the ActionsAndOperations resource. The affected versions are before 7.13.18, from version 8.0.0 before 8.5.9, and from version 8.6.0 before version 8.12.2. | CVSS3: 5.3 | 0% Низкий | почти 4 года назад | |
GHSA-xpwh-c6wc-qg9f A user controlled parameter related to SMTP test functionality is not correctly validated making it possible to bypass blocked network recipients. | CVSS3: 7.5 | 0% Низкий | почти 4 года назад | |
GHSA-xpwh-4xmj-5wrc An issue has been discovered in GitLab affecting all versions starting from 10.0 to 15.7.8, 15.8 prior to 15.8.4 and 15.9 prior to 15.9.2. A crafted URL could be used to redirect users to arbitrary sites | CVSS3: 6.1 | 1% Низкий | около 3 лет назад | |
GHSA-xpwg-v658-286m Information disclosure may occur during a video call if a device resets due to a non-conforming RTCP packet that doesn`t adhere to RFC standards. | CVSS3: 8.2 | 0% Низкий | около 1 года назад | |
GHSA-xpwg-9vrv-hq2j A Plaintext Storage of a Password vulnerability in ebooknote function in Hamastar MeetingHub Paperless Meetings 2021 allows remote attackers to obtain the other users’ credentials and gain access to the product via an XML file. | CVSS3: 9.1 | 0% Низкий | больше 1 года назад | |
GHSA-xpwf-qvcr-m7xh SQL injection vulnerability in repository/repository_attachment.php in AlienVault Open Source Security Information Management (OSSIM) 2.1.5, and possibly other versions before 2.1.5-4, allows remote attackers to execute arbitrary SQL commands via the id_document parameter. | 0% Низкий | почти 4 года назад | ||
GHSA-xpwf-pw24-jcwf In the Linux kernel, the following vulnerability has been resolved: drivers: staging: rtl8723bs: Fix deadlock in rtw_surveydone_event_callback() There is a deadlock in rtw_surveydone_event_callback(), which is shown below: (Thread 1) | (Thread 2) | _set_timer() rtw_surveydone_event_callback()| mod_timer() spin_lock_bh() //(1) | (wait a time) ... | rtw_scan_timeout_handler() del_timer_sync() | spin_lock_bh() //(2) (wait timer to stop) | ... We hold pmlmepriv->lock in position (1) of thread 1 and use del_timer_sync() to wait timer to stop, but timer handler also need pmlmepriv->lock in position (2) of thread 2. As a result, rtw_surveydone_event_callback() will block forever. This patch extracts del_timer_sync() from the protection of spin_lock_bh(), which could let timer handler to obtain the needed lock. What`s more, we change spin_lock_bh() in rtw_scan_timeou... | CVSS3: 5.5 | 0% Низкий | около 1 года назад |
Уязвимостей на страницу