Количество 357 271
Количество 357 271
GHSA-xp7j-9g27-rqpj
Format string vulnerability in scsiopen.c of the cdrecord program in cdrtools 2.0 allows local users to gain privileges via format string specifiers in the dev parameter.
GHSA-xp7h-ghc6-47w2
Memory corruption while parsing IPC frequency table parameters for LPLH that has size greater than expected size.
GHSA-xp7h-368q-wc44
Cross-site scripting (XSS) vulnerability in browse.php in Website Baker Project allows remote attackers to inject arbitrary web script or HTML via the dir parameter.
GHSA-xp7g-78mw-jp2h
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in Safari 13.0.1, iOS 13.1 and iPadOS 13.1, iCloud for Windows 10.7, iCloud for Windows 7.14, tvOS 13, watchOS 6, iTunes 12.10.1 for Windows. Processing maliciously crafted web content may lead to arbitrary code execution.
GHSA-xp7f-xgjj-34wc
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
GHSA-xp7f-v245-w3w8
An issue in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash_uploader/httprequesthandler.py, dash_uploader/upload.py in the Upload function and max_file_size parameter, dash_uploader/configure_upload.py components
GHSA-xp79-9mxw-878j
`finch-rst` was removed from crates.io for malicious code
GHSA-xp79-5mx3-jx52
Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion)
GHSA-xp78-rqf2-cf9c
DLL Search Order Hijacking vulnerability in the Microsoft Windows client in McAfee Tech Check 3.0.0.17 and earlier allows local users to execute arbitrary code via the local folder placed there by an attacker.
GHSA-xp77-qrh7-8wvm
Medical Systems Co. Medisys Weblab Products v19.4.03 was discovered to contain a SQL injection vulnerability via the tem:statement parameter in the WSDL files.
GHSA-xp77-g88w-h7mg
Single Connect does not perform an authorization check when using the sc-reports-ui" module. A remote attacker could exploit this vulnerability to access the device configuration page and export the data to an external file. The exploitation of this vulnerability might allow a remote attacker to obtain sensitive information including the database credentials. Since the database runs with high privileges it is possible to execute commands with the attained credentials.
GHSA-xp77-7ppq-j5jg
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Callback Request allows Reflected XSS. This issue affects Callback Request: from n/a through 1.4.
GHSA-xp76-357g-9wqq
SciPy creates insecure temporary directories
GHSA-xp76-33m9-43ww
XML Injection RCE by parse http sitemap xml response vulnerability in Apache HertzBeat. The attacker needs to have an authenticated account with access, and add monitor parsed by xml, returned special content can trigger the XML parsing vulnerability. This issue affects Apache HertzBeat (incubating): before 1.7.0. Users are recommended to upgrade to version 1.7.0, which fixes the issue.
GHSA-xp75-w7vq-5x6j
OpenDaylight SFC Insecure Shiro Cookie Configuration
GHSA-xp75-r577-cvhp
Privileged OpenBao Operator May Execute Code on the Underlying Host
GHSA-xp73-99p3-8q2g
The Subscriptions feature in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 does not properly validate the publication-source URL, which allows remote authenticated users to trigger arbitrary outbound TCP traffic via a crafted Source field, as demonstrated by (1) an ftp: URL, (2) a gopher: URL, or (3) an http://127.0.0.1/ URL, related to a "Server-side request forging (SSRF)" issue.
GHSA-xp6x-f75w-g3q7
An issue discovered in OpenCart 4.0.0.0 to 4.0.2.3 allows authenticated backend users having common/security write privilege can write arbitrary untrusted data inside config.php and admin/config.php, resulting in remote code execution on the underlying server.
GHSA-xp6x-8hgv-x5w5
A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege escalation or possible remote code execution in cases where X11 forwarding is involved.
GHSA-xp6x-54qx-mg3m
HRSALE 1.1.8 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized administrative users through the employee registration form. Attackers can craft a malicious HTML page with hidden form fields to trick authenticated administrators into creating new user accounts with elevated privileges.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xp7j-9g27-rqpj Format string vulnerability in scsiopen.c of the cdrecord program in cdrtools 2.0 allows local users to gain privileges via format string specifiers in the dev parameter. | 1% Низкий | больше 4 лет назад | ||
GHSA-xp7h-ghc6-47w2 Memory corruption while parsing IPC frequency table parameters for LPLH that has size greater than expected size. | CVSS3: 6.7 | 0% Низкий | почти 2 года назад | |
GHSA-xp7h-368q-wc44 Cross-site scripting (XSS) vulnerability in browse.php in Website Baker Project allows remote attackers to inject arbitrary web script or HTML via the dir parameter. | 1% Низкий | больше 4 лет назад | ||
GHSA-xp7g-78mw-jp2h Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in Safari 13.0.1, iOS 13.1 and iPadOS 13.1, iCloud for Windows 10.7, iCloud for Windows 7.14, tvOS 13, watchOS 6, iTunes 12.10.1 for Windows. Processing maliciously crafted web content may lead to arbitrary code execution. | 1% Низкий | около 4 лет назад | ||
GHSA-xp7f-xgjj-34wc Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. | CVSS3: 5.4 | 0% Низкий | 8 месяцев назад | |
GHSA-xp7f-v245-w3w8 An issue in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash_uploader/httprequesthandler.py, dash_uploader/upload.py in the Upload function and max_file_size parameter, dash_uploader/configure_upload.py components | CVSS3: 7.5 | 3% Низкий | 3 месяца назад | |
GHSA-xp79-9mxw-878j `finch-rst` was removed from crates.io for malicious code | 6 месяцев назад | |||
GHSA-xp79-5mx3-jx52 Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion) | 0% Низкий | около 2 месяцев назад | ||
GHSA-xp78-rqf2-cf9c DLL Search Order Hijacking vulnerability in the Microsoft Windows client in McAfee Tech Check 3.0.0.17 and earlier allows local users to execute arbitrary code via the local folder placed there by an attacker. | 0% Низкий | около 4 лет назад | ||
GHSA-xp77-qrh7-8wvm Medical Systems Co. Medisys Weblab Products v19.4.03 was discovered to contain a SQL injection vulnerability via the tem:statement parameter in the WSDL files. | CVSS3: 9.8 | 1% Низкий | больше 3 лет назад | |
GHSA-xp77-g88w-h7mg Single Connect does not perform an authorization check when using the sc-reports-ui" module. A remote attacker could exploit this vulnerability to access the device configuration page and export the data to an external file. The exploitation of this vulnerability might allow a remote attacker to obtain sensitive information including the database credentials. Since the database runs with high privileges it is possible to execute commands with the attained credentials. | CVSS3: 8.6 | 1% Низкий | больше 4 лет назад | |
GHSA-xp77-7ppq-j5jg Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Callback Request allows Reflected XSS. This issue affects Callback Request: from n/a through 1.4. | CVSS3: 7.1 | 0% Низкий | больше 1 года назад | |
GHSA-xp76-357g-9wqq SciPy creates insecure temporary directories | CVSS3: 7.8 | 0% Низкий | больше 4 лет назад | |
GHSA-xp76-33m9-43ww XML Injection RCE by parse http sitemap xml response vulnerability in Apache HertzBeat. The attacker needs to have an authenticated account with access, and add monitor parsed by xml, returned special content can trigger the XML parsing vulnerability. This issue affects Apache HertzBeat (incubating): before 1.7.0. Users are recommended to upgrade to version 1.7.0, which fixes the issue. | CVSS3: 8.8 | 1% Низкий | 11 месяцев назад | |
GHSA-xp75-w7vq-5x6j OpenDaylight SFC Insecure Shiro Cookie Configuration | CVSS3: 8.1 | 0% Низкий | больше 1 года назад | |
GHSA-xp75-r577-cvhp Privileged OpenBao Operator May Execute Code on the Underlying Host | CVSS3: 9.1 | 0% Низкий | около 1 года назад | |
GHSA-xp73-99p3-8q2g The Subscriptions feature in Open-Xchange Server before 6.20.7 rev14, 6.22.0 before rev13, and 6.22.1 before rev14 does not properly validate the publication-source URL, which allows remote authenticated users to trigger arbitrary outbound TCP traffic via a crafted Source field, as demonstrated by (1) an ftp: URL, (2) a gopher: URL, or (3) an http://127.0.0.1/ URL, related to a "Server-side request forging (SSRF)" issue. | 1% Низкий | около 4 лет назад | ||
GHSA-xp6x-f75w-g3q7 An issue discovered in OpenCart 4.0.0.0 to 4.0.2.3 allows authenticated backend users having common/security write privilege can write arbitrary untrusted data inside config.php and admin/config.php, resulting in remote code execution on the underlying server. | CVSS3: 8.8 | 2% Низкий | больше 2 лет назад | |
GHSA-xp6x-8hgv-x5w5 A flaw was found in xorg-server. Querying or changing XKB button actions such as moving from a touchpad to a mouse can result in out-of-bounds memory reads and writes. This may allow local privilege escalation or possible remote code execution in cases where X11 forwarding is involved. | CVSS3: 7.8 | 2% Низкий | больше 2 лет назад | |
GHSA-xp6x-54qx-mg3m HRSALE 1.1.8 contains a cross-site request forgery vulnerability that allows attackers to add unauthorized administrative users through the employee registration form. Attackers can craft a malicious HTML page with hidden form fields to trick authenticated administrators into creating new user accounts with elevated privileges. | CVSS3: 4.3 | 0% Низкий | 6 месяцев назад |
Уязвимостей на страницу