Количество 357 575
Количество 357 575
GHSA-xm9m-2vj8-fmfr
Uninitialized memory access in toodee
GHSA-xm9j-x4hp-v2x3
In the Linux kernel, the following vulnerability has been resolved: drm/nouveau/kms/nv50-: fix file release memory leak When using single_open() for opening, single_release() should be called, otherwise the 'op' allocated in single_open() will be leaked.
GHSA-xm9j-54hw-p785
A potential memory vulnerability due to insufficient input validation in PDFXEditCore.x64.dll in PDF-XChange Editor version 9.3 by Tracker Software may allow attackers to execute code when a user opens a crafted PDF file. The issue occurs when handling a large number of objects in a PDF file.
GHSA-xm9j-3ggw-w823
IBM AIX 5.3, 6.1, 7.1, and 7.2 contains a vulnerability in the rmsock command that may be used to expose kernel memory. IBM X-Force ID: 144748.
GHSA-xm9h-x34f-j9hj
Improper input validation in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network.
GHSA-xm9h-q2f5-rq5x
A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for macOS could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The openvpn_launcher binary is setuid root. This program is called during the connection process and executes several operating system utilities to configure the system. The networksetup utility is called using relative paths. A local unprivileged user can execute arbitrary commands as root by creating a networksetup trojan which will be executed during the connection process. This is possible because the PATH environment variable is not reset prior to executing the OS utility.
GHSA-xm9h-gvgh-crf7
The Logging Server (ftplogsrv.exe) 7.9.14.0 and earlier in IPSwitch WS_FTP 6.1 allows remote attackers to cause a denial of service (loss of responsiveness) via a large number of large packets to port 5151/udp, which causes the listening socket to terminate and prevents log commands from being recorded, a different vulnerability than CVE-2007-3823.
GHSA-xm9g-m236-mvcw
Missing Authorization vulnerability in fraudlabspro FraudLabs Pro for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects FraudLabs Pro for WooCommerce: from n/a through 2.22.11.
GHSA-xm9g-8m49-7qpg
Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Suite 12.0.4, 12.0.5, 12.0.6, 12.1.1, 12.1.2, 12.1.3, 12.2.2, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality and integrity via unknown vectors related to List of Values.
GHSA-xm9g-6f9f-23pj
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
GHSA-xm9g-3p7c-jr4h
The Filestack Official plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'fstab' and 'filestack_options' parameters in all versions up to, and including, 2.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
GHSA-xm9f-vxmx-4m58
Data Flow Sanitation Issue Fix
GHSA-xm9f-p78g-g8cf
Product: AndroidVersions: Android kernelAndroid ID: A-207116951References: N/A
GHSA-xm9f-jp6r-h9h7
Unrestricted file upload vulnerability in Opial 1.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension as a User Image, then accessing it via a request to the file in userimages, related to register.php.
GHSA-xm9f-gqc6-828p
SQL injection vulnerability in out.php in E-topbiz Link ADS 1 allows remote attackers to execute arbitrary SQL commands via the linkid parameter.
GHSA-xm9f-fph8-8369
In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-220302519
GHSA-xm9f-5xv9-93pc
Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.
GHSA-xm9f-3ph3-v8p6
Unauthenticated Java deserialization vulnerability in Serviceguard Manager
GHSA-xm9c-pm26-gfwx
Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter at /admin/ajax.php?action=login.
GHSA-xm99-mgxp-q9jf
Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the organization parameter. Attackers can send POST requests to the korugan/cmclient endpoint with script payloads in the organization parameter to execute arbitrary JavaScript in users' browsers.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xm9m-2vj8-fmfr Uninitialized memory access in toodee | CVSS3: 7.5 | 1% Низкий | почти 5 лет назад | |
GHSA-xm9j-x4hp-v2x3 In the Linux kernel, the following vulnerability has been resolved: drm/nouveau/kms/nv50-: fix file release memory leak When using single_open() for opening, single_release() should be called, otherwise the 'op' allocated in single_open() will be leaked. | CVSS3: 5.5 | 0% Низкий | около 2 лет назад | |
GHSA-xm9j-54hw-p785 A potential memory vulnerability due to insufficient input validation in PDFXEditCore.x64.dll in PDF-XChange Editor version 9.3 by Tracker Software may allow attackers to execute code when a user opens a crafted PDF file. The issue occurs when handling a large number of objects in a PDF file. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-xm9j-3ggw-w823 IBM AIX 5.3, 6.1, 7.1, and 7.2 contains a vulnerability in the rmsock command that may be used to expose kernel memory. IBM X-Force ID: 144748. | CVSS3: 5.5 | 0% Низкий | больше 4 лет назад | |
GHSA-xm9h-x34f-j9hj Improper input validation in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network. | CVSS3: 7.5 | 1% Низкий | 4 месяца назад | |
GHSA-xm9h-q2f5-rq5x A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for macOS could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The openvpn_launcher binary is setuid root. This program is called during the connection process and executes several operating system utilities to configure the system. The networksetup utility is called using relative paths. A local unprivileged user can execute arbitrary commands as root by creating a networksetup trojan which will be executed during the connection process. This is possible because the PATH environment variable is not reset prior to executing the OS utility. | 1% Низкий | около 4 лет назад | ||
GHSA-xm9h-gvgh-crf7 The Logging Server (ftplogsrv.exe) 7.9.14.0 and earlier in IPSwitch WS_FTP 6.1 allows remote attackers to cause a denial of service (loss of responsiveness) via a large number of large packets to port 5151/udp, which causes the listening socket to terminate and prevents log commands from being recorded, a different vulnerability than CVE-2007-3823. | 6% Низкий | больше 4 лет назад | ||
GHSA-xm9g-m236-mvcw Missing Authorization vulnerability in fraudlabspro FraudLabs Pro for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects FraudLabs Pro for WooCommerce: from n/a through 2.22.11. | CVSS3: 5.3 | 0% Низкий | около 1 года назад | |
GHSA-xm9g-8m49-7qpg Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Suite 12.0.4, 12.0.5, 12.0.6, 12.1.1, 12.1.2, 12.1.3, 12.2.2, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality and integrity via unknown vectors related to List of Values. | 1% Низкий | около 4 лет назад | ||
GHSA-xm9g-6f9f-23pj Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | CVSS3: 5.5 | 0% Низкий | 2 дня назад | |
GHSA-xm9g-3p7c-jr4h The Filestack Official plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'fstab' and 'filestack_options' parameters in all versions up to, and including, 2.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. | CVSS3: 6.1 | 0% Низкий | больше 1 года назад | |
GHSA-xm9f-vxmx-4m58 Data Flow Sanitation Issue Fix | 1% Низкий | почти 5 лет назад | ||
GHSA-xm9f-p78g-g8cf Product: AndroidVersions: Android kernelAndroid ID: A-207116951References: N/A | CVSS3: 9.8 | 1% Низкий | около 4 лет назад | |
GHSA-xm9f-jp6r-h9h7 Unrestricted file upload vulnerability in Opial 1.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension as a User Image, then accessing it via a request to the file in userimages, related to register.php. | 4% Низкий | больше 4 лет назад | ||
GHSA-xm9f-gqc6-828p SQL injection vulnerability in out.php in E-topbiz Link ADS 1 allows remote attackers to execute arbitrary SQL commands via the linkid parameter. | 1% Низкий | больше 4 лет назад | ||
GHSA-xm9f-fph8-8369 In WorkSource, there is a possible parcel mismatch. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11 Android-12 Android-12L Android-13Android ID: A-220302519 | CVSS3: 7.8 | 1% Низкий | больше 3 лет назад | |
GHSA-xm9f-5xv9-93pc Adobe Acrobat and Reader versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and earlier have an Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure. | CVSS3: 6.5 | 9% Низкий | около 4 лет назад | |
GHSA-xm9f-3ph3-v8p6 Unauthenticated Java deserialization vulnerability in Serviceguard Manager | CVSS3: 9.8 | 1% Низкий | больше 3 лет назад | |
GHSA-xm9c-pm26-gfwx Dynamic Transaction Queuing System v1.0 was discovered to contain a SQL injection vulnerability via the name parameter at /admin/ajax.php?action=login. | CVSS3: 7.2 | 1% Низкий | больше 3 лет назад | |
GHSA-xm99-mgxp-q9jf Comodo Dome Firewall 2.7.0 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the organization parameter. Attackers can send POST requests to the korugan/cmclient endpoint with script payloads in the organization parameter to execute arbitrary JavaScript in users' browsers. | CVSS3: 6.1 | 0% Низкий | 6 месяцев назад |
Уязвимостей на страницу