Количество 358 043
Количество 358 043
GHSA-xjpj-3mr7-gcpf
Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options
GHSA-xjph-r444-9j84
Incorrect Default Permissions vulnerability in Hitachi Storage Provider for VMware vCenter allows local users to read and write specific files.This issue affects Hitachi Storage Provider for VMware vCenter: from 3.1.0 before 3.7.4.
GHSA-xjph-mj93-g3gw
The DNP3 component in Cooper Power Systems SMP 4, 4/DP, and 16 gateways allows physically proximate attackers to cause a denial of service (reboot or link outage) via crafted input over a serial line.
GHSA-xjpg-r9jg-hhhf
In the Linux kernel, the following vulnerability has been resolved: pds_core: fix error handling in pdsc_devcmd_wait Fix two cases where pdsc_devcmd_wait() returns stale success from the completion register instead of an error: 1. FW crash: If firmware stops running, the wait loop breaks early with running=false. The condition "if ((!done || timeout) && running)" is false, so error handling is bypassed and stale status is returned. Check !running first and return -ENXIO. 2. Timeout: If a command times out, err is set to -ETIMEDOUT but then overwritten by pdsc_err_to_errno(status) which reads stale status. Return -ETIMEDOUT immediately after cleaning up. Both errors now propagate to pdsc_devcmd_locked() which queues health_work for recovery.
GHSA-xjpf-mwm5-w4cr
A maliciously crafted USD file, when loaded or imported into Autodesk Arnold or Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
GHSA-xjpc-m35x-gfvr
Cross-site request forgery (CSRF) vulnerability in Shared Sign-On 5.x and 6.x, a module for Drupal, allows remote attackers to hijack the authentication of arbitrary users via unknown vectors.
GHSA-xjpc-56ff-89r7
Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability."
GHSA-xjpc-3v7h-498j
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the HDMI video driver function hdmi_edid_sysfs_rda_res_info(), userspace can perform an arbitrary write into kernel memory.
GHSA-xjp9-7hx4-8rwc
Stability-related vulnerability in the binder background management and control module. Successful exploitation of this vulnerability may affect availability.
GHSA-xjp8-j4mm-q4h6
Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without proper escaping or parameterized queries, enabling blind SQL injection and unauthorized database read access.
GHSA-xjp8-93c2-7gxm
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Estatik Estatik Mortgage Calculator plugin <= 2.0.7 versions.
GHSA-xjp7-q8q7-c6x4
PY Software Active Webcam WebServer (webcam.exe) 5.5 allows remote attackers to cause a denial of service (memory exhaustion and process crash) via a large number of HTTP requests.
GHSA-xjp6-jcwj-9qp5
Unspecified vulnerability in the Oracle Applications DBA component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.2, 12.2.3, and 12.2.4 allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to AD_DDL.
GHSA-xjp5-p9r4-x8c7
A command injection vulnerability in the EXE parameter of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allows attackers to execute arbitrary commands via supplying a crafted GET request.
GHSA-xjp5-m6c5-6c7w
onekeyadmin v1.3.9 was discovered to contain an arbitrary file delete vulnerability via the component \admin\controller\plugins.
GHSA-xjp5-gg6j-cwrg
The Download Validation in LaunchServices for Apple Mac OS X 10.4.7 can identify certain HTML as "safe", which could allow attackers to execute Javascript code in local context when the "Open 'safe' files after downloading" option is enabled in Safari.
GHSA-xjp5-5ph6-c66c
Missing Critical Step in Authentication in GitHub repository namelessmc/nameless prior to v2.0.2.
GHSA-xjp4-wv35-98vj
Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by an invalid VerticesPerRow value in a PDF shading dictionary.
GHSA-xjp4-hw94-mvp5
Apache Commons Configuration: StackOverflowError adding property in AbstractListDelimiterHandler.flattenIterator()
GHSA-xjp4-6w75-qrj7
Remote CLI Command Execution Vulnerability in CodeIgniter4
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xjpj-3mr7-gcpf Handlebars.js has JavaScript Injection in CLI Precompiler via Unescaped Names and Options | CVSS3: 8.2 | 0% Низкий | 5 месяцев назад | |
GHSA-xjph-r444-9j84 Incorrect Default Permissions vulnerability in Hitachi Storage Provider for VMware vCenter allows local users to read and write specific files.This issue affects Hitachi Storage Provider for VMware vCenter: from 3.1.0 before 3.7.4. | CVSS3: 4.4 | 0% Низкий | около 2 лет назад | |
GHSA-xjph-mj93-g3gw The DNP3 component in Cooper Power Systems SMP 4, 4/DP, and 16 gateways allows physically proximate attackers to cause a denial of service (reboot or link outage) via crafted input over a serial line. | 0% Низкий | около 4 лет назад | ||
GHSA-xjpg-r9jg-hhhf In the Linux kernel, the following vulnerability has been resolved: pds_core: fix error handling in pdsc_devcmd_wait Fix two cases where pdsc_devcmd_wait() returns stale success from the completion register instead of an error: 1. FW crash: If firmware stops running, the wait loop breaks early with running=false. The condition "if ((!done || timeout) && running)" is false, so error handling is bypassed and stale status is returned. Check !running first and return -ENXIO. 2. Timeout: If a command times out, err is set to -ETIMEDOUT but then overwritten by pdsc_err_to_errno(status) which reads stale status. Return -ETIMEDOUT immediately after cleaning up. Both errors now propagate to pdsc_devcmd_locked() which queues health_work for recovery. | CVSS3: 7.5 | 0% Низкий | 26 дней назад | |
GHSA-xjpf-mwm5-w4cr A maliciously crafted USD file, when loaded or imported into Autodesk Arnold or Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process. | CVSS3: 7.8 | 0% Низкий | 6 месяцев назад | |
GHSA-xjpc-m35x-gfvr Cross-site request forgery (CSRF) vulnerability in Shared Sign-On 5.x and 6.x, a module for Drupal, allows remote attackers to hijack the authentication of arbitrary users via unknown vectors. | 1% Низкий | больше 4 лет назад | ||
GHSA-xjpc-56ff-89r7 Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability." | 18% Средний | больше 4 лет назад | ||
GHSA-xjpc-3v7h-498j In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the HDMI video driver function hdmi_edid_sysfs_rda_res_info(), userspace can perform an arbitrary write into kernel memory. | CVSS3: 7.8 | 0% Низкий | больше 4 лет назад | |
GHSA-xjp9-7hx4-8rwc Stability-related vulnerability in the binder background management and control module. Successful exploitation of this vulnerability may affect availability. | CVSS3: 7.5 | 0% Низкий | почти 3 года назад | |
GHSA-xjp8-j4mm-q4h6 Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without proper escaping or parameterized queries, enabling blind SQL injection and unauthorized database read access. | CVSS3: 7.1 | 0% Низкий | 24 дня назад | |
GHSA-xjp8-93c2-7gxm Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Estatik Estatik Mortgage Calculator plugin <= 2.0.7 versions. | CVSS3: 7.1 | 0% Низкий | почти 3 года назад | |
GHSA-xjp7-q8q7-c6x4 PY Software Active Webcam WebServer (webcam.exe) 5.5 allows remote attackers to cause a denial of service (memory exhaustion and process crash) via a large number of HTTP requests. | 2% Низкий | больше 4 лет назад | ||
GHSA-xjp6-jcwj-9qp5 Unspecified vulnerability in the Oracle Applications DBA component in Oracle E-Business Suite 11.5.10.2, 12.0.6, 12.1.3, 12.2.2, 12.2.3, and 12.2.4 allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to AD_DDL. | 1% Низкий | около 4 лет назад | ||
GHSA-xjp5-p9r4-x8c7 A command injection vulnerability in the EXE parameter of D-Link DSL-7740C with firmware DSL7740C.V6.TR069.20211230 allows attackers to execute arbitrary commands via supplying a crafted GET request. | CVSS3: 5.3 | 2% Низкий | 12 месяцев назад | |
GHSA-xjp5-m6c5-6c7w onekeyadmin v1.3.9 was discovered to contain an arbitrary file delete vulnerability via the component \admin\controller\plugins. | CVSS3: 9.1 | 1% Низкий | больше 3 лет назад | |
GHSA-xjp5-gg6j-cwrg The Download Validation in LaunchServices for Apple Mac OS X 10.4.7 can identify certain HTML as "safe", which could allow attackers to execute Javascript code in local context when the "Open 'safe' files after downloading" option is enabled in Safari. | 1% Низкий | больше 4 лет назад | ||
GHSA-xjp5-5ph6-c66c Missing Critical Step in Authentication in GitHub repository namelessmc/nameless prior to v2.0.2. | CVSS3: 7.5 | 1% Низкий | почти 4 года назад | |
GHSA-xjp4-wv35-98vj Out-of-bounds array write in Xpdf 4.05 and earlier, triggered by an invalid VerticesPerRow value in a PDF shading dictionary. | 0% Низкий | больше 1 года назад | ||
GHSA-xjp4-hw94-mvp5 Apache Commons Configuration: StackOverflowError adding property in AbstractListDelimiterHandler.flattenIterator() | CVSS3: 6.5 | 2% Низкий | больше 2 лет назад | |
GHSA-xjp4-6w75-qrj7 Remote CLI Command Execution Vulnerability in CodeIgniter4 | CVSS3: 9.4 | 1% Низкий | больше 4 лет назад |
Уязвимостей на страницу