Количество 358 043
Количество 358 043
GHSA-xjmq-x923-hrwq
A memory leak in the dwc3_pci_probe() function in drivers/usb/dwc3/dwc3-pci.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering platform_device_add_properties() failures, aka CID-9bbfceea12a8.
GHSA-xjmj-w54m-v5gr
In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services.
GHSA-xjmj-p278-4jp5
OpenStack Compute (Nova) Exposure of Sensitive Information to an Unauthorized Actor vulnerability
GHSA-xjmj-jj97-789f
A remote code execution (RCE) vulnerability in the component /admin/index.php?id=themes&action=edit_template&filename=blog of Monstra v3.0.4 allows attackers to execute arbitrary commands via a crafted PHP file.
GHSA-xjmj-77vh-qf7w
An arbitrary file deletion vulnerability exists within Maccms10.
GHSA-xjmh-6wp6-74q8
In the Linux kernel, the following vulnerability has been resolved: idpf: avoid vport access in idpf_get_link_ksettings When the device control plane is removed or the platform running device control plane is rebooted, a reset is detected on the driver. On driver reset, it releases the resources and waits for the reset to complete. If the reset fails, it takes the error path and releases the vport lock. At this time if the monitoring tools tries to access link settings, it call traces for accessing released vport pointer. To avoid it, move link_speed_mbps to netdev_priv structure which removes the dependency on vport pointer and the vport lock in idpf_get_link_ksettings. Also use netif_carrier_ok() to check the link status and adjust the offsetof to use link_up instead of link_speed_mbps.
GHSA-xjmg-vpvm-gr84
Static code injection vulnerability in admin.php in Ryneezy phoSheezy 0.2 allows remote authenticated administrators to inject arbitrary PHP code into config/header via the header parameter. NOTE: this can be exploited by unauthenticated attackers by leveraging CVE-2009-0250. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
GHSA-xjmg-ppqq-vfgg
The `Kudos Donations – Easy donations and payments with Mollie` plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of `add_query_arg` without appropriate escaping on the URL in all versions up to, and including, 3.2.9. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute if they can successfully trick a user into performing an action, such as clicking on a specially crafted link.
GHSA-xjmf-xr2j-gfx7
An exploitable vulnerability exists in the verified boot protection of the Das U-Boot from version 2013.07-rc1 to 2014.07-rc2. The affected versions lack proper FIT signature enforcement, which allows an attacker to bypass U-Boot's verified boot and execute an unsigned kernel, embedded in a legacy image format. To trigger this vulnerability, a local attacker needs to be able to supply the image to boot.
GHSA-xjmf-cg3p-vmcm
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in matthewrubin Local Magic allows SQL Injection. This issue affects Local Magic: from n/a through 2.6.0.
GHSA-xjmc-6x2g-58qh
An issue in briscKernelDriver.sys in BlueRiSC WindowsSCOPE Cyber Forensics before 3.3 allows a local attacker to execute arbitrary code within the driver and create a local denial-of-service condition due to an improper DACL being applied to the device the driver creates.
GHSA-xjmc-37gv-8mrp
An elevation of privilege (user to user) vulnerability exists in Windows Security Health Service when handling certain objects in memory.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1324.
GHSA-xjm9-rr2c-vpq2
Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the backend connection. This can lead to Denial-of-Service and confidential data being disclosed to the attacker.
GHSA-xjm9-9gr6-gcpx
A flaw was found in the check_chunk_name() function of pngcheck-2.4.0. An attacker able to pass a malicious file to be processed by pngcheck could cause a temporary denial of service, posing a low risk to application availability.
GHSA-xjm8-v6p6-5c3j
A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the id parameter at /getAssetContent.
GHSA-xjm8-9w9g-9h2f
In multiple functions of io_uring.c, there is a possible kernel memory corruption due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation.
GHSA-xjm8-5h8c-cc2g
A possible arbitrary memory overwrite vulnerabilities in quram library version prior to SMR Jan-2021 Release 1 allow arbitrary code execution.
GHSA-xjm6-pf3c-5gjq
Cross-site scripting (XSS) vulnerability in neomail.pl in NeoMail 1.29 allows remote attackers to inject arbitrary web script or HTML via the sessionid parameter.
GHSA-xjm6-m6g9-99gh
Cross-site scripting (XSS) vulnerability in WebMail Pro in IceWarp Software Merak Mail Server 9.3.2 allows remote attackers to inject arbitrary web script or HTML via an IMG element in an HTML e-mail message.
GHSA-xjm6-jfmg-qc6p
Aimeos denial of service vulnerability in SaaS and marketplace setups
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xjmq-x923-hrwq A memory leak in the dwc3_pci_probe() function in drivers/usb/dwc3/dwc3-pci.c in the Linux kernel through 5.3.9 allows attackers to cause a denial of service (memory consumption) by triggering platform_device_add_properties() failures, aka CID-9bbfceea12a8. | CVSS3: 7.5 | 4% Низкий | около 4 лет назад | |
GHSA-xjmj-w54m-v5gr In wlan driver, there is a possible missing params check. This could lead to local denial of service in wlan services. | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
GHSA-xjmj-p278-4jp5 OpenStack Compute (Nova) Exposure of Sensitive Information to an Unauthorized Actor vulnerability | 2% Низкий | больше 4 лет назад | ||
GHSA-xjmj-jj97-789f A remote code execution (RCE) vulnerability in the component /admin/index.php?id=themes&action=edit_template&filename=blog of Monstra v3.0.4 allows attackers to execute arbitrary commands via a crafted PHP file. | 3% Низкий | около 4 лет назад | ||
GHSA-xjmj-77vh-qf7w An arbitrary file deletion vulnerability exists within Maccms10. | 1% Низкий | около 4 лет назад | ||
GHSA-xjmh-6wp6-74q8 In the Linux kernel, the following vulnerability has been resolved: idpf: avoid vport access in idpf_get_link_ksettings When the device control plane is removed or the platform running device control plane is rebooted, a reset is detected on the driver. On driver reset, it releases the resources and waits for the reset to complete. If the reset fails, it takes the error path and releases the vport lock. At this time if the monitoring tools tries to access link settings, it call traces for accessing released vport pointer. To avoid it, move link_speed_mbps to netdev_priv structure which removes the dependency on vport pointer and the vport lock in idpf_get_link_ksettings. Also use netif_carrier_ok() to check the link status and adjust the offsetof to use link_up instead of link_speed_mbps. | CVSS3: 7.8 | 0% Низкий | больше 1 года назад | |
GHSA-xjmg-vpvm-gr84 Static code injection vulnerability in admin.php in Ryneezy phoSheezy 0.2 allows remote authenticated administrators to inject arbitrary PHP code into config/header via the header parameter. NOTE: this can be exploited by unauthenticated attackers by leveraging CVE-2009-0250. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 5% Низкий | больше 4 лет назад | ||
GHSA-xjmg-ppqq-vfgg The `Kudos Donations – Easy donations and payments with Mollie` plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of `add_query_arg` without appropriate escaping on the URL in all versions up to, and including, 3.2.9. This makes it possible for unauthenticated attackers to inject arbitrary web scripts that execute if they can successfully trick a user into performing an action, such as clicking on a specially crafted link. | CVSS3: 6.1 | 0% Низкий | больше 1 года назад | |
GHSA-xjmf-xr2j-gfx7 An exploitable vulnerability exists in the verified boot protection of the Das U-Boot from version 2013.07-rc1 to 2014.07-rc2. The affected versions lack proper FIT signature enforcement, which allows an attacker to bypass U-Boot's verified boot and execute an unsigned kernel, embedded in a legacy image format. To trigger this vulnerability, a local attacker needs to be able to supply the image to boot. | CVSS3: 7 | 0% Низкий | больше 4 лет назад | |
GHSA-xjmf-cg3p-vmcm Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in matthewrubin Local Magic allows SQL Injection. This issue affects Local Magic: from n/a through 2.6.0. | CVSS3: 9.3 | 0% Низкий | больше 1 года назад | |
GHSA-xjmc-6x2g-58qh An issue in briscKernelDriver.sys in BlueRiSC WindowsSCOPE Cyber Forensics before 3.3 allows a local attacker to execute arbitrary code within the driver and create a local denial-of-service condition due to an improper DACL being applied to the device the driver creates. | CVSS3: 7.8 | 0% Низкий | больше 2 лет назад | |
GHSA-xjmc-37gv-8mrp An elevation of privilege (user to user) vulnerability exists in Windows Security Health Service when handling certain objects in memory.To exploit the vulnerability, an attacker would first have to log on to the system, aka 'Windows Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1324. | 1% Низкий | около 4 лет назад | ||
GHSA-xjm9-rr2c-vpq2 Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the backend connection. This can lead to Denial-of-Service and confidential data being disclosed to the attacker. | CVSS3: 9.8 | 0% Низкий | 16 дней назад | |
GHSA-xjm9-9gr6-gcpx A flaw was found in the check_chunk_name() function of pngcheck-2.4.0. An attacker able to pass a malicious file to be processed by pngcheck could cause a temporary denial of service, posing a low risk to application availability. | CVSS3: 3.3 | 1% Низкий | около 4 лет назад | |
GHSA-xjm8-v6p6-5c3j A SQL injection vulnerability has been identified in Siyuan 3.1.11 via the id parameter at /getAssetContent. | CVSS3: 9.8 | 0% Низкий | больше 1 года назад | |
GHSA-xjm8-9w9g-9h2f In multiple functions of io_uring.c, there is a possible kernel memory corruption due to improper locking. This could lead to local escalation of privilege in the kernel with System execution privileges needed. User interaction is not needed for exploitation. | CVSS3: 6.7 | 0% Низкий | около 3 лет назад | |
GHSA-xjm8-5h8c-cc2g A possible arbitrary memory overwrite vulnerabilities in quram library version prior to SMR Jan-2021 Release 1 allow arbitrary code execution. | 1% Низкий | около 4 лет назад | ||
GHSA-xjm6-pf3c-5gjq Cross-site scripting (XSS) vulnerability in neomail.pl in NeoMail 1.29 allows remote attackers to inject arbitrary web script or HTML via the sessionid parameter. | 2% Низкий | больше 4 лет назад | ||
GHSA-xjm6-m6g9-99gh Cross-site scripting (XSS) vulnerability in WebMail Pro in IceWarp Software Merak Mail Server 9.3.2 allows remote attackers to inject arbitrary web script or HTML via an IMG element in an HTML e-mail message. | 1% Низкий | около 4 лет назад | ||
GHSA-xjm6-jfmg-qc6p Aimeos denial of service vulnerability in SaaS and marketplace setups | CVSS3: 5.5 | 0% Низкий | около 2 лет назад |
Уязвимостей на страницу