Количество 358 234
Количество 358 234
GHSA-xhw9-4wqq-x67v
rdiffweb vulnerable to potential DoS via memory consumption
GHSA-xhw8-g8mh-rxvw
An issue was discovered in Corel PaintShop Pro 2019 21.0.0.119. An integer overflow in the jp2 parsing library allows an attacker to overwrite memory and to execute arbitrary code.
GHSA-xhw8-cw4m-2j3c
An access control issue in MobaXterm before v22.1 allows attackers to make connections to the server via the SSH or SFTP protocols without authentication.
GHSA-xhw8-7rfw-2fg2
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer handler, where an unprivileged user can cause improper restriction of operations within the bounds of a memory buffer cause an out-of-bounds read, which may lead to denial of service.
GHSA-xhw8-68ww-6958
AsIO2_64.sys and AsIO2_32.sys in ASUS GPUTweak II before 2.3.0.3 allow low-privileged users to interact directly with physical memory (by calling one of several driver routines that map physical memory into the virtual address space of the calling process) and to interact with MSR registers. This could enable low-privileged users to achieve NT AUTHORITY\SYSTEM privileges via a DeviceIoControl.
GHSA-xhw8-46vj-3gq5
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
GHSA-xhw7-r59x-5m6x
An authenticated user can perform command injection via unsanitized input to the NetFax Server’s ping functionality via the /test.php endpoint.
GHSA-xhw7-jhmp-j62j
`dnp3times` was removed from crates.io due to malicious code
GHSA-xhw7-j96h-c3g5
YAFNET: Pre-Handler Authorization Bypass on Admin Pages Enables Blind SQL Execution via `/Admin/RunSql`
GHSA-xhw7-9wqv-ffm2
The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webstartflash function.
GHSA-xhw7-5gmc-634h
Cross-site scripting in the /DroboAccess/delete_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execute JavaScript via the "username" URL parameter.
GHSA-xhw6-hjc9-679m
Pac4j token validation bypass if OpenID Connect provider supports none algorithm
GHSA-xhw6-399x-xj62
The login implementation in AirDroid 1.0.4 beta allows remote attackers to bypass a multiple-login protection mechanism by modifying a pass value within JSON data.
GHSA-xhw5-gfmh-rhfw
IBM i 7.3, 7.4, and 7.5 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 226941.
GHSA-xhw5-6m93-pmpj
An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. Nearly all of the AJAX action endpoints lacked permission checks, allowing these actions to be executed by anyone authenticated on the site. This happened because nonces were used as a means of authorization, but a nonce was present in a publicly viewable page. The greatest impact was the pagelayer_save_content function that allowed pages to be modified and allowed XSS to occur.
GHSA-xhw4-f4c3-7c2f
In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: Clear wcid pointer in mt7996_mac_sta_deinit_link() Clear WCID pointer removing the sta link in mt7996_mac_sta_deinit_link routine.
GHSA-xhw4-5qgr-c2w2
Directory traversal vulnerability in the Picasa2Gallery (com_picasa2gallery) component 1.2.8 and earlier for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.
GHSA-xhw3-wmx2-76wf
Buffer overflow in Jenkins WMI Windows Agents plugin
GHSA-xhw3-h8gq-2w23
Potential race conditions in IndexedDB could have caused memory corruption, leading to a potentially exploitable crash. This vulnerability affects Firefox < 132 and Thunderbird < 132.
GHSA-xhw3-4j3m-hq53
Winter CMS Modules allows a sandbox bypass in Twig templates leading to data modification and deletion
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xhw9-4wqq-x67v rdiffweb vulnerable to potential DoS via memory consumption | CVSS3: 7.5 | 1% Низкий | почти 4 года назад | |
GHSA-xhw8-g8mh-rxvw An issue was discovered in Corel PaintShop Pro 2019 21.0.0.119. An integer overflow in the jp2 parsing library allows an attacker to overwrite memory and to execute arbitrary code. | 3% Низкий | около 4 лет назад | ||
GHSA-xhw8-cw4m-2j3c An access control issue in MobaXterm before v22.1 allows attackers to make connections to the server via the SSH or SFTP protocols without authentication. | CVSS3: 8.1 | 1% Низкий | больше 3 лет назад | |
GHSA-xhw8-7rfw-2fg2 NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel mode layer handler, where an unprivileged user can cause improper restriction of operations within the bounds of a memory buffer cause an out-of-bounds read, which may lead to denial of service. | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
GHSA-xhw8-68ww-6958 AsIO2_64.sys and AsIO2_32.sys in ASUS GPUTweak II before 2.3.0.3 allow low-privileged users to interact directly with physical memory (by calling one of several driver routines that map physical memory into the virtual address space of the calling process) and to interact with MSR registers. This could enable low-privileged users to achieve NT AUTHORITY\SYSTEM privileges via a DeviceIoControl. | CVSS3: 7.8 | 0% Низкий | около 4 лет назад | |
GHSA-xhw8-46vj-3gq5 IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
GHSA-xhw7-r59x-5m6x An authenticated user can perform command injection via unsanitized input to the NetFax Server’s ping functionality via the /test.php endpoint. | 14% Средний | около 1 года назад | ||
GHSA-xhw7-jhmp-j62j `dnp3times` was removed from crates.io due to malicious code | 5 месяцев назад | |||
GHSA-xhw7-j96h-c3g5 YAFNET: Pre-Handler Authorization Bypass on Admin Pages Enables Blind SQL Execution via `/Admin/RunSql` | CVSS3: 8.8 | 0% Низкий | 3 месяца назад | |
GHSA-xhw7-9wqv-ffm2 The Baseboard Management Controller (BMC) firmware in HPE Apollo 70 System prior to version 3.0.14.0 has a local buffer overflow in libifc.so webstartflash function. | 0% Низкий | около 4 лет назад | ||
GHSA-xhw7-5gmc-634h Cross-site scripting in the /DroboAccess/delete_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to execute JavaScript via the "username" URL parameter. | CVSS3: 6.1 | 1% Низкий | больше 4 лет назад | |
GHSA-xhw6-hjc9-679m Pac4j token validation bypass if OpenID Connect provider supports none algorithm | CVSS3: 7.5 | 1% Низкий | больше 4 лет назад | |
GHSA-xhw6-399x-xj62 The login implementation in AirDroid 1.0.4 beta allows remote attackers to bypass a multiple-login protection mechanism by modifying a pass value within JSON data. | 1% Низкий | около 4 лет назад | ||
GHSA-xhw5-gfmh-rhfw IBM i 7.3, 7.4, and 7.5 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 226941. | CVSS3: 8.8 | 2% Низкий | около 4 лет назад | |
GHSA-xhw5-6m93-pmpj An issue was discovered in the PageLayer plugin before 1.1.2 for WordPress. Nearly all of the AJAX action endpoints lacked permission checks, allowing these actions to be executed by anyone authenticated on the site. This happened because nonces were used as a means of authorization, but a nonce was present in a publicly viewable page. The greatest impact was the pagelayer_save_content function that allowed pages to be modified and allowed XSS to occur. | 1% Низкий | около 4 лет назад | ||
GHSA-xhw4-f4c3-7c2f In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: mt7996: Clear wcid pointer in mt7996_mac_sta_deinit_link() Clear WCID pointer removing the sta link in mt7996_mac_sta_deinit_link routine. | CVSS3: 8.8 | 0% Низкий | 28 дней назад | |
GHSA-xhw4-5qgr-c2w2 Directory traversal vulnerability in the Picasa2Gallery (com_picasa2gallery) component 1.2.8 and earlier for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php. | 9% Низкий | около 4 лет назад | ||
GHSA-xhw3-wmx2-76wf Buffer overflow in Jenkins WMI Windows Agents plugin | CVSS3: 4.2 | 2% Низкий | около 4 лет назад | |
GHSA-xhw3-h8gq-2w23 Potential race conditions in IndexedDB could have caused memory corruption, leading to a potentially exploitable crash. This vulnerability affects Firefox < 132 and Thunderbird < 132. | CVSS3: 9.8 | 0% Низкий | почти 2 года назад | |
GHSA-xhw3-4j3m-hq53 Winter CMS Modules allows a sandbox bypass in Twig templates leading to data modification and deletion | CVSS3: 8.4 | 0% Низкий | больше 1 года назад |
Уязвимостей на страницу