Количество 358 234
Количество 358 234
GHSA-xhw2-xhmj-qmw7
Unsafe navigation in Navigation in Google Chrome on iOS prior to 146.0.7680.71 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
GHSA-xhw2-2448-gp38
Microsoft Internet Explorer 8 does not properly handle content settings in HTTP responses, which allows remote web servers to obtain sensitive information from a different (1) domain or (2) zone via a crafted response, aka "MIME Sniffing Information Disclosure Vulnerability."
GHSA-xhvx-fprp-87jr
In ImageMagick 7.0.7-23 Q16 x86_64 2018-01-24, there is a heap-based buffer over-read in ReadSUNImage in coders/sun.c, which allows attackers to cause a denial of service (application crash in SetGrayscaleImage in MagickCore/quantize.c) via a crafted SUN image file.
GHSA-xhvx-9w5h-q8q6
Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network.
GHSA-xhvx-6vm7-468w
Cross-site scripting (XSS) vulnerability in u2u.php in XMB 1.9.3 allows remote attackers to inject arbitrary web script or HTML via the username parameter.
GHSA-xhvw-7r48-hpxr
D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function httpd_debug.asp. This vulnerability allows attackers to execute arbitrary commands via the time parameter.
GHSA-xhvw-36mm-785h
Cross-site scripting (XSS) vulnerability in the Help Tip module before 4.7.x-1.0 for Drupal allows remote attackers to inject arbitrary web script or HTML, and possibly obtain administrative access, via node titles.
GHSA-xhvw-2w3w-fwpc
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.1 ( 2025/07/09 ) and later
GHSA-xhvv-3jww-c487
ActiveAdmin CSV Injection leading to sensitive information disclosure
GHSA-xhvr-qq82-mmqx
An issue was discovered in Octopus before 3.17.7. When the special Guest user account is granted the CertificateExportPrivateKey permission, and Guest Access is enabled for the Octopus Server, an attacker can sign in as the Guest account and export Certificates managed by Octopus, including the private key.
GHSA-xhvr-qpr3-6jfg
Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
GHSA-xhvq-7mc2-jx9w
Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection while getting file server details.
GHSA-xhvp-6rv7-fw9x
Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Steven Henty Drop Shadow Boxes plugin <= 1.7.10 versions.
GHSA-xhvm-w5fj-p25w
There is a reachable assertion abort in the function jpc_dec_process_siz() in jpc/jpc_dec.c:1296 in JasPer 2.0.12 that will lead to a remote denial of service attack.
GHSA-xhvm-vfp7-h7mh
Missing Authorization vulnerability in Hyyan Abo Fakher Hyyan WooCommerce Polylang Integration woo-poly-integration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hyyan WooCommerce Polylang Integration: from n/a through <= 1.5.0.
GHSA-xhvm-q4fr-5m4f
In the content provider of the download manager, there is a possible SQL injection due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.0 Android ID: A-111085900
GHSA-xhvm-m8qv-p64r
A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause unexpected system termination or write kernel memory.
GHSA-xhvj-h5pc-rgrw
Nokia 7610 and 3210 phones allows attackers to cause a denial of service via certain characters in the filename of a Bluetooth OBEX transfer.
GHSA-xhvg-qmw2-rr5r
A Buffer Overflow vulnerability exists in zlog 1.2.15 via zlog_conf_build_with_file in src/zlog/src/conf.c.
GHSA-xhvg-mcp8-54f9
SQL injection vulnerability in shopcurrency.asp in VP-ASP 6.00 allows remote attackers to execute arbitrary SQL commands via the cid parameter.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xhw2-xhmj-qmw7 Unsafe navigation in Navigation in Google Chrome on iOS prior to 146.0.7680.71 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium) | CVSS3: 5.3 | 0% Низкий | 5 месяцев назад | |
GHSA-xhw2-2448-gp38 Microsoft Internet Explorer 8 does not properly handle content settings in HTTP responses, which allows remote web servers to obtain sensitive information from a different (1) domain or (2) zone via a crafted response, aka "MIME Sniffing Information Disclosure Vulnerability." | 6% Низкий | больше 4 лет назад | ||
GHSA-xhvx-fprp-87jr In ImageMagick 7.0.7-23 Q16 x86_64 2018-01-24, there is a heap-based buffer over-read in ReadSUNImage in coders/sun.c, which allows attackers to cause a denial of service (application crash in SetGrayscaleImage in MagickCore/quantize.c) via a crafted SUN image file. | CVSS3: 6.5 | 2% Низкий | больше 4 лет назад | |
GHSA-xhvx-9w5h-q8q6 Null pointer dereference in Windows Local Security Authority Subsystem Service (LSASS) allows an authorized attacker to deny service over a network. | CVSS3: 6.5 | 1% Низкий | около 1 года назад | |
GHSA-xhvx-6vm7-468w Cross-site scripting (XSS) vulnerability in u2u.php in XMB 1.9.3 allows remote attackers to inject arbitrary web script or HTML via the username parameter. | 5% Низкий | больше 4 лет назад | ||
GHSA-xhvw-7r48-hpxr D-Link device DI-7200GV2.E1 v21.04.09E1 was discovered to contain a command injection vulnerability in the function httpd_debug.asp. This vulnerability allows attackers to execute arbitrary commands via the time parameter. | CVSS3: 9.8 | 4% Низкий | больше 4 лет назад | |
GHSA-xhvw-36mm-785h Cross-site scripting (XSS) vulnerability in the Help Tip module before 4.7.x-1.0 for Drupal allows remote attackers to inject arbitrary web script or HTML, and possibly obtain administrative access, via node titles. | 1% Низкий | больше 4 лет назад | ||
GHSA-xhvw-2w3w-fwpc A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.1 ( 2025/07/09 ) and later | CVSS3: 6.5 | 0% Низкий | 11 месяцев назад | |
GHSA-xhvv-3jww-c487 ActiveAdmin CSV Injection leading to sensitive information disclosure | CVSS3: 5.2 | 1% Низкий | больше 2 лет назад | |
GHSA-xhvr-qq82-mmqx An issue was discovered in Octopus before 3.17.7. When the special Guest user account is granted the CertificateExportPrivateKey permission, and Guest Access is enabled for the Octopus Server, an attacker can sign in as the Guest account and export Certificates managed by Octopus, including the private key. | CVSS3: 6.5 | 1% Низкий | около 4 лет назад | |
GHSA-xhvr-qpr3-6jfg Adobe Experience Manager versions 6.5.23 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. | CVSS3: 5.4 | 0% Низкий | 5 месяцев назад | |
GHSA-xhvq-7mc2-jx9w Zoho ManageEngine ADAudit Plus versions below 7271 allows SQL injection while getting file server details. | CVSS3: 8.3 | 3% Низкий | около 2 лет назад | |
GHSA-xhvp-6rv7-fw9x Auth. (contributor+) Cross-Site Scripting (XSS) vulnerability in Steven Henty Drop Shadow Boxes plugin <= 1.7.10 versions. | CVSS3: 6.5 | 0% Низкий | около 3 лет назад | |
GHSA-xhvm-w5fj-p25w There is a reachable assertion abort in the function jpc_dec_process_siz() in jpc/jpc_dec.c:1296 in JasPer 2.0.12 that will lead to a remote denial of service attack. | CVSS3: 7.5 | 4% Низкий | больше 4 лет назад | |
GHSA-xhvm-vfp7-h7mh Missing Authorization vulnerability in Hyyan Abo Fakher Hyyan WooCommerce Polylang Integration woo-poly-integration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Hyyan WooCommerce Polylang Integration: from n/a through <= 1.5.0. | CVSS3: 6.5 | 0% Низкий | 7 месяцев назад | |
GHSA-xhvm-q4fr-5m4f In the content provider of the download manager, there is a possible SQL injection due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.0 Android ID: A-111085900 | CVSS3: 5.5 | 1% Низкий | больше 4 лет назад | |
GHSA-xhvm-m8qv-p64r A buffer overflow issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.3. An app may be able to cause unexpected system termination or write kernel memory. | CVSS3: 7.8 | 0% Низкий | почти 3 года назад | |
GHSA-xhvj-h5pc-rgrw Nokia 7610 and 3210 phones allows attackers to cause a denial of service via certain characters in the filename of a Bluetooth OBEX transfer. | 1% Низкий | больше 4 лет назад | ||
GHSA-xhvg-qmw2-rr5r A Buffer Overflow vulnerability exists in zlog 1.2.15 via zlog_conf_build_with_file in src/zlog/src/conf.c. | CVSS3: 7.5 | 1% Низкий | больше 4 лет назад | |
GHSA-xhvg-mcp8-54f9 SQL injection vulnerability in shopcurrency.asp in VP-ASP 6.00 allows remote attackers to execute arbitrary SQL commands via the cid parameter. | 1% Низкий | больше 4 лет назад |
Уязвимостей на страницу