Количество 359 154
Количество 359 154
GHSA-xh9h-692f-mmg4
Withdrawn Advisory: Microsoft Knack ReDoS Vulnerability in the Introspection Module
GHSA-xh9g-cqwj-6chj
SPBAS Business Automation Software 2012 has XSS.
GHSA-xh9g-cp3v-p8q4
Missing Authorization in Crater Invoice
GHSA-xh9g-5fg8-p3wh
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in remote code execution, when a malicious CGF or WSP file is being parsed by IGSS Definition.
GHSA-xh9c-vcf9-h94m
Jenkins Git server Plugin does not perform a permission check
GHSA-xh9c-cqj7-g26j
Multiple SQL injection vulnerabilities in BOINC allow remote attackers to execute arbitrary SQL commands via unspecified vectors.
GHSA-xh9c-76xx-xhrp
Double free vulnerability in WebKit in Apple iOS before 4.1 on the iPhone and iPod touch allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the rendering of an inline element.
GHSA-xh99-hw7h-wf63
Unchecked validity of Facing values in PlayerActionPacket
GHSA-xh98-xq72-x84p
SQL injection vulnerability in announcements.php in SiteEngine 5.x allows remote attackers to execute arbitrary SQL commands via the id parameter.
GHSA-xh98-rwp8-8rpw
An issue has been discovered in GitLab affecting all versions starting from 17.1 to 17.1.7, 17.2 prior to 17.2.5 and 17.3 prior to 17.3.2. A crafted URL could be used to trick a victim to trust an attacker controlled application.
GHSA-xh98-g799-3775
The Opera Mobile application before 12.1 and Opera Mini application before 7.5 for Android do not properly implement the WebView class, which allows attackers to obtain sensitive information via a crafted application.
GHSA-xh97-fh55-wr34
Missing Authorization vulnerability in turitop TuriTop Booking System allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects TuriTop Booking System: from n/a through 1.0.10.
GHSA-xh97-73h5-gfm9
ephy-session.c in libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 allows remote attackers to cause a denial of service (application crash) via JavaScript code that triggers access to a NULL URL, as demonstrated by a crafted window.open call.
GHSA-xh97-72ww-2w58
Duplicate Advisory: Improper Verification of Cryptographic Signature in google-oauth-java-client
GHSA-xh96-vq46-m9ww
Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from its initial commit in 2002 (3861aa5) up to today on any platform allows an attacker on the local network to leak memory from four up to 32 bytes of memory stored behind the packet to the network depending on the later use of DHCP-provided parameters via crafted DHCP responses.
GHSA-xh96-q52c-cw5m
S-CMS PHP 1.0 has SQL injection in member/member_news.php via the type parameter (aka the $N_type field).
GHSA-xh96-g262-xhpr
Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter macFilterType and parameter deviceList at /goform/setMacFilterCfg.
GHSA-xh96-fgxf-4776
Missing Authorization vulnerability in Frenify Guff guff allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Guff: from n/a through <= 1.0.1.
GHSA-xh96-5xc9-3w5h
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code by calling the ActionScript native object 2200 connect method multiple times with different arguments, a different vulnerability than CVE-2010-2160, CVE-2010-2165, CVE-2010-2166, CVE-2010-2171, CVE-2010-2175, CVE-2010-2176, CVE-2010-2177, CVE-2010-2178, CVE-2010-2180, CVE-2010-2182, CVE-2010-2184, and CVE-2010-2187.
GHSA-xh95-j7j4-ghg2
The BLOGCHAT Chat System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.6.3. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xh9h-692f-mmg4 Withdrawn Advisory: Microsoft Knack ReDoS Vulnerability in the Introspection Module | 0% Низкий | 12 месяцев назад | ||
GHSA-xh9g-cqwj-6chj SPBAS Business Automation Software 2012 has XSS. | 2% Низкий | больше 4 лет назад | ||
GHSA-xh9g-cp3v-p8q4 Missing Authorization in Crater Invoice | CVSS3: 5.3 | 1% Низкий | больше 4 лет назад | |
GHSA-xh9g-5fg8-p3wh A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in remote code execution, when a malicious CGF or WSP file is being parsed by IGSS Definition. | 1% Низкий | около 4 лет назад | ||
GHSA-xh9c-vcf9-h94m Jenkins Git server Plugin does not perform a permission check | CVSS3: 5.3 | 1% Низкий | больше 2 лет назад | |
GHSA-xh9c-cqj7-g26j Multiple SQL injection vulnerabilities in BOINC allow remote attackers to execute arbitrary SQL commands via unspecified vectors. | CVSS3: 9.8 | 2% Низкий | больше 4 лет назад | |
GHSA-xh9c-76xx-xhrp Double free vulnerability in WebKit in Apple iOS before 4.1 on the iPhone and iPod touch allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to the rendering of an inline element. | 4% Низкий | больше 4 лет назад | ||
GHSA-xh99-hw7h-wf63 Unchecked validity of Facing values in PlayerActionPacket | CVSS3: 7.5 | больше 4 лет назад | ||
GHSA-xh98-xq72-x84p SQL injection vulnerability in announcements.php in SiteEngine 5.x allows remote attackers to execute arbitrary SQL commands via the id parameter. | 1% Низкий | больше 4 лет назад | ||
GHSA-xh98-rwp8-8rpw An issue has been discovered in GitLab affecting all versions starting from 17.1 to 17.1.7, 17.2 prior to 17.2.5 and 17.3 prior to 17.3.2. A crafted URL could be used to trick a victim to trust an attacker controlled application. | CVSS3: 3.5 | 0% Низкий | почти 2 года назад | |
GHSA-xh98-g799-3775 The Opera Mobile application before 12.1 and Opera Mini application before 7.5 for Android do not properly implement the WebView class, which allows attackers to obtain sensitive information via a crafted application. | 1% Низкий | больше 4 лет назад | ||
GHSA-xh97-fh55-wr34 Missing Authorization vulnerability in turitop TuriTop Booking System allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects TuriTop Booking System: from n/a through 1.0.10. | CVSS3: 6.5 | 0% Низкий | больше 1 года назад | |
GHSA-xh97-73h5-gfm9 ephy-session.c in libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 allows remote attackers to cause a denial of service (application crash) via JavaScript code that triggers access to a NULL URL, as demonstrated by a crafted window.open call. | CVSS3: 7.5 | 1% Низкий | больше 4 лет назад | |
GHSA-xh97-72ww-2w58 Duplicate Advisory: Improper Verification of Cryptographic Signature in google-oauth-java-client | CVSS3: 7.3 | больше 4 лет назад | ||
GHSA-xh96-vq46-m9ww Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from its initial commit in 2002 (3861aa5) up to today on any platform allows an attacker on the local network to leak memory from four up to 32 bytes of memory stored behind the packet to the network depending on the later use of DHCP-provided parameters via crafted DHCP responses. | CVSS3: 8.1 | 1% Низкий | почти 2 года назад | |
GHSA-xh96-q52c-cw5m S-CMS PHP 1.0 has SQL injection in member/member_news.php via the type parameter (aka the $N_type field). | CVSS3: 9.8 | 1% Низкий | больше 4 лет назад | |
GHSA-xh96-g262-xhpr Tenda AC10 v4 US_AC10V4.0si_V16.03.10.13_cn was discovered to contain a stack overflow via parameter macFilterType and parameter deviceList at /goform/setMacFilterCfg. | CVSS3: 9.8 | 1% Низкий | почти 3 года назад | |
GHSA-xh96-fgxf-4776 Missing Authorization vulnerability in Frenify Guff guff allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Guff: from n/a through <= 1.0.1. | CVSS3: 7.5 | 0% Низкий | 5 месяцев назад | |
GHSA-xh96-5xc9-3w5h Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, allows attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code by calling the ActionScript native object 2200 connect method multiple times with different arguments, a different vulnerability than CVE-2010-2160, CVE-2010-2165, CVE-2010-2166, CVE-2010-2171, CVE-2010-2175, CVE-2010-2176, CVE-2010-2177, CVE-2010-2178, CVE-2010-2180, CVE-2010-2182, CVE-2010-2184, and CVE-2010-2187. | 7% Низкий | больше 4 лет назад | ||
GHSA-xh95-j7j4-ghg2 The BLOGCHAT Chat System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.6.3. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request granted they can trick a site administrator into performing an action such as clicking on a link. | CVSS3: 6.1 | 0% Низкий | 3 месяца назад |
Уязвимостей на страницу