Количество 359 267
Количество 359 267
GHSA-xh58-cx6c-2h9h
Heap-based buffer overflow in the K7FWFilt.sys kernel mode driver (aka K7Firewall Packet Driver) before 14.0.1.16, as used in multiple K7 Computing products, allows local users to execute arbitrary code with kernel privileges via a crafted parameter in a DeviceIoControl API call.
GHSA-xh57-2h8m-3798
Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromSetlpBind function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
GHSA-xh56-mjcr-q6vw
Use after free in WebRTC in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
GHSA-xh56-g7w6-x8rp
The view-source feature in Google Chrome before 16.0.912.63 allows remote attackers to spoof the URL bar via unspecified vectors.
GHSA-xh56-fj78-hc8j
Untrusted search path vulnerability in TKY2JGD (TKY2JGD1379.EXE) ver. 1.3.79 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
GHSA-xh56-3xp6-p447
IntelliJ IDEA XML parser was found vulnerable to XML External Entity attack, an attacker can exploit the vulnerability by implementing malicious code on both Androidmanifest.xml.
GHSA-xh56-3f5w-9h25
nodemailer-js is malware
GHSA-xh56-3cv8-89c9
Cross-Site Request Forgery (CSRF) vulnerability in Andrea Tarantini Menubar plugin <= 5.8.2 versions.
GHSA-xh56-37r6-8jjx
WP User Groups version 2.0.0 contains a Cross ite Request Forgery (CSRF) vulnerability in Settings page that can result in allows anybody to modify user groups and types. This attack appear to be exploitable via Admin must click on link. This vulnerability appears to have been fixed in 2.1.1.
GHSA-xh55-2fqp-p775
Command injection in mail agent settings
GHSA-xh54-v5gh-jq8v
The Team Members Showcase WordPress plugin before 3.5.0 does not sanitize and escape a parameter before outputting it back in the page, leading to reflected cross-site scripting, which could be used against high-privilege users such as admins.
GHSA-xh54-hh7j-wm53
ICQ Web Front HTTPd allows remote attackers to cause a denial of service by requesting a URL that contains a "?" character.
GHSA-xh54-7xjp-2239
An access issue was addressed with additional sandbox restrictions on third-party apps. This issue is fixed in macOS Ventura 13. An app may be able to record audio with paired AirPods.
GHSA-xh53-wc36-2h2x
Cross-Site Request Forgery (CSRF) vulnerability in ApusTheme Findgo allows Cross Site Request Forgery. This issue affects Findgo: from n/a through 1.3.57.
GHSA-xh53-849p-cfvq
D-Link DI-8400 16.07.26A1 is vulnerable to Command Injection via upgrade_filter_asp.
GHSA-xh53-2m5x-5pw7
A memory corruption issue was addressed with improved input validation. This issue affected versions prior to macOS Mojave 10.14.
GHSA-xh52-rg2r-x4m5
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-284 Improper Access Control, and stores project data in a directory with improper access control lists.
GHSA-xh52-6wwc-2j2x
Unrestricted Upload of File with Dangerous Type in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated attackers to upload malicious files to the DLP case management section via lack of sanity checking.
GHSA-xh52-5493-q8vx
A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001 and classified as critical. Affected by this issue is the function RP_checkFWByBBS of the file /goform/RP_checkFWByBBS. The manipulation of the argument type/ch/ssidhex/security/extch/pwd/mode/ip/nm/gw leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
GHSA-xh4x-ph6p-vmxh
An issue was discovered in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3. It does not taint strings that result from unpacking tainted strings with some formats.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xh58-cx6c-2h9h Heap-based buffer overflow in the K7FWFilt.sys kernel mode driver (aka K7Firewall Packet Driver) before 14.0.1.16, as used in multiple K7 Computing products, allows local users to execute arbitrary code with kernel privileges via a crafted parameter in a DeviceIoControl API call. | 1% Низкий | больше 4 лет назад | ||
GHSA-xh57-2h8m-3798 Tenda FH1206 v02.03.01.35 was discovered to contain a stack overflow via the page parameter in the fromSetlpBind function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | CVSS3: 6.5 | 1% Низкий | около 2 лет назад | |
GHSA-xh56-mjcr-q6vw Use after free in WebRTC in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | CVSS3: 8.8 | 0% Низкий | 5 месяцев назад | |
GHSA-xh56-g7w6-x8rp The view-source feature in Google Chrome before 16.0.912.63 allows remote attackers to spoof the URL bar via unspecified vectors. | 1% Низкий | больше 4 лет назад | ||
GHSA-xh56-fj78-hc8j Untrusted search path vulnerability in TKY2JGD (TKY2JGD1379.EXE) ver. 1.3.79 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | CVSS3: 7.8 | 1% Низкий | больше 4 лет назад | |
GHSA-xh56-3xp6-p447 IntelliJ IDEA XML parser was found vulnerable to XML External Entity attack, an attacker can exploit the vulnerability by implementing malicious code on both Androidmanifest.xml. | CVSS3: 7.5 | 2% Низкий | больше 4 лет назад | |
GHSA-xh56-3f5w-9h25 nodemailer-js is malware | CVSS3: 7.5 | 1% Низкий | почти 8 лет назад | |
GHSA-xh56-3cv8-89c9 Cross-Site Request Forgery (CSRF) vulnerability in Andrea Tarantini Menubar plugin <= 5.8.2 versions. | CVSS3: 5.4 | 0% Низкий | около 3 лет назад | |
GHSA-xh56-37r6-8jjx WP User Groups version 2.0.0 contains a Cross ite Request Forgery (CSRF) vulnerability in Settings page that can result in allows anybody to modify user groups and types. This attack appear to be exploitable via Admin must click on link. This vulnerability appears to have been fixed in 2.1.1. | CVSS3: 6.5 | 0% Низкий | больше 4 лет назад | |
GHSA-xh55-2fqp-p775 Command injection in mail agent settings | CVSS3: 8.8 | 2% Низкий | почти 5 лет назад | |
GHSA-xh54-v5gh-jq8v The Team Members Showcase WordPress plugin before 3.5.0 does not sanitize and escape a parameter before outputting it back in the page, leading to reflected cross-site scripting, which could be used against high-privilege users such as admins. | CVSS3: 6.1 | 0% Низкий | 9 месяцев назад | |
GHSA-xh54-hh7j-wm53 ICQ Web Front HTTPd allows remote attackers to cause a denial of service by requesting a URL that contains a "?" character. | 5% Низкий | больше 4 лет назад | ||
GHSA-xh54-7xjp-2239 An access issue was addressed with additional sandbox restrictions on third-party apps. This issue is fixed in macOS Ventura 13. An app may be able to record audio with paired AirPods. | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад | |
GHSA-xh53-wc36-2h2x Cross-Site Request Forgery (CSRF) vulnerability in ApusTheme Findgo allows Cross Site Request Forgery. This issue affects Findgo: from n/a through 1.3.57. | CVSS3: 8.8 | 0% Низкий | около 1 года назад | |
GHSA-xh53-849p-cfvq D-Link DI-8400 16.07.26A1 is vulnerable to Command Injection via upgrade_filter_asp. | CVSS3: 8 | 14% Средний | почти 2 года назад | |
GHSA-xh53-2m5x-5pw7 A memory corruption issue was addressed with improved input validation. This issue affected versions prior to macOS Mojave 10.14. | CVSS3: 7.8 | 1% Низкий | больше 4 лет назад | |
GHSA-xh52-rg2r-x4m5 Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-284 Improper Access Control, and stores project data in a directory with improper access control lists. | CVSS3: 7.5 | 0% Низкий | почти 4 года назад | |
GHSA-xh52-6wwc-2j2x Unrestricted Upload of File with Dangerous Type in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated attackers to upload malicious files to the DLP case management section via lack of sanity checking. | 1% Низкий | около 4 лет назад | ||
GHSA-xh52-5493-q8vx A vulnerability was found in Linksys RE6500, RE6250, RE6300, RE6350, RE7000 and RE9000 1.0.013.001/1.0.04.001/1.0.04.002/1.1.05.003/1.2.07.001 and classified as critical. Affected by this issue is the function RP_checkFWByBBS of the file /goform/RP_checkFWByBBS. The manipulation of the argument type/ch/ssidhex/security/extch/pwd/mode/ip/nm/gw leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 6.3 | 21% Средний | около 1 года назад | |
GHSA-xh4x-ph6p-vmxh An issue was discovered in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3. It does not taint strings that result from unpacking tainted strings with some formats. | CVSS3: 8.1 | 8% Низкий | больше 4 лет назад |
Уязвимостей на страницу