Количество 359 267
Количество 359 267
GHSA-xh2m-55cw-vq57
The Pricing Table by Supsystic WordPress plugin before 1.9.5 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting
GHSA-xh2j-q4mc-v522
Moodle calculated question type allows remote code execution by Question authors
GHSA-xh2h-xr83-rv32
An issue was discovered in the Secure Boot component in Samsung Mobile Processor and Wearable Processor Exynos 9820, 9825, 980, 990, 850, 1080, 1280, 2200, 1330, 1380, 1480, 2400. The lack of a length check leads to out-of-bounds writes.
GHSA-xh2h-f6rw-xfqx
Improper validation of the cloud certificate chain in Mobile Connect allows man-in-the-middle attack to impersonate the legitimate Command Centre Server. This issue affects: Gallagher Command Centre Mobile Connect for Android 15 versions prior to 15.04.040; version 14 and prior versions.
GHSA-xh2h-cw6h-x9h5
Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit f070ef2ac66716357066b683fb0baf55f8191a2e.
GHSA-xh2g-m2wv-2336
A vulnerability classified as critical was found in CodeAstro Membership Management System 1.0. This vulnerability affects unknown code of the file settings.php. The manipulation of the argument currency leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-255502 is the identifier assigned to this vulnerability.
GHSA-xh2g-2958-rp54
BlueCMS 1.6 allows SQL Injection via the user_id parameter in an uploads/admin/user.php?act=edit request.
GHSA-xh2f-mpwc-mhh4
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Gutenberg allows Cross Site Request Forgery.This issue affects Gutenberg: from 0.0.0 before 2.13.0, from 3.0.0 before 3.0.5.
GHSA-xh2f-j4vc-q8qj
In the Linux kernel, the following vulnerability has been resolved: media: platform: mtk-mdp3: Add missing check and free for ida_alloc Add the check for the return value of the ida_alloc in order to avoid NULL pointer dereference. Moreover, free allocated "ctx->id" if mdp_m2m_open fails later in order to avoid memory leak.
GHSA-xh2f-h76w-4qqc
The PTR_MANGLE implementation in the GNU C Library (aka glibc or libc6) 2.4, 2.17, and earlier, and Embedded GLIBC (EGLIBC) does not initialize the random value for the pointer guard, which makes it easier for context-dependent attackers to control execution flow by leveraging a buffer-overflow vulnerability in an application and using the known zero value pointer guard to calculate a pointer address.
GHSA-xh2c-vxrg-5c77
JPEGDEC commit be4843c was discovered to contain a segmentation fault via fseek at /libio/fseek.c.
GHSA-xh2c-m49q-f2gf
Missing Authorization vulnerability in RedNao Smart Forms.This issue affects Smart Forms: from n/a through 2.6.91.
GHSA-xh2c-fh83-6hgx
In affected versions of Octopus Deploy it is possible to bypass rate limiting on login using null bytes.
GHSA-xh2c-5r7j-3g84
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
GHSA-xh29-wvh5-6vww
RPC endpoint mapper in Windows NT 4.0 allows remote attackers to cause a denial of service (loss of RPC services) via a malformed request.
GHSA-xh29-r392-48pf
The Head, Footer and Post Injections plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3.3.0. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject PHP Code in multisite environments.
GHSA-xh29-r2w5-wx8m
Nokogiri Improperly Handles Unexpected Data Type
GHSA-xh29-jpw9-pv7c
In the Linux kernel, the following vulnerability has been resolved: iio: adc: at91_adc: fix possible memory leak in at91_adc_allocate_trigger() If iio_trigger_register() returns error, it should call iio_trigger_free() to give up the reference that hold in iio_trigger_alloc(), so that it can call iio_trig_release() to free memory when the refcount hit to 0.
GHSA-xh29-778x-wq63
Multiple cross-site scripting (XSS) vulnerabilities in account_settings.php in TorrentTrader 1.07 allow remote attackers to inject arbitrary web script or HTML via the (1) avatar and (2) title parameters.
GHSA-xh28-r3j4-439x
Missing Authorization vulnerability in QuantumCloud ChatBot chatbot allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ChatBot: from n/a through <= 7.3.9.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xh2m-55cw-vq57 The Pricing Table by Supsystic WordPress plugin before 1.9.5 does not escape the tab parameter before outputting it back in an attribute in the admin dashboard, leading to a Reflected Cross-Site Scripting | CVSS3: 6.1 | 1% Низкий | больше 4 лет назад | |
GHSA-xh2j-q4mc-v522 Moodle calculated question type allows remote code execution by Question authors | CVSS3: 8.8 | 32% Средний | больше 4 лет назад | |
GHSA-xh2h-xr83-rv32 An issue was discovered in the Secure Boot component in Samsung Mobile Processor and Wearable Processor Exynos 9820, 9825, 980, 990, 850, 1080, 1280, 2200, 1330, 1380, 1480, 2400. The lack of a length check leads to out-of-bounds writes. | CVSS3: 5.3 | 0% Низкий | 10 месяцев назад | |
GHSA-xh2h-f6rw-xfqx Improper validation of the cloud certificate chain in Mobile Connect allows man-in-the-middle attack to impersonate the legitimate Command Centre Server. This issue affects: Gallagher Command Centre Mobile Connect for Android 15 versions prior to 15.04.040; version 14 and prior versions. | 0% Низкий | около 4 лет назад | ||
GHSA-xh2h-cw6h-x9h5 Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127, 4.19.52, 5.1.11, and is fixed in commit f070ef2ac66716357066b683fb0baf55f8191a2e. | CVSS3: 7.5 | 95% Критический | около 4 лет назад | |
GHSA-xh2g-m2wv-2336 A vulnerability classified as critical was found in CodeAstro Membership Management System 1.0. This vulnerability affects unknown code of the file settings.php. The manipulation of the argument currency leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-255502 is the identifier assigned to this vulnerability. | CVSS3: 4.7 | 1% Низкий | больше 2 лет назад | |
GHSA-xh2g-2958-rp54 BlueCMS 1.6 allows SQL Injection via the user_id parameter in an uploads/admin/user.php?act=edit request. | CVSS3: 9.8 | 1% Низкий | больше 4 лет назад | |
GHSA-xh2f-mpwc-mhh4 Cross-Site Request Forgery (CSRF) vulnerability in Drupal Gutenberg allows Cross Site Request Forgery.This issue affects Gutenberg: from 0.0.0 before 2.13.0, from 3.0.0 before 3.0.5. | CVSS3: 8.8 | 0% Низкий | больше 1 года назад | |
GHSA-xh2f-j4vc-q8qj In the Linux kernel, the following vulnerability has been resolved: media: platform: mtk-mdp3: Add missing check and free for ida_alloc Add the check for the return value of the ida_alloc in order to avoid NULL pointer dereference. Moreover, free allocated "ctx->id" if mdp_m2m_open fails later in order to avoid memory leak. | 0% Низкий | 8 месяцев назад | ||
GHSA-xh2f-h76w-4qqc The PTR_MANGLE implementation in the GNU C Library (aka glibc or libc6) 2.4, 2.17, and earlier, and Embedded GLIBC (EGLIBC) does not initialize the random value for the pointer guard, which makes it easier for context-dependent attackers to control execution flow by leveraging a buffer-overflow vulnerability in an application and using the known zero value pointer guard to calculate a pointer address. | 11% Средний | больше 4 лет назад | ||
GHSA-xh2c-vxrg-5c77 JPEGDEC commit be4843c was discovered to contain a segmentation fault via fseek at /libio/fseek.c. | CVSS3: 5.5 | 0% Низкий | около 4 лет назад | |
GHSA-xh2c-m49q-f2gf Missing Authorization vulnerability in RedNao Smart Forms.This issue affects Smart Forms: from n/a through 2.6.91. | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад | |
GHSA-xh2c-fh83-6hgx In affected versions of Octopus Deploy it is possible to bypass rate limiting on login using null bytes. | CVSS3: 9.8 | 1% Низкий | почти 4 года назад | |
GHSA-xh2c-5r7j-3g84 Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. | CVSS3: 7 | 0% Низкий | около 1 года назад | |
GHSA-xh29-wvh5-6vww RPC endpoint mapper in Windows NT 4.0 allows remote attackers to cause a denial of service (loss of RPC services) via a malformed request. | 22% Средний | больше 4 лет назад | ||
GHSA-xh29-r392-48pf The Head, Footer and Post Injections plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3.3.0. This makes it possible for authenticated attackers, with Administrator-level access and above, to inject PHP Code in multisite environments. | CVSS3: 4.1 | 0% Низкий | больше 1 года назад | |
GHSA-xh29-r2w5-wx8m Nokogiri Improperly Handles Unexpected Data Type | CVSS3: 8.2 | 3% Низкий | около 4 лет назад | |
GHSA-xh29-jpw9-pv7c In the Linux kernel, the following vulnerability has been resolved: iio: adc: at91_adc: fix possible memory leak in at91_adc_allocate_trigger() If iio_trigger_register() returns error, it should call iio_trigger_free() to give up the reference that hold in iio_trigger_alloc(), so that it can call iio_trig_release() to free memory when the refcount hit to 0. | CVSS3: 5.5 | 0% Низкий | больше 1 года назад | |
GHSA-xh29-778x-wq63 Multiple cross-site scripting (XSS) vulnerabilities in account_settings.php in TorrentTrader 1.07 allow remote attackers to inject arbitrary web script or HTML via the (1) avatar and (2) title parameters. | 1% Низкий | больше 4 лет назад | ||
GHSA-xh28-r3j4-439x Missing Authorization vulnerability in QuantumCloud ChatBot chatbot allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ChatBot: from n/a through <= 7.3.9. | CVSS3: 5.3 | 0% Низкий | 9 месяцев назад |
Уязвимостей на страницу