Количество 359 267
Количество 359 267
GHSA-xgp2-f259-4rjq
Format string vulnerability in man in some Linux distributions allows local users to gain privileges via a malformed -l parameter.
GHSA-xgp2-cc4r-7vf6
Denial of Service in http-live-simulator
GHSA-xgp2-4cpq-g2m7
ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs.
GHSA-xgmx-rr3c-2xgc
The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authentication and execute arbitrary PHP code by uploading a crafted theme using wp-admin/admin-post.php and accessing the theme in wp-content/uploads/wysija/themes/mailp/.
GHSA-xgmx-j3hv-jh9x
TYPO3 Cross-Site Scripting in Link Handling
GHSA-xgmx-gwqj-mmc5
Juniper Networks ScreenOS devices do not pad Ethernet packets with zeros, and thus some packets can contain fragments of system memory or data from previous packets. This issue is often detected as CVE-2003-0001. The issue affects all versions of Juniper Networks ScreenOS prior to 6.3.0r25.
GHSA-xgmx-762m-r89c
PHPMyChat 0.14.5 does not remove or protect setup.php3 after installation, which allows attackers to obtain sensitive information including database passwords via a direct request.
GHSA-xgmx-456f-v7hp
Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an integer overflow or wraparound vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.
GHSA-xgmw-gxmf-fm4w
named in ISC BIND 9.x before 9.9.9-P4, 9.10.x before 9.10.4-P4, and 9.11.x before 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a DNAME record in the answer section of a response to a recursive query, related to db.c and resolver.c.
GHSA-xgmw-g7ph-gfh3
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9615, MDM9625, MDM9635M, SD 400, SD 600, and SD 800, a buffer overflow can occur when processing an audio buffer.
GHSA-xgmw-fp9v-9rff
Cross Site Request Forgery (CSRF) vulnerability in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain control of the device via crafted GET request to /man_password.htm.
GHSA-xgmv-27h3-874r
A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_2/PM_io_parser.h PM_io_parser::read_vertex() Face_of[] OOB read. An attacker can provide malicious input to trigger this vulnerability.
GHSA-xgmv-256h-6689
A vulnerability was found in Jinher OA up to 1.2. This impacts an unknown function of the file /c6/Jhsoft.Web.projectmanage/TaskManage/AddTask.aspx/?Type=add of the component XML Handler. The manipulation results in xml external entity reference. The attack can be executed remotely. The exploit has been made public and could be used.
GHSA-xgmr-mh2m-j5vq
The WP Recipe Maker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘Referer' header in all versions up to, and including, 9.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
GHSA-xgmr-hcvf-x3qc
CamaleonCMS 2.9.1 contains a server-side template injection vulnerability that allows authenticated administrators to execute arbitrary commands by embedding ERB tags in the email parameter of the test_email settings action, which are evaluated when an SMTP rejection reflects the recipient address back in the exception message rendered as an inline ERB template. Attackers can submit a crafted email parameter containing ERB expressions through the admin settings test_email endpoint, causing the Rails inline template renderer to evaluate attacker-controlled Ruby code and achieve arbitrary command execution as the Rails process user.
GHSA-xgmq-mgc9-gwfc
code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket.php.
GHSA-xgmp-w3rr-9p7r
An access control issue in MantisBT before 1.2.13 allows users with "Reporter" permissions to change any issue to "New".
GHSA-xgmp-rp9g-wppg
Open redirect vulnerability in Novius OS 5.0.1 (Elche) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect parameter to admin/nos/login.
GHSA-xgmp-mj76-c47c
Linksys EtherFast BEFN2PS4, BEFSR41, and BEFSR81 Routers, and possibly other products, allow remote attackers to gain sensitive information and cause a denial of service via an SNMP query for the default community string "public," which causes the router to change its configuration and send SNMP trap information back to the system that initiated the query.
GHSA-xgmm-vjx3-4m7q
Black Box iCOMPEL 9.2.3 through 11.1.4, as used in ONELAN Net-Top-Box 9.2.3 through 11.1.4 and other products, has default credentials that allow remote attackers to access devices remotely via SSH, HTTP, HTTPS, and FTP.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xgp2-f259-4rjq Format string vulnerability in man in some Linux distributions allows local users to gain privileges via a malformed -l parameter. | 1% Низкий | больше 4 лет назад | ||
GHSA-xgp2-cc4r-7vf6 Denial of Service in http-live-simulator | почти 6 лет назад | |||
GHSA-xgp2-4cpq-g2m7 ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs. | CVSS3: 7.5 | 26% Средний | больше 4 лет назад | |
GHSA-xgmx-rr3c-2xgc The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authentication and execute arbitrary PHP code by uploading a crafted theme using wp-admin/admin-post.php and accessing the theme in wp-content/uploads/wysija/themes/mailp/. | 60% Средний | больше 4 лет назад | ||
GHSA-xgmx-j3hv-jh9x TYPO3 Cross-Site Scripting in Link Handling | CVSS3: 6.1 | около 2 лет назад | ||
GHSA-xgmx-gwqj-mmc5 Juniper Networks ScreenOS devices do not pad Ethernet packets with zeros, and thus some packets can contain fragments of system memory or data from previous packets. This issue is often detected as CVE-2003-0001. The issue affects all versions of Juniper Networks ScreenOS prior to 6.3.0r25. | CVSS3: 6.5 | 1% Низкий | больше 4 лет назад | |
GHSA-xgmx-762m-r89c PHPMyChat 0.14.5 does not remove or protect setup.php3 after installation, which allows attackers to obtain sensitive information including database passwords via a direct request. | 2% Низкий | больше 4 лет назад | ||
GHSA-xgmx-456f-v7hp Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 release version 8.3.1.0 through 8.3.1.30, LTS2024 release versions 7.13.1.0 through 7.13.1.70 contain an integer overflow or wraparound vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service. | CVSS3: 6.5 | 0% Низкий | около 2 месяцев назад | |
GHSA-xgmw-gxmf-fm4w named in ISC BIND 9.x before 9.9.9-P4, 9.10.x before 9.10.4-P4, and 9.11.x before 9.11.0-P1 allows remote attackers to cause a denial of service (assertion failure and daemon exit) via a DNAME record in the answer section of a response to a recursive query, related to db.c and resolver.c. | CVSS3: 7.5 | 39% Средний | больше 4 лет назад | |
GHSA-xgmw-g7ph-gfh3 In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile MDM9615, MDM9625, MDM9635M, SD 400, SD 600, and SD 800, a buffer overflow can occur when processing an audio buffer. | CVSS3: 9.8 | 1% Низкий | больше 4 лет назад | |
GHSA-xgmw-fp9v-9rff Cross Site Request Forgery (CSRF) vulnerability in Connectize AC21000 G6 641.139.1.1256 allows attackers to gain control of the device via crafted GET request to /man_password.htm. | CVSS3: 8.8 | 0% Низкий | больше 2 лет назад | |
GHSA-xgmv-27h3-874r A code execution vulnerability exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. An oob read vulnerability exists in Nef_2/PM_io_parser.h PM_io_parser::read_vertex() Face_of[] OOB read. An attacker can provide malicious input to trigger this vulnerability. | CVSS3: 9.8 | 3% Низкий | около 4 лет назад | |
GHSA-xgmv-256h-6689 A vulnerability was found in Jinher OA up to 1.2. This impacts an unknown function of the file /c6/Jhsoft.Web.projectmanage/TaskManage/AddTask.aspx/?Type=add of the component XML Handler. The manipulation results in xml external entity reference. The attack can be executed remotely. The exploit has been made public and could be used. | CVSS3: 7.3 | 1% Низкий | 11 месяцев назад | |
GHSA-xgmr-mh2m-j5vq The WP Recipe Maker plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘Referer' header in all versions up to, and including, 9.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. | CVSS3: 6.1 | 1% Низкий | больше 2 лет назад | |
GHSA-xgmr-hcvf-x3qc CamaleonCMS 2.9.1 contains a server-side template injection vulnerability that allows authenticated administrators to execute arbitrary commands by embedding ERB tags in the email parameter of the test_email settings action, which are evaluated when an SMTP rejection reflects the recipient address back in the exception message rendered as an inline ERB template. Attackers can submit a crafted email parameter containing ERB expressions through the admin settings test_email endpoint, causing the Rails inline template renderer to evaluate attacker-controlled Ruby code and achieve arbitrary command execution as the Rails process user. | CVSS3: 6.6 | 1% Низкий | 5 дней назад | |
GHSA-xgmq-mgc9-gwfc code-projects Simple Food Order System v1.0 is vulnerable to SQL Injection in /food/view-ticket.php. | CVSS3: 9.8 | 0% Низкий | 6 месяцев назад | |
GHSA-xgmp-w3rr-9p7r An access control issue in MantisBT before 1.2.13 allows users with "Reporter" permissions to change any issue to "New". | 1% Низкий | больше 4 лет назад | ||
GHSA-xgmp-rp9g-wppg Open redirect vulnerability in Novius OS 5.0.1 (Elche) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect parameter to admin/nos/login. | 13% Средний | больше 4 лет назад | ||
GHSA-xgmp-mj76-c47c Linksys EtherFast BEFN2PS4, BEFSR41, and BEFSR81 Routers, and possibly other products, allow remote attackers to gain sensitive information and cause a denial of service via an SNMP query for the default community string "public," which causes the router to change its configuration and send SNMP trap information back to the system that initiated the query. | 2% Низкий | больше 4 лет назад | ||
GHSA-xgmm-vjx3-4m7q Black Box iCOMPEL 9.2.3 through 11.1.4, as used in ONELAN Net-Top-Box 9.2.3 through 11.1.4 and other products, has default credentials that allow remote attackers to access devices remotely via SSH, HTTP, HTTPS, and FTP. | CVSS3: 9.8 | 3% Низкий | около 4 лет назад |
Уязвимостей на страницу