Количество 360 872
Количество 360 872
GHSA-xgf9-9fpj-mv3c
Heap-based buffer overflow in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code via unspecified vectors.
GHSA-xgf9-7jgm-fgxp
In the Linux kernel, the following vulnerability has been resolved: usb: typec: altmodes/displayport: fix pin_assignment_show This patch fixes negative indexing of buf array in pin_assignment_show when get_current_pin_assignments returns 0 i.e. no compatible pin assignments are found. BUG: KASAN: use-after-free in pin_assignment_show+0x26c/0x33c ... Call trace: dump_backtrace+0x110/0x204 dump_stack_lvl+0x84/0xbc print_report+0x358/0x974 kasan_report+0x9c/0xfc __do_kernel_fault+0xd4/0x2d4 do_bad_area+0x48/0x168 do_tag_check_fault+0x24/0x38 do_mem_abort+0x6c/0x14c el1_abort+0x44/0x68 el1h_64_sync_handler+0x64/0xa4 el1h_64_sync+0x78/0x7c pin_assignment_show+0x26c/0x33c dev_attr_show+0x50/0xc0
GHSA-xgf9-6xh9-8mvh
Array index error in Adobe Shockwave Player before 11.5.2.602 allows remote attackers to execute arbitrary code via crafted Shockwave content on a web site. NOTE: some of these details are obtained from third party information.
GHSA-xgf9-6mx9-6fv3
IBM QRadar SIEM 7.3 and 7.4 when configured to use Active Directory Authentication may be susceptible to spoofing attacks. IBM X-Force ID: 165877.
GHSA-xgf9-46hc-5c98
The Mailgun for WordPress plugin before 2.2.1 does not perform any capability or nonce check on an unauthenticated AJAX action that adds subscribers to the site owner's configured email service mailing lists, allowing unauthenticated attackers to enrol arbitrary email addresses into those lists using the owner's stored API credentials.
GHSA-xgf8-98pj-cm5c
An issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can occur when a client disconnects during D-Bus processing of a WriteValue call.
GHSA-xgf8-6gvg-9rvw
A vulnerability in synotheme_upload.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to upload arbitrary files without authentication via the logo_upload action.
GHSA-xgf8-49jx-rh6m
iMessage (Messages app) iOS 12.4 and prior user interface does not properly represent URI messages to the user, which results in URI spoofing via specially crafted messages.
GHSA-xgf6-69f9-3847
Nokia OneNDS 17r2 has Insecure Permissions vulnerability that allows for privilege escalation.
GHSA-xgf6-3v64-jvfv
Vulnerability in the Oracle One-to-One Fulfillment component of Oracle E-Business Suite (subcomponent: Print Server). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle One-to-One Fulfillment. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle One-to-One Fulfillment, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle One-to-One Fulfillment accessible data as well as unauthorized update, insert or delete access to some of Oracle One-to-One Fulfillment accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).
GHSA-xgf5-5gjr-4hjq
Directory Traversal in zjjserver
GHSA-xgf4-vh79-4g7j
IBM Security Verify Privilege On-Premises 11.5 does not validate, or incorrectly validates, a certificate which could disclose sensitive information which could aid further attacks against the system. IBM X-Force ID: 240455.
GHSA-xgf4-g8fr-fcv9
Authorization Bypass Through User-Controlled Key vulnerability in Wptexture Image Slider Slideshow allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Slider Slideshow: from n/a through 1.8.
GHSA-xgf4-6mjg-7hqq
Transient DOS due to reachable assertion in Modem when UE received Downlink Data Indication message from the network.
GHSA-xgf3-qx4m-5q5j
In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc4-topology: Fix input format query of process modules without base extension If a process module does not have base config extension then the same format applies to all of it's inputs and the process->base_config_ext is NULL, causing NULL dereference when specifically crafted topology and sequences used.
GHSA-xgf3-6w37-8rhc
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.0 through 6.1.0.6 CF27, 6.1.5.0 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF28, and 8.0.0 before 8.0.0.1 CF12 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
GHSA-xgf3-3873-jq4x
The zoho-salesiq plugin before 1.0.9 for WordPress has CSRF.
GHSA-xgf2-vxv2-rrmg
OpenClaw's shell startup env injection bypasses system.run allowlist intent (RCE class)
GHSA-xgf2-5w76-r5jg
Missing access permissions checks in M-Files Client before 23.5.12598.0 allows elevation of privilege via UI extension applications
GHSA-xgcx-vvr8-486q
In Joomla! 3.5.0 through 3.8.5, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the User Notes list view.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xgf9-9fpj-mv3c Heap-based buffer overflow in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on Linux, Adobe AIR before 20.0.0.260, Adobe AIR SDK before 20.0.0.260, and Adobe AIR SDK & Compiler before 20.0.0.260 allows attackers to execute arbitrary code via unspecified vectors. | CVSS3: 9.8 | 35% Средний | больше 4 лет назад | |
GHSA-xgf9-7jgm-fgxp In the Linux kernel, the following vulnerability has been resolved: usb: typec: altmodes/displayport: fix pin_assignment_show This patch fixes negative indexing of buf array in pin_assignment_show when get_current_pin_assignments returns 0 i.e. no compatible pin assignments are found. BUG: KASAN: use-after-free in pin_assignment_show+0x26c/0x33c ... Call trace: dump_backtrace+0x110/0x204 dump_stack_lvl+0x84/0xbc print_report+0x358/0x974 kasan_report+0x9c/0xfc __do_kernel_fault+0xd4/0x2d4 do_bad_area+0x48/0x168 do_tag_check_fault+0x24/0x38 do_mem_abort+0x6c/0x14c el1_abort+0x44/0x68 el1h_64_sync_handler+0x64/0xa4 el1h_64_sync+0x78/0x7c pin_assignment_show+0x26c/0x33c dev_attr_show+0x50/0xc0 | CVSS3: 7.8 | 0% Низкий | 8 месяцев назад | |
GHSA-xgf9-6xh9-8mvh Array index error in Adobe Shockwave Player before 11.5.2.602 allows remote attackers to execute arbitrary code via crafted Shockwave content on a web site. NOTE: some of these details are obtained from third party information. | 6% Низкий | больше 4 лет назад | ||
GHSA-xgf9-6mx9-6fv3 IBM QRadar SIEM 7.3 and 7.4 when configured to use Active Directory Authentication may be susceptible to spoofing attacks. IBM X-Force ID: 165877. | 2% Низкий | около 4 лет назад | ||
GHSA-xgf9-46hc-5c98 The Mailgun for WordPress plugin before 2.2.1 does not perform any capability or nonce check on an unauthenticated AJAX action that adds subscribers to the site owner's configured email service mailing lists, allowing unauthenticated attackers to enrol arbitrary email addresses into those lists using the owner's stored API credentials. | CVSS3: 6.5 | 0% Низкий | 19 дней назад | |
GHSA-xgf8-98pj-cm5c An issue was discovered in gatt-database.c in BlueZ 5.61. A use-after-free can occur when a client disconnects during D-Bus processing of a WriteValue call. | CVSS3: 9.1 | 2% Низкий | около 4 лет назад | |
GHSA-xgf8-6gvg-9rvw A vulnerability in synotheme_upload.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to upload arbitrary files without authentication via the logo_upload action. | CVSS3: 9.8 | 16% Средний | больше 4 лет назад | |
GHSA-xgf8-49jx-rh6m iMessage (Messages app) iOS 12.4 and prior user interface does not properly represent URI messages to the user, which results in URI spoofing via specially crafted messages. | CVSS3: 6.5 | 1% Низкий | больше 4 лет назад | |
GHSA-xgf6-69f9-3847 Nokia OneNDS 17r2 has Insecure Permissions vulnerability that allows for privilege escalation. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-xgf6-3v64-jvfv Vulnerability in the Oracle One-to-One Fulfillment component of Oracle E-Business Suite (subcomponent: Print Server). Supported versions that are affected are 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily "exploitable" vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle One-to-One Fulfillment. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle One-to-One Fulfillment, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle One-to-One Fulfillment accessible data as well as unauthorized update, insert or delete access to some of Oracle One-to-One Fulfillment accessible data. CVSS 3.0 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N). | CVSS3: 7.1 | 2% Низкий | больше 4 лет назад | |
GHSA-xgf5-5gjr-4hjq Directory Traversal in zjjserver | CVSS3: 7.5 | 2% Низкий | почти 6 лет назад | |
GHSA-xgf4-vh79-4g7j IBM Security Verify Privilege On-Premises 11.5 does not validate, or incorrectly validates, a certificate which could disclose sensitive information which could aid further attacks against the system. IBM X-Force ID: 240455. | CVSS3: 3.7 | 0% Низкий | почти 3 года назад | |
GHSA-xgf4-g8fr-fcv9 Authorization Bypass Through User-Controlled Key vulnerability in Wptexture Image Slider Slideshow allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Slider Slideshow: from n/a through 1.8. | CVSS3: 4.3 | 0% Низкий | 7 месяцев назад | |
GHSA-xgf4-6mjg-7hqq Transient DOS due to reachable assertion in Modem when UE received Downlink Data Indication message from the network. | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
GHSA-xgf3-qx4m-5q5j In the Linux kernel, the following vulnerability has been resolved: ASoC: SOF: ipc4-topology: Fix input format query of process modules without base extension If a process module does not have base config extension then the same format applies to all of it's inputs and the process->base_config_ext is NULL, causing NULL dereference when specifically crafted topology and sequences used. | CVSS3: 5.5 | 0% Низкий | около 2 лет назад | |
GHSA-xgf3-6w37-8rhc Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.0 through 6.1.0.6 CF27, 6.1.5.0 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF28, and 8.0.0 before 8.0.0.1 CF12 allows remote attackers to inject arbitrary web script or HTML via a crafted URL. | 2% Низкий | больше 4 лет назад | ||
GHSA-xgf3-3873-jq4x The zoho-salesiq plugin before 1.0.9 for WordPress has CSRF. | CVSS3: 8.8 | 1% Низкий | около 4 лет назад | |
GHSA-xgf2-vxv2-rrmg OpenClaw's shell startup env injection bypasses system.run allowlist intent (RCE class) | CVSS3: 7.5 | 1% Низкий | 6 месяцев назад | |
GHSA-xgf2-5w76-r5jg Missing access permissions checks in M-Files Client before 23.5.12598.0 allows elevation of privilege via UI extension applications | CVSS3: 7.5 | 0% Низкий | около 3 лет назад | |
GHSA-xgcx-vvr8-486q In Joomla! 3.5.0 through 3.8.5, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the User Notes list view. | CVSS3: 8.8 | 29% Средний | больше 4 лет назад |
Уязвимостей на страницу