Количество 374 825
Количество 374 825
GHSA-xx3g-v5fx-v7w6
launchAnyWhere vulnerability in the ActivityManagerService module. Successful exploitation of this vulnerability will affect availability.
GHSA-xx3g-89q2-w8hh
Cross-site scripting (XSS) vulnerability in the search functionality in Simon Brown Pebble 2.0.0 RC1 and RC2 allows remote attackers to inject arbitrary web script or HTML via the query string.
GHSA-xx3f-8qwx-w9mh
The (1) av-centerd SOAP service and (2) backup command in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attackers to execute arbitrary commands via unspecified vectors.
GHSA-xx3f-44rh-4g76
Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.13489 on Windows allows an attacker to load an arbitrary Windows library. The patch released in version 12.2.0.16909 to mitigate CVE-2024-7262 was not restrictive enough. Another hyperlink parameter was not properly sanitized which leads to the execution of an arbitrary Windows library.
GHSA-xx3f-437p-fp69
A vulnerability was found in D-Link DI-7400G+ 19.12.25A1. This affects an unknown function of the file /msp_info.htm?flag=cmd. The manipulation of the argument cmd results in command injection. The attack can be launched remotely. The exploit has been made public and could be used.
GHSA-xx3c-ww24-2pgq
Template injection (Improper Neutralization of Special Elements Used in a Template Engine) vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.75, Ver.2.9.x series versions prior to Ver.2.9.40, Ver.2.10.x series versions prior to Ver.2.10.44, Ver.2.11.x series versions prior to Ver.2.11.42, and Ver.3.0.x series versions prior to Ver.3.0.1 allows a remote authenticated attacker to obtain an arbitrary file on the server via unspecified vectors.
GHSA-xx3c-qf5g-hc39
Symfony has an Argument Injection in SendmailTransport via Dash-Prefixed Recipient Address
GHSA-xx3c-6h6w-w5rg
JWT.php in F21 JWT before 2.0 allows remote attackers to bypass signature verification via crafted tokens.
GHSA-xx3c-35rv-h773
The (1) udp_recvmsg and (2) udpv6_recvmsg functions in the Linux kernel before 4.0.6 do not properly consider yielding a processor, which allows remote attackers to cause a denial of service (system hang) via incorrect checksums within a UDP packet flood.
GHSA-xx38-qpxm-6j8x
IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 on Linux, Solaris, and HP-UX, when a Local OS registry is used, does not properly validate user accounts, which allows remote attackers to bypass intended access restrictions via unspecified vectors.
GHSA-xx38-8wp6-c2jw
Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, tvOS 13.3.1, Safari 13.0.5, iTunes for Windows 12.10.4, iCloud for Windows 11.0, iCloud for Windows 7.17. Processing maliciously crafted web content may lead to arbitrary code execution.
GHSA-xx38-25wr-hmh9
Subscriber Broken Access Control in Bookify <= 1.1.1 versions.
GHSA-xx36-85fv-r3w7
The dhcp.client program for QNX 4.25 vmware is setuid, possibly by default, which allows local users to modify the NIC configuration and conduct other attacks.
GHSA-xx36-6rv4-gj8r
ecdsa-elixir fails to check signatures, vulnerable to message forging
GHSA-xx34-wh4m-w39f
The AMaViS virus scanner 0.2.0-pre4 and earlier allows remote attackers to execute arbitrary commands as root via an infected mail message with shell metacharacters in the reply-to field.
GHSA-xx34-qq6x-qvv2
IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, and 10.4.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158880.
GHSA-xx34-6cjg-prh8
Duplicate Advisory: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully decrypted document content while a notebook is unlocked
GHSA-xx33-j3mf-gffc
TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function upgradeInfoRegister.
GHSA-xx33-84gg-2vw9
A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. Affected by this issue is some unknown functionality of the file /pages/us_del.php?type=user. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.
GHSA-xx33-83f8-v2gp
The mintToken function of a smart contract implementation for loncoin (LON), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xx3g-v5fx-v7w6 launchAnyWhere vulnerability in the ActivityManagerService module. Successful exploitation of this vulnerability will affect availability. | CVSS3: 7.5 | 0% Низкий | больше 2 лет назад | |
GHSA-xx3g-89q2-w8hh Cross-site scripting (XSS) vulnerability in the search functionality in Simon Brown Pebble 2.0.0 RC1 and RC2 allows remote attackers to inject arbitrary web script or HTML via the query string. | 1% Низкий | больше 4 лет назад | ||
GHSA-xx3f-8qwx-w9mh The (1) av-centerd SOAP service and (2) backup command in the ossim-framework service in AlienVault OSSIM before 4.6.0 allows remote attackers to execute arbitrary commands via unspecified vectors. | 4% Низкий | больше 4 лет назад | ||
GHSA-xx3f-44rh-4g76 Improper path validation in promecefpluginhost.exe in Kingsoft WPS Office version ranging from 12.2.0.13110 to 12.2.0.13489 on Windows allows an attacker to load an arbitrary Windows library. The patch released in version 12.2.0.16909 to mitigate CVE-2024-7262 was not restrictive enough. Another hyperlink parameter was not properly sanitized which leads to the execution of an arbitrary Windows library. | CVSS3: 7.8 | 0% Низкий | около 2 лет назад | |
GHSA-xx3f-437p-fp69 A vulnerability was found in D-Link DI-7400G+ 19.12.25A1. This affects an unknown function of the file /msp_info.htm?flag=cmd. The manipulation of the argument cmd results in command injection. The attack can be launched remotely. The exploit has been made public and could be used. | CVSS3: 6.3 | 5% Низкий | 9 месяцев назад | |
GHSA-xx3c-ww24-2pgq Template injection (Improper Neutralization of Special Elements Used in a Template Engine) vulnerability in a-blog cms Ver.2.8.x series versions prior to Ver.2.8.75, Ver.2.9.x series versions prior to Ver.2.9.40, Ver.2.10.x series versions prior to Ver.2.10.44, Ver.2.11.x series versions prior to Ver.2.11.42, and Ver.3.0.x series versions prior to Ver.3.0.1 allows a remote authenticated attacker to obtain an arbitrary file on the server via unspecified vectors. | 1% Низкий | больше 4 лет назад | ||
GHSA-xx3c-qf5g-hc39 Symfony has an Argument Injection in SendmailTransport via Dash-Prefixed Recipient Address | 1% Низкий | 4 месяца назад | ||
GHSA-xx3c-6h6w-w5rg JWT.php in F21 JWT before 2.0 allows remote attackers to bypass signature verification via crafted tokens. | 4% Низкий | больше 4 лет назад | ||
GHSA-xx3c-35rv-h773 The (1) udp_recvmsg and (2) udpv6_recvmsg functions in the Linux kernel before 4.0.6 do not properly consider yielding a processor, which allows remote attackers to cause a denial of service (system hang) via incorrect checksums within a UDP packet flood. | 6% Низкий | больше 4 лет назад | ||
GHSA-xx38-qpxm-6j8x IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.47, 7.0 before 7.0.0.29, 8.0 before 8.0.0.6, and 8.5 before 8.5.0.2 on Linux, Solaris, and HP-UX, when a Local OS registry is used, does not properly validate user accounts, which allows remote attackers to bypass intended access restrictions via unspecified vectors. | 3% Низкий | больше 4 лет назад | ||
GHSA-xx38-8wp6-c2jw Multiple memory corruption issues were addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, tvOS 13.3.1, Safari 13.0.5, iTunes for Windows 12.10.4, iCloud for Windows 11.0, iCloud for Windows 7.17. Processing maliciously crafted web content may lead to arbitrary code execution. | 2% Низкий | больше 4 лет назад | ||
GHSA-xx38-25wr-hmh9 Subscriber Broken Access Control in Bookify <= 1.1.1 versions. | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
GHSA-xx36-85fv-r3w7 The dhcp.client program for QNX 4.25 vmware is setuid, possibly by default, which allows local users to modify the NIC configuration and conduct other attacks. | 0% Низкий | больше 4 лет назад | ||
GHSA-xx36-6rv4-gj8r ecdsa-elixir fails to check signatures, vulnerable to message forging | CVSS3: 9.8 | 1% Низкий | больше 4 лет назад | |
GHSA-xx34-wh4m-w39f The AMaViS virus scanner 0.2.0-pre4 and earlier allows remote attackers to execute arbitrary commands as root via an infected mail message with shell metacharacters in the reply-to field. | 5% Низкий | больше 4 лет назад | ||
GHSA-xx34-qq6x-qvv2 IBM Cognos Controller 10.3.0, 10.3.1, 10.4.0, and 10.4.1 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 158880. | CVSS3: 7.5 | 1% Низкий | больше 4 лет назад | |
GHSA-xx34-6cjg-prh8 Duplicate Advisory: The publish-access gate treats encrypted notebooks as publicly accessible by default, allowing anonymous readers to retrieve fully decrypted document content while a notebook is unlocked | CVSS3: 8.6 | около 1 месяца назад | ||
GHSA-xx33-j3mf-gffc TP-LINK TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin was discovered to contain a stack overflow via the function upgradeInfoRegister. | CVSS3: 9.8 | 1% Низкий | почти 3 года назад | |
GHSA-xx33-84gg-2vw9 A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. Affected by this issue is some unknown functionality of the file /pages/us_del.php?type=user. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. | CVSS3: 6.3 | 0% Низкий | 12 дней назад | |
GHSA-xx33-83f8-v2gp The mintToken function of a smart contract implementation for loncoin (LON), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | CVSS3: 7.5 | 1% Низкий | больше 4 лет назад |
Уязвимостей на страницу