Количество 323 571
Количество 323 571
GHSA-xvx6-286h-35qm
Due to missing authorization check, an unauthorized user can view the files of other company. This might lead to disclosure of personal data of employees. There is no impact on integrity and availability.
GHSA-xvx5-4wp8-4f6g
WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4759, CVE-2016-4765, CVE-2016-4766, and CVE-2016-4768.
GHSA-xvx4-v362-295f
An improper certificate validation vulnerability in Palo Alto Networks PAN-OS software enables an authorized user with a specially crafted client certificate to connect to an impacted GlobalProtect portal or GlobalProtect gateway as a different legitimate user. This attack is possible only if you "Allow Authentication with User Credentials OR Client Certificate."
GHSA-xvx4-fr25-r858
QEMU 4.2.0 has a use-after-free in hw/net/e1000e_core.c because a guest OS user can trigger an e1000e packet with the data's address set to the e1000e's MMIO address.
GHSA-xvx3-whgp-7rq7
The mdjvu_bitmap_pack_row function in base/4bitmap.c in minidjvu 0.8 can cause a denial of service (invalid memory read and application crash) via a crafted djvu file.
GHSA-xvx3-23h3-m25g
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.51, 8.52, and 8.53 allows remote attackers to affect availability via vectors related to XML Publisher.
GHSA-xvx2-wqf5-jjgv
typo3/cms-felogin Cross-site Scripting vulnerability
GHSA-xvx2-w5pj-9472
When following a link that opened an intent://-schemed URL, causing a custom tab to be opened, Firefox for Android could be tricked into displaying the incorrect URI. <br> *Note: This issue only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.7.
GHSA-xvx2-r4w7-hx6q
Improper input validation in the Intel(R) SGX Platform Software for Windows* may allow an authenticated user to potentially enable a denial of service via local access.
GHSA-xvx2-mpv8-r9xf
An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is stack buffer overflow in mjs_execute() in mjs.c.
GHSA-xvx2-hw78-h573
Citrix ADC and Citrix/NetScaler Gateway 13.0 before 13.0-76.29, 12.1-61.18, 11.1-65.20, Citrix ADC 12.1-FIPS before 12.1-55.238, and Citrix SD-WAN WANOP Edition before 11.4.0, 11.3.2, 11.3.1a, 11.2.3a, 11.1.2c, 10.2.9a suffers from uncontrolled resource consumption by way of a network-based denial-of-service from within the same Layer 2 network segment. Note that the attacker must be in the same Layer 2 network segment as the vulnerable appliance.
GHSA-xvwx-g9pc-953x
time server daemon timed allows remote attackers to cause a denial of service via malformed packets.
GHSA-xvww-cpj4-267x
Dojo Toolkit, as used in the Web client in IBM Rational ClearQuest 7.1.1.x before 7.1.1.4 and 7.1.2.x before 7.1.2.1, allows remote attackers to read cookies by navigating to a Dojo file, related to an "open direct" issue.
GHSA-xvww-87m7-74xx
The version V2.5.0_EG1T5_TED of ZTE ZXHN H108N product are impacted by an information leak vulnerability. An attacker could exploit the vulnerability to obtain sensitive information and perform unauthorized operations.
GHSA-xvwv-6wvx-px9x
Plone Open Redirect
GHSA-xvwr-jcvg-47ph
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Basix NEX-Forms – Ultimate Form Builder allows SQL Injection.This issue affects NEX-Forms – Ultimate Form Builder: from n/a through 8.7.8.
GHSA-xvwq-6652-7rm2
Cross-site scripting (XSS) vulnerability in GMOD GBrowse before 1.69 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
GHSA-xvwp-q2w5-88cf
A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.4.2596 build 20231128 and later QuTS hero h5.1.4.2596 build 20231128 and later
GHSA-xvwp-h6jv-7472
FractionalMaxPool and FractionalAVGPool heap out-of-bounds acess
GHSA-xvwm-fhx3-vrj9
Use-after-free vulnerability in the HTMLCollection implementation in Google Chrome before 10.0.648.204 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xvx6-286h-35qm Due to missing authorization check, an unauthorized user can view the files of other company. This might lead to disclosure of personal data of employees. There is no impact on integrity and availability. | CVSS3: 5.8 | 0% Низкий | 11 месяцев назад | |
GHSA-xvx5-4wp8-4f6g WebKit in Apple iOS before 10, tvOS before 10, iTunes before 12.5.1 on Windows, and Safari before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4759, CVE-2016-4765, CVE-2016-4766, and CVE-2016-4768. | CVSS3: 8.8 | 1% Низкий | почти 4 года назад | |
GHSA-xvx4-v362-295f An improper certificate validation vulnerability in Palo Alto Networks PAN-OS software enables an authorized user with a specially crafted client certificate to connect to an impacted GlobalProtect portal or GlobalProtect gateway as a different legitimate user. This attack is possible only if you "Allow Authentication with User Credentials OR Client Certificate." | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
GHSA-xvx4-fr25-r858 QEMU 4.2.0 has a use-after-free in hw/net/e1000e_core.c because a guest OS user can trigger an e1000e packet with the data's address set to the e1000e's MMIO address. | CVSS3: 3.3 | 0% Низкий | почти 4 года назад | |
GHSA-xvx3-whgp-7rq7 The mdjvu_bitmap_pack_row function in base/4bitmap.c in minidjvu 0.8 can cause a denial of service (invalid memory read and application crash) via a crafted djvu file. | CVSS3: 6.5 | 0% Низкий | почти 4 года назад | |
GHSA-xvx3-23h3-m25g Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.51, 8.52, and 8.53 allows remote attackers to affect availability via vectors related to XML Publisher. | 1% Низкий | почти 4 года назад | ||
GHSA-xvx2-wqf5-jjgv typo3/cms-felogin Cross-site Scripting vulnerability | 0% Низкий | почти 4 года назад | ||
GHSA-xvx2-w5pj-9472 When following a link that opened an intent://-schemed URL, causing a custom tab to be opened, Firefox for Android could be tricked into displaying the incorrect URI. <br> *Note: This issue only affects Firefox for Android. Other operating systems are unaffected.*. This vulnerability affects Firefox ESR < 68.7. | 0% Низкий | почти 4 года назад | ||
GHSA-xvx2-r4w7-hx6q Improper input validation in the Intel(R) SGX Platform Software for Windows* may allow an authenticated user to potentially enable a denial of service via local access. | 0% Низкий | почти 4 года назад | ||
GHSA-xvx2-mpv8-r9xf An issue was discovered in mjs (mJS: Restricted JavaScript engine), ES6 (JavaScript version 6). There is stack buffer overflow in mjs_execute() in mjs.c. | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
GHSA-xvx2-hw78-h573 Citrix ADC and Citrix/NetScaler Gateway 13.0 before 13.0-76.29, 12.1-61.18, 11.1-65.20, Citrix ADC 12.1-FIPS before 12.1-55.238, and Citrix SD-WAN WANOP Edition before 11.4.0, 11.3.2, 11.3.1a, 11.2.3a, 11.1.2c, 10.2.9a suffers from uncontrolled resource consumption by way of a network-based denial-of-service from within the same Layer 2 network segment. Note that the attacker must be in the same Layer 2 network segment as the vulnerable appliance. | 0% Низкий | почти 4 года назад | ||
GHSA-xvwx-g9pc-953x time server daemon timed allows remote attackers to cause a denial of service via malformed packets. | 1% Низкий | почти 4 года назад | ||
GHSA-xvww-cpj4-267x Dojo Toolkit, as used in the Web client in IBM Rational ClearQuest 7.1.1.x before 7.1.1.4 and 7.1.2.x before 7.1.2.1, allows remote attackers to read cookies by navigating to a Dojo file, related to an "open direct" issue. | 0% Низкий | почти 4 года назад | ||
GHSA-xvww-87m7-74xx The version V2.5.0_EG1T5_TED of ZTE ZXHN H108N product are impacted by an information leak vulnerability. An attacker could exploit the vulnerability to obtain sensitive information and perform unauthorized operations. | CVSS3: 6.5 | 0% Низкий | почти 4 года назад | |
GHSA-xvwv-6wvx-px9x Plone Open Redirect | CVSS3: 6.1 | 0% Низкий | около 7 лет назад | |
GHSA-xvwr-jcvg-47ph Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Basix NEX-Forms – Ultimate Form Builder allows SQL Injection.This issue affects NEX-Forms – Ultimate Form Builder: from n/a through 8.7.8. | CVSS3: 8.5 | 0% Низкий | больше 1 года назад | |
GHSA-xvwq-6652-7rm2 Cross-site scripting (XSS) vulnerability in GMOD GBrowse before 1.69 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 0% Низкий | почти 4 года назад | ||
GHSA-xvwp-q2w5-88cf A buffer copy without checking size of input vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow authenticated administrators to execute code via a network. We have already fixed the vulnerability in the following versions: QTS 5.1.4.2596 build 20231128 and later QuTS hero h5.1.4.2596 build 20231128 and later | CVSS3: 3.8 | 0% Низкий | около 2 лет назад | |
GHSA-xvwp-h6jv-7472 FractionalMaxPool and FractionalAVGPool heap out-of-bounds acess | CVSS3: 7.1 | 1% Низкий | больше 3 лет назад | |
GHSA-xvwm-fhx3-vrj9 Use-after-free vulnerability in the HTMLCollection implementation in Google Chrome before 10.0.648.204 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors. | 1% Низкий | почти 4 года назад |
Уязвимостей на страницу