Количество 323 805
Количество 323 805
GHSA-xvq8-m37c-gmmv
A security flaw has been discovered in Edimax BR-6208AC 1.02/1.03. Affected by this vulnerability is the function formRoute of the file /gogorm/formRoute of the component Web-based Configuration Interface. The manipulation of the argument strIp/strMask/strGateway results in command injection. The attack can be executed remotely. The exploit has been released to the public and may be exploited. Edimax confirms this issue: "The product mentioned, EDIMAX BR-6208AC V2, has reached its End of Life (EOL) status. It is no longer supported or maintained by Edimax, and it is no longer available for purchase in the market. Consequently, there will be no further firmware updates or patches for this device. We recommend users upgrade to newer models for better security." This vulnerability only affects products that are no longer supported by the maintainer.
GHSA-xvq8-f2vm-qf3p
Rejected reason: Not used
GHSA-xvq8-82jr-qr82
The newstatpress plugin before 1.0.4 for WordPress has XSS related to the Referer header.
GHSA-xvq8-2qwv-cr72
CubeCart 2.0.6 allows remote attackers to obtain sensitive information via an invalid (1) language parameter to index.php, (2) PHPSESSID parameter to index.php, (3) product parameter to tellafriend.php, (4) add parameter to view_cart.php, or (5) product parameter to view_product.php, which reveals the path in a PHP error message.
GHSA-xvq7-6cjq-gwh7
There is a possible out of bounds read due to an incorrect bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-152647751
GHSA-xvq6-mh4q-2wm8
Multiple buffer overflows in realtime operating system (RTOS) 6.1.0 allows local users to execute arbitrary code via (1) a long ABLANG environment variable in phlocale or (2) a long -u option to pkg-installer.
GHSA-xvq6-h898-wcj8
Mattermost denial of service vulnerability
GHSA-xvq5-pp86-qj79
Samsung SM-G920F build G920FXXU2COH2 (Galaxy S6), SM-N9005 build N9005XXUGBOK6 (Galaxy Note 3), GT-I9192 build I9192XXUBNB1 (Galaxy S4 mini), GT-I9195 build I9195XXUCOL1 (Galaxy S4 mini LTE), and GT-I9505 build I9505XXUHOJ2 (Galaxy S4) devices have unintended availability of the modem in USB configuration number 2 within the secure lockscreen state, allowing an attacker to make phone calls, send text messages, or issue commands, aka SVE-2016-5301.
GHSA-xvq4-9j7v-qqhv
Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.
GHSA-xvq3-j3j3-hfjp
SQL injection vulnerability in login.php in Keld PHP-MySQL News Script 0.7.1 allows remote attackers to execute arbitrary SQL commands via the username parameter.
GHSA-xvpx-6hh8-7h72
Magento XML Injection vulnerability in the 'City' field
GHSA-xvpw-pp3c-gx2x
RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of RealDefense SUPERAntiSpyware. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the SAS Core Service. The issue results from an exposed dangerous function. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-27677.
GHSA-xvpw-j9f9-fw7v
Internet Explorer 3 records a history of all URL's that are visited by a user in DAT files located in the Temporary Internet Files and History folders, which are not cleared when the user selects the "Clear History" option, and are not visible when the user browses the folders because of tailored displays.
GHSA-xvpr-22g7-3fc2
The Debian apache2ctl script in the apache2 package squeeze before 2.2.16-6+squeeze11, wheezy before 2.2.22-13, and sid before 2.2.22-13 for the Apache HTTP Server on Debian GNU/Linux does not properly create the /var/lock/apache2 lock directory, which allows local users to gain privileges via an unspecified symlink attack.
GHSA-xvpq-v2cq-9v92
Buffer overflow vulnerability in Core FTP Server v2 Build 697, via a crafted username.
GHSA-xvpp-m96v-c2pr
D-Link DIR-655 C devices before 3.02B05 BETA03 allow remote attackers to execute arbitrary commands via shell metacharacters in the online_firmware_check.cgi check_fw_url parameter.
GHSA-xvpp-hhff-gp7v
In WAGO Unmanaged Switch (852-111/000-001) in firmware version 01 an undocumented configuration interface without authorization allows an remote attacker to read system information and configure a limited set of parameters.
GHSA-xvpp-959v-c63p
Unspecified vulnerability in NWFS.SYS in Novell Client for Windows 4.91 SP4 has unknown impact and attack vectors, possibly related to IOCTL requests that overwrite arbitrary memory.
GHSA-xvpp-5hc3-fp4m
Improper Access Control vulnerability in AcyMailing Enterprise component for Joomla. It allows the unauthorized removal of attachments from campaigns.
GHSA-xvpm-v9x9-vg99
Cross-site scripting (XSS) vulnerability in webglimpse.cgi in Webglimpse 2.14.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the ID parameter.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xvq8-m37c-gmmv A security flaw has been discovered in Edimax BR-6208AC 1.02/1.03. Affected by this vulnerability is the function formRoute of the file /gogorm/formRoute of the component Web-based Configuration Interface. The manipulation of the argument strIp/strMask/strGateway results in command injection. The attack can be executed remotely. The exploit has been released to the public and may be exploited. Edimax confirms this issue: "The product mentioned, EDIMAX BR-6208AC V2, has reached its End of Life (EOL) status. It is no longer supported or maintained by Edimax, and it is no longer available for purchase in the market. Consequently, there will be no further firmware updates or patches for this device. We recommend users upgrade to newer models for better security." This vulnerability only affects products that are no longer supported by the maintainer. | CVSS3: 7.3 | 0% Низкий | 3 месяца назад | |
GHSA-xvq8-f2vm-qf3p Rejected reason: Not used | 8 месяцев назад | |||
GHSA-xvq8-82jr-qr82 The newstatpress plugin before 1.0.4 for WordPress has XSS related to the Referer header. | CVSS3: 6.1 | 0% Низкий | почти 4 года назад | |
GHSA-xvq8-2qwv-cr72 CubeCart 2.0.6 allows remote attackers to obtain sensitive information via an invalid (1) language parameter to index.php, (2) PHPSESSID parameter to index.php, (3) product parameter to tellafriend.php, (4) add parameter to view_cart.php, or (5) product parameter to view_product.php, which reveals the path in a PHP error message. | 4% Низкий | почти 4 года назад | ||
GHSA-xvq7-6cjq-gwh7 There is a possible out of bounds read due to an incorrect bounds check.Product: AndroidVersions: Android SoCAndroid ID: A-152647751 | 0% Низкий | почти 4 года назад | ||
GHSA-xvq6-mh4q-2wm8 Multiple buffer overflows in realtime operating system (RTOS) 6.1.0 allows local users to execute arbitrary code via (1) a long ABLANG environment variable in phlocale or (2) a long -u option to pkg-installer. | 0% Низкий | почти 4 года назад | ||
GHSA-xvq6-h898-wcj8 Mattermost denial of service vulnerability | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад | |
GHSA-xvq5-pp86-qj79 Samsung SM-G920F build G920FXXU2COH2 (Galaxy S6), SM-N9005 build N9005XXUGBOK6 (Galaxy Note 3), GT-I9192 build I9192XXUBNB1 (Galaxy S4 mini), GT-I9195 build I9195XXUCOL1 (Galaxy S4 mini LTE), and GT-I9505 build I9505XXUHOJ2 (Galaxy S4) devices have unintended availability of the modem in USB configuration number 2 within the secure lockscreen state, allowing an attacker to make phone calls, send text messages, or issue commands, aka SVE-2016-5301. | CVSS3: 6.8 | 0% Низкий | почти 4 года назад | |
GHSA-xvq4-9j7v-qqhv Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure. | 3 месяца назад | |||
GHSA-xvq3-j3j3-hfjp SQL injection vulnerability in login.php in Keld PHP-MySQL News Script 0.7.1 allows remote attackers to execute arbitrary SQL commands via the username parameter. | 0% Низкий | почти 4 года назад | ||
GHSA-xvpx-6hh8-7h72 Magento XML Injection vulnerability in the 'City' field | 31% Средний | почти 4 года назад | ||
GHSA-xvpw-pp3c-gx2x RealDefense SUPERAntiSpyware Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of RealDefense SUPERAntiSpyware. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the SAS Core Service. The issue results from an exposed dangerous function. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-27677. | CVSS3: 7.8 | 0% Низкий | 3 месяца назад | |
GHSA-xvpw-j9f9-fw7v Internet Explorer 3 records a history of all URL's that are visited by a user in DAT files located in the Temporary Internet Files and History folders, which are not cleared when the user selects the "Clear History" option, and are not visible when the user browses the folders because of tailored displays. | 1% Низкий | почти 4 года назад | ||
GHSA-xvpr-22g7-3fc2 The Debian apache2ctl script in the apache2 package squeeze before 2.2.16-6+squeeze11, wheezy before 2.2.22-13, and sid before 2.2.22-13 for the Apache HTTP Server on Debian GNU/Linux does not properly create the /var/lock/apache2 lock directory, which allows local users to gain privileges via an unspecified symlink attack. | 0% Низкий | почти 4 года назад | ||
GHSA-xvpq-v2cq-9v92 Buffer overflow vulnerability in Core FTP Server v2 Build 697, via a crafted username. | 0% Низкий | почти 4 года назад | ||
GHSA-xvpp-m96v-c2pr D-Link DIR-655 C devices before 3.02B05 BETA03 allow remote attackers to execute arbitrary commands via shell metacharacters in the online_firmware_check.cgi check_fw_url parameter. | 22% Средний | почти 4 года назад | ||
GHSA-xvpp-hhff-gp7v In WAGO Unmanaged Switch (852-111/000-001) in firmware version 01 an undocumented configuration interface without authorization allows an remote attacker to read system information and configure a limited set of parameters. | CVSS3: 9.1 | 1% Низкий | около 3 лет назад | |
GHSA-xvpp-959v-c63p Unspecified vulnerability in NWFS.SYS in Novell Client for Windows 4.91 SP4 has unknown impact and attack vectors, possibly related to IOCTL requests that overwrite arbitrary memory. | 18% Средний | почти 4 года назад | ||
GHSA-xvpp-5hc3-fp4m Improper Access Control vulnerability in AcyMailing Enterprise component for Joomla. It allows the unauthorized removal of attachments from campaigns. | CVSS3: 4.3 | 0% Низкий | больше 2 лет назад | |
GHSA-xvpm-v9x9-vg99 Cross-site scripting (XSS) vulnerability in webglimpse.cgi in Webglimpse 2.14.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the ID parameter. | 3% Низкий | почти 4 года назад |
Уязвимостей на страницу