Количество 313 854
Количество 313 854
GHSA-xxq8-5mc3-63xg
IBM CICS TX 11.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. X-Force ID: 229449.
GHSA-xxq8-555q-w627
Unspecified "absolute path vulnerability" in umountall in IBM AIX 5.1 through 5.3 allows local users to cause unknown impact via unknown vectors.
GHSA-xxq7-hjr2-f27f
Verizon 4G LTE Network Extender GA4.38 - V0.4.038.2131 utilizes a weak default admin password generation algorithm which generates passwords that are accessible to unauthenticated attackers via the webUI login page.
GHSA-xxq5-xj37-9fx7
It was discovered that the fix for CVE-2017-12163 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6.
GHSA-xxq5-c27j-953j
Microsoft Outlook for Mac Spoofing Vulnerability
GHSA-xxq4-jv5p-cfwc
In JetBrains TeamCity before 2020.2.1, the server admin could create and see access tokens for any other users.
GHSA-xxq4-9c68-6533
Windows Authentication Information Disclosure Vulnerability
GHSA-xxq4-3742-3h28
Generation of Error Message Containing Sensitive Information in microweber
GHSA-xxq3-gj76-wh9v
PHP remote file inclusion vulnerability in core/videodb.class.xml.php in the VideoDB component for Mambo 0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
GHSA-xxq3-764r-q6rm
AdPlug 2.3.1 has a heap-based buffer overflow in CmkjPlayer::load() in mkj.cpp.
GHSA-xxq2-fm9w-xjv8
The Relevanssi WordPress plugin before 4.26.0, Relevanssi Premium WordPress plugin before 2.29.0 do not sanitize and escape a parameter before using it in a SQL statement, allowing contributor and above roles to perform SQL injection attacks
GHSA-xxq2-74hw-vg6m
Jenkins WSO2 Oauth Plugin Session Fixation vulnerability
GHSA-xxq2-62cv-vmcw
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in psicosi448 wp2syslog plugin <= 1.0.5 versions.
GHSA-xxpx-w698-q23j
When a user opens manipulated JPEG 2000 (.jp2, jp2k.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application. The file format details along with their CVE relevant information can be found below
GHSA-xxpx-f58m-683f
Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Insufficient Resource Pool vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.
GHSA-xxpv-mm3c-74x5
Cross-site request forgery (CSRF) vulnerability in Bugzilla 2.17 to 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote attackers to delete unused flag types via a link or IMG tag to editflagtypes.cgi.
GHSA-xxpv-gwrv-58xv
Aten PE8108 2.4.232 is vulnerable to denial of service (DOS).
GHSA-xxpv-3q6j-c873
The Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘parent_url’ parameter in all versions up to, and including, 1.12.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
GHSA-xxpr-8m4r-4fgq
Microsoft PowerPoint for Mac 2011 allows a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-0254 and CVE-2017-0265.
GHSA-xxpq-jv5h-r9hg
Cross-site scripting (XSS) vulnerability in C.P.Sub 5.2 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter to index.php.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xxq8-5mc3-63xg IBM CICS TX 11.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. X-Force ID: 229449. | CVSS3: 3.1 | 0% Низкий | около 3 лет назад | |
GHSA-xxq8-555q-w627 Unspecified "absolute path vulnerability" in umountall in IBM AIX 5.1 through 5.3 allows local users to cause unknown impact via unknown vectors. | 0% Низкий | почти 4 года назад | ||
GHSA-xxq7-hjr2-f27f Verizon 4G LTE Network Extender GA4.38 - V0.4.038.2131 utilizes a weak default admin password generation algorithm which generates passwords that are accessible to unauthenticated attackers via the webUI login page. | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | |
GHSA-xxq5-xj37-9fx7 It was discovered that the fix for CVE-2017-12163 was not properly shipped in erratum RHSA-2017:2858 for Red Hat Gluster Storage 3.3 for RHEL 6. | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | |
GHSA-xxq5-c27j-953j Microsoft Outlook for Mac Spoofing Vulnerability | CVSS3: 5.3 | 1% Низкий | около 2 лет назад | |
GHSA-xxq4-jv5p-cfwc In JetBrains TeamCity before 2020.2.1, the server admin could create and see access tokens for any other users. | CVSS3: 3.8 | 0% Низкий | больше 3 лет назад | |
GHSA-xxq4-9c68-6533 Windows Authentication Information Disclosure Vulnerability | CVSS3: 5.5 | 0% Низкий | больше 1 года назад | |
GHSA-xxq4-3742-3h28 Generation of Error Message Containing Sensitive Information in microweber | CVSS3: 6.5 | 0% Низкий | почти 4 года назад | |
GHSA-xxq3-gj76-wh9v PHP remote file inclusion vulnerability in core/videodb.class.xml.php in the VideoDB component for Mambo 0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | 9% Низкий | почти 4 года назад | ||
GHSA-xxq3-764r-q6rm AdPlug 2.3.1 has a heap-based buffer overflow in CmkjPlayer::load() in mkj.cpp. | 1% Низкий | больше 3 лет назад | ||
GHSA-xxq2-fm9w-xjv8 The Relevanssi WordPress plugin before 4.26.0, Relevanssi Premium WordPress plugin before 2.29.0 do not sanitize and escape a parameter before using it in a SQL statement, allowing contributor and above roles to perform SQL injection attacks | CVSS3: 4.9 | 0% Низкий | 28 дней назад | |
GHSA-xxq2-74hw-vg6m Jenkins WSO2 Oauth Plugin Session Fixation vulnerability | CVSS3: 8.8 | 0% Низкий | больше 2 лет назад | |
GHSA-xxq2-62cv-vmcw Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in psicosi448 wp2syslog plugin <= 1.0.5 versions. | CVSS3: 5.9 | 0% Низкий | больше 2 лет назад | |
GHSA-xxpx-w698-q23j When a user opens manipulated JPEG 2000 (.jp2, jp2k.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application. The file format details along with their CVE relevant information can be found below | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
GHSA-xxpx-f58m-683f Dell Wyse Management Suite, versions prior to WMS 5.1, contains an Insufficient Resource Pool vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Denial of service. | CVSS3: 5.3 | 0% Низкий | 10 месяцев назад | |
GHSA-xxpv-mm3c-74x5 Cross-site request forgery (CSRF) vulnerability in Bugzilla 2.17 to 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote attackers to delete unused flag types via a link or IMG tag to editflagtypes.cgi. | 0% Низкий | почти 4 года назад | ||
GHSA-xxpv-gwrv-58xv Aten PE8108 2.4.232 is vulnerable to denial of service (DOS). | CVSS3: 5.3 | 0% Низкий | почти 3 года назад | |
GHSA-xxpv-3q6j-c873 The Giveaways and Contests by RafflePress – Get More Website Traffic, Email Subscribers, and Social Followers plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘parent_url’ parameter in all versions up to, and including, 1.12.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. | CVSS3: 7.2 | 3% Низкий | почти 2 года назад | |
GHSA-xxpr-8m4r-4fgq Microsoft PowerPoint for Mac 2011 allows a remote code execution vulnerability when the software fails to properly handle objects in memory, aka "Microsoft Office Memory Corruption Vulnerability". This CVE ID is unique from CVE-2017-0254 and CVE-2017-0265. | CVSS3: 7.8 | 29% Средний | больше 3 лет назад | |
GHSA-xxpq-jv5h-r9hg Cross-site scripting (XSS) vulnerability in C.P.Sub 5.2 allows remote attackers to inject arbitrary web script or HTML via the keyword parameter to index.php. | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу