Количество 314 691
Количество 314 691
GHSA-43vh-22m9-hr9x
Multiple PHP remote file inclusion vulnerabilities in Wap Portal Server 1.x allow remote attackers to execute arbitrary PHP code via a URL in the language parameter to (1) index.php and (2) admin/index.php.
GHSA-43vf-866m-gxw3
Unspecified vulnerability in McAfee Email and Web Security Appliance 5.1 VMtrial allows remote attackers to read arbitrary files via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.9 through 8.11. NOTE: as of 20090917, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes.
GHSA-43vf-7f59-hwgm
UWA 2.3.11 allows index.php?g=admin&c=admin&a=add_admin_do CSRF.
GHSA-43vf-2x6g-p2m5
Malicious Package in browserift
GHSA-43vf-262m-2h43
Cross-site scripting (XSS) vulnerability in page.php in JShop allows remote attackers to inject arbitrary web script or HTML via the xPage parameter.
GHSA-43vc-pv65-hrhm
The isearch package (textproc/isearch) before 1.47.01nb1 uses the tempnam() function to create insecure temporary files into a publicly-writable area (/tmp).
GHSA-43v9-vxgc-g477
Rekonq 0.7.0 and earlier does not use a certain font when rendering certificate fields in a security dialog, which allows remote attackers to spoof the common name (CN) of a certificate via rich text.
GHSA-43v9-p898-p49x
An HTTP parameter pollution issue was discovered on Shenzhen Dragon Brothers Fingerprint Bluetooth Round Padlock FB50 2.3. With the user ID, user name, and the lock's MAC address, anyone can unbind the existing owner of the lock, and bind themselves instead. This leads to complete takeover of the lock. The user ID, name, and MAC address are trivially obtained from APIs found within the Android or iOS application. With only the MAC address of the lock, any attacker can transfer ownership of the lock from the current user, over to the attacker's account. Thus rendering the lock completely inaccessible to the current user.
GHSA-43v9-5jqv-2894
Unspecified vulnerability in the Flash Player ActiveX control in Adobe Flash Player 9.0.124.0 and earlier on Windows allows attackers to obtain sensitive information via unknown vectors.
GHSA-43v7-wxwq-5hp3
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.
GHSA-43v6-mq3r-qmhx
An authentication bypass vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to access key methods as an admin user and modify product configurations on affected installations.
GHSA-43v5-w42f-65jx
Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a certain createTextRange call on a checkbox object, which results in a dereference of an invalid table pointer.
GHSA-43v5-882w-9hpj
A vulnerability, which was classified as problematic, was found in PHPOK 6.4.100. This affects an unknown part of the file /admin.php?c=upload&f=zip&_noCache=0.1683794968. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The identifier VDB-229953 was assigned to this vulnerability.
GHSA-43v5-5g9q-m394
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows local users to bypass the ASLR protection mechanism via a crafted application, aka "GDI Information Disclosure Vulnerability."
GHSA-43v3-5j9f-4vh2
IBM Security SOAR 51.0.2.0 could allow an authenticated user to execute malicious code loaded from a specially crafted script. IBM X-Force ID: 294830.
GHSA-43v2-6grp-9pp9
Apache Tomcat does not enforce the maxHttpHeaderSize limit
GHSA-43rr-x62x-q96w
MineAdmin improperly refreshes tokens
GHSA-43rr-wcj9-h45w
Incorrect Authorization in PostgreSQL
GHSA-43rr-vh89-fj97
An issue was discovered in EasyLogin Pro through 1.3.0. Encryptor.php contains an unserialize call that can be exploited for remote code execution in the decrypt function, if the attacker knows the key.
GHSA-43rr-prv9-867f
ZyXEL ZyWALL 1050 has a hard-coded password for the Quagga and Zebra processes that is not changed when it is set by a user, which allows remote attackers to gain privileges.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-43vh-22m9-hr9x Multiple PHP remote file inclusion vulnerabilities in Wap Portal Server 1.x allow remote attackers to execute arbitrary PHP code via a URL in the language parameter to (1) index.php and (2) admin/index.php. | 1% Низкий | почти 4 года назад | ||
GHSA-43vf-866m-gxw3 Unspecified vulnerability in McAfee Email and Web Security Appliance 5.1 VMtrial allows remote attackers to read arbitrary files via unknown vectors, as demonstrated by a certain module in VulnDisco Pack Professional 8.9 through 8.11. NOTE: as of 20090917, this disclosure has no actionable information. However, because the VulnDisco Pack author is a reliable researcher, the issue is being assigned a CVE identifier for tracking purposes. | 0% Низкий | почти 4 года назад | ||
GHSA-43vf-7f59-hwgm UWA 2.3.11 allows index.php?g=admin&c=admin&a=add_admin_do CSRF. | CVSS3: 8.8 | 0% Низкий | больше 3 лет назад | |
GHSA-43vf-2x6g-p2m5 Malicious Package in browserift | CVSS3: 9.8 | больше 5 лет назад | ||
GHSA-43vf-262m-2h43 Cross-site scripting (XSS) vulnerability in page.php in JShop allows remote attackers to inject arbitrary web script or HTML via the xPage parameter. | 0% Низкий | почти 4 года назад | ||
GHSA-43vc-pv65-hrhm The isearch package (textproc/isearch) before 1.47.01nb1 uses the tempnam() function to create insecure temporary files into a publicly-writable area (/tmp). | CVSS3: 7.5 | 0% Низкий | почти 4 года назад | |
GHSA-43v9-vxgc-g477 Rekonq 0.7.0 and earlier does not use a certain font when rendering certificate fields in a security dialog, which allows remote attackers to spoof the common name (CN) of a certificate via rich text. | 0% Низкий | больше 3 лет назад | ||
GHSA-43v9-p898-p49x An HTTP parameter pollution issue was discovered on Shenzhen Dragon Brothers Fingerprint Bluetooth Round Padlock FB50 2.3. With the user ID, user name, and the lock's MAC address, anyone can unbind the existing owner of the lock, and bind themselves instead. This leads to complete takeover of the lock. The user ID, name, and MAC address are trivially obtained from APIs found within the Android or iOS application. With only the MAC address of the lock, any attacker can transfer ownership of the lock from the current user, over to the attacker's account. Thus rendering the lock completely inaccessible to the current user. | CVSS3: 9.8 | 4% Низкий | больше 3 лет назад | |
GHSA-43v9-5jqv-2894 Unspecified vulnerability in the Flash Player ActiveX control in Adobe Flash Player 9.0.124.0 and earlier on Windows allows attackers to obtain sensitive information via unknown vectors. | 6% Низкий | больше 3 лет назад | ||
GHSA-43v7-wxwq-5hp3 Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 4.x through 10.0, Firefox ESR 10.x before 10.0.3, Thunderbird 5.0 through 10.0, Thunderbird ESR 10.x before 10.0.3, and SeaMonkey before 2.8 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. | 2% Низкий | почти 4 года назад | ||
GHSA-43v6-mq3r-qmhx An authentication bypass vulnerability in the Trend Micro Endpoint Encryption PolicyServer could allow an attacker to access key methods as an admin user and modify product configurations on affected installations. | CVSS3: 9.8 | 0% Низкий | 8 месяцев назад | |
GHSA-43v5-w42f-65jx Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a certain createTextRange call on a checkbox object, which results in a dereference of an invalid table pointer. | 88% Высокий | почти 4 года назад | ||
GHSA-43v5-882w-9hpj A vulnerability, which was classified as problematic, was found in PHPOK 6.4.100. This affects an unknown part of the file /admin.php?c=upload&f=zip&_noCache=0.1683794968. The manipulation leads to unrestricted upload. It is possible to initiate the attack remotely. The identifier VDB-229953 was assigned to this vulnerability. | CVSS3: 4.7 | 0% Низкий | больше 2 лет назад | |
GHSA-43v5-5g9q-m394 The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allows local users to bypass the ASLR protection mechanism via a crafted application, aka "GDI Information Disclosure Vulnerability." | CVSS3: 3.3 | 6% Низкий | больше 3 лет назад | |
GHSA-43v3-5j9f-4vh2 IBM Security SOAR 51.0.2.0 could allow an authenticated user to execute malicious code loaded from a specially crafted script. IBM X-Force ID: 294830. | CVSS3: 7.5 | 0% Низкий | больше 1 года назад | |
GHSA-43v2-6grp-9pp9 Apache Tomcat does not enforce the maxHttpHeaderSize limit | CVSS3: 7.5 | 16% Средний | больше 3 лет назад | |
GHSA-43rr-x62x-q96w MineAdmin improperly refreshes tokens | CVSS3: 5 | 0% Низкий | 22 дня назад | |
GHSA-43rr-wcj9-h45w Incorrect Authorization in PostgreSQL | CVSS3: 4.3 | 0% Низкий | почти 4 года назад | |
GHSA-43rr-vh89-fj97 An issue was discovered in EasyLogin Pro through 1.3.0. Encryptor.php contains an unserialize call that can be exploited for remote code execution in the decrypt function, if the attacker knows the key. | CVSS3: 8.1 | 8% Низкий | больше 3 лет назад | |
GHSA-43rr-prv9-867f ZyXEL ZyWALL 1050 has a hard-coded password for the Quagga and Zebra processes that is not changed when it is set by a user, which allows remote attackers to gain privileges. | CVSS3: 9.8 | 16% Средний | почти 4 года назад |
Уязвимостей на страницу