Количество 314 458
Количество 314 458
GHSA-3w9v-5hv6-vvfx
Advantech iView versions 5.7.05.7057 and prior do not properly sanitize SNMP v1 trap (Port 162) requests, which could allow an attacker to inject SQL commands.
GHSA-3w9v-5f2g-97c5
XSS exists in the admin web console in Pulse Secure Pulse Connect Secure (PCS) 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, and 5.2RX before 5.2R12.1.
GHSA-3w9r-m576-jv7x
Cross-site scripting (XSS) vulnerability in openwebmail-read.pl in Open WebMail (OWM) 2.52, and other versions released before 06/18/2006, allows remote attackers to inject arbitrary web script or HTML via the from field. NOTE: some third party sources have mentioned the "to" and "from" fields, although CVE analysis shows that these are associated with the previous version, a different executable, and a different CVE.
GHSA-3w9r-7m69-42xv
A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.4907 and later
GHSA-3w9r-2mqj-cf5c
Integer Overflow vulnerability in qsvghandler.cpp in Qt qtsvg versions 5.15.1, 6.0.0, 6.0.2, and 6.2, allows local attackers to cause a denial of service (DoS).
GHSA-3w9q-v2w9-rrmm
A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to cause unexpected system termination.
GHSA-3w9q-c44j-37jj
High severity vulnerability that affects Microsoft.ChakraCore
GHSA-3w9p-x4pg-9hc2
H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function switch_debug_info_set.
GHSA-3w9p-v94j-2ggh
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0968, CVE-2019-0977, CVE-2019-1009, CVE-2019-1010, CVE-2019-1012, CVE-2019-1013, CVE-2019-1015, CVE-2019-1016, CVE-2019-1046, CVE-2019-1047, CVE-2019-1048, CVE-2019-1049, CVE-2019-1050.
GHSA-3w9p-phq7-3r7c
** DISPUTED ** An issue was discovered in SMA Solar Technology products. An attacker can use Sunny Explorer or the SMAdata2+ network protocol to update the device firmware without ever having to authenticate. If an attacker is able to create a custom firmware version that is accepted by the inverter, the inverter is compromised completely. This allows the attacker to do nearly anything: for example, giving access to the local OS, creating a botnet, using the inverters as a stepping stone into companies, etc. NOTE: the vendor reports that this attack has always been blocked by "a final integrity and compatibility check." Also, only Sunny Boy TLST-21 and TL-21 and Sunny Tripower TL-10 and TL-30 could potentially be affected.
GHSA-3w9p-mc8r-hc9p
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a memory leak in the function ReadMPCImage of coders/mpc.c, which allows attackers to cause a denial of service via a crafted image file.
GHSA-3w9m-vg42-8v9h
By using XSL Transforms, a malicious webserver could have served a user an XSL document that would continue to execute JavaScript (within the bounds of the same-origin policy) even after the tab was closed. This vulnerability affects Firefox < 97.
GHSA-3w9m-rh5f-x696
Internet Anywhere POP3 Mail Server allows local users to cause a denial of service via a malformed RETR command.
GHSA-3w9m-ph4c-w2xx
Trend Micro Home Network Security 6.5.599 and earlier is vulnerable to a file-parsing vulnerability which could allow an attacker to exploit the vulnerability and cause a denial-of-service to the device. This vulnerability is similar, but not identical to CVE-2021-31517.
GHSA-3w9m-7j3j-w9p6
Power BI Report Server Spoofing Vulnerability
GHSA-3w9j-cqm3-rw92
maccms10 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field.
GHSA-3w9h-5fv2-f86j
The kernel subsystem hmdfs within OpenHarmony-v3.1.5 and prior versions has an arbitrary memory accessing vulnerability which network attackers can launch a remote attack to obtain kernel memory data of the target system.
GHSA-3w9g-v5jv-vm58
Dell EMC Isilon OneFS version 8.2.2 and Dell EMC PowerScale OneFS version 9.0.0 contains a buffer overflow vulnerability in the Likewise component. A remote unauthenticated malicious attacker may potentially exploit this vulnerability to cause a process restart.
GHSA-3w9f-2pph-j5vc
com.xwiki.confluencepro:application-confluence-migrator-pro-ui's application homepage is public
GHSA-3w9c-vcrh-mvp2
Integer overflow in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a 0x7fffffff argument to the setSlice method on a WebViewFolderIcon ActiveX object, which leads to an invalid memory copy.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3w9v-5hv6-vvfx Advantech iView versions 5.7.05.7057 and prior do not properly sanitize SNMP v1 trap (Port 162) requests, which could allow an attacker to inject SQL commands. | CVSS3: 7.5 | 0% Низкий | 2 месяца назад | |
GHSA-3w9v-5f2g-97c5 XSS exists in the admin web console in Pulse Secure Pulse Connect Secure (PCS) 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, and 5.2RX before 5.2R12.1. | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-3w9r-m576-jv7x Cross-site scripting (XSS) vulnerability in openwebmail-read.pl in Open WebMail (OWM) 2.52, and other versions released before 06/18/2006, allows remote attackers to inject arbitrary web script or HTML via the from field. NOTE: some third party sources have mentioned the "to" and "from" fields, although CVE analysis shows that these are associated with the previous version, a different executable, and a different CVE. | 1% Низкий | почти 4 года назад | ||
GHSA-3w9r-7m69-42xv A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.4907 and later | CVSS3: 6.5 | 0% Низкий | 5 месяцев назад | |
GHSA-3w9r-2mqj-cf5c Integer Overflow vulnerability in qsvghandler.cpp in Qt qtsvg versions 5.15.1, 6.0.0, 6.0.2, and 6.2, allows local attackers to cause a denial of service (DoS). | CVSS3: 5.5 | 0% Низкий | больше 2 лет назад | |
GHSA-3w9q-v2w9-rrmm A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.6, macOS Sonoma 14.7.7, macOS Ventura 13.7.7. An app may be able to cause unexpected system termination. | CVSS3: 9.8 | 0% Низкий | 6 месяцев назад | |
GHSA-3w9q-c44j-37jj High severity vulnerability that affects Microsoft.ChakraCore | CVSS3: 7.5 | 4% Низкий | почти 7 лет назад | |
GHSA-3w9p-x4pg-9hc2 H3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function switch_debug_info_set. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-3w9p-v94j-2ggh An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0968, CVE-2019-0977, CVE-2019-1009, CVE-2019-1010, CVE-2019-1012, CVE-2019-1013, CVE-2019-1015, CVE-2019-1016, CVE-2019-1046, CVE-2019-1047, CVE-2019-1048, CVE-2019-1049, CVE-2019-1050. | CVSS3: 6.5 | 8% Низкий | больше 3 лет назад | |
GHSA-3w9p-phq7-3r7c ** DISPUTED ** An issue was discovered in SMA Solar Technology products. An attacker can use Sunny Explorer or the SMAdata2+ network protocol to update the device firmware without ever having to authenticate. If an attacker is able to create a custom firmware version that is accepted by the inverter, the inverter is compromised completely. This allows the attacker to do nearly anything: for example, giving access to the local OS, creating a botnet, using the inverters as a stepping stone into companies, etc. NOTE: the vendor reports that this attack has always been blocked by "a final integrity and compatibility check." Also, only Sunny Boy TLST-21 and TL-21 and Sunny Tripower TL-10 and TL-30 could potentially be affected. | CVSS3: 9.8 | 0% Низкий | больше 3 лет назад | |
GHSA-3w9p-mc8r-hc9p In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a memory leak in the function ReadMPCImage of coders/mpc.c, which allows attackers to cause a denial of service via a crafted image file. | CVSS3: 6.5 | 1% Низкий | больше 3 лет назад | |
GHSA-3w9m-vg42-8v9h By using XSL Transforms, a malicious webserver could have served a user an XSL document that would continue to execute JavaScript (within the bounds of the same-origin policy) even after the tab was closed. This vulnerability affects Firefox < 97. | CVSS3: 8.8 | 1% Низкий | около 3 лет назад | |
GHSA-3w9m-rh5f-x696 Internet Anywhere POP3 Mail Server allows local users to cause a denial of service via a malformed RETR command. | 0% Низкий | почти 4 года назад | ||
GHSA-3w9m-ph4c-w2xx Trend Micro Home Network Security 6.5.599 and earlier is vulnerable to a file-parsing vulnerability which could allow an attacker to exploit the vulnerability and cause a denial-of-service to the device. This vulnerability is similar, but not identical to CVE-2021-31517. | 1% Низкий | больше 3 лет назад | ||
GHSA-3w9m-7j3j-w9p6 Power BI Report Server Spoofing Vulnerability | CVSS3: 7.6 | 0% Низкий | больше 3 лет назад | |
GHSA-3w9j-cqm3-rw92 maccms10 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Server Group text field. | CVSS3: 5.4 | 0% Низкий | больше 3 лет назад | |
GHSA-3w9h-5fv2-f86j The kernel subsystem hmdfs within OpenHarmony-v3.1.5 and prior versions has an arbitrary memory accessing vulnerability which network attackers can launch a remote attack to obtain kernel memory data of the target system. | CVSS3: 7.5 | 0% Низкий | почти 3 года назад | |
GHSA-3w9g-v5jv-vm58 Dell EMC Isilon OneFS version 8.2.2 and Dell EMC PowerScale OneFS version 9.0.0 contains a buffer overflow vulnerability in the Likewise component. A remote unauthenticated malicious attacker may potentially exploit this vulnerability to cause a process restart. | 0% Низкий | больше 3 лет назад | ||
GHSA-3w9f-2pph-j5vc com.xwiki.confluencepro:application-confluence-migrator-pro-ui's application homepage is public | CVSS3: 7.5 | 0% Низкий | 11 месяцев назад | |
GHSA-3w9c-vcrh-mvp2 Integer overflow in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a 0x7fffffff argument to the setSlice method on a WebViewFolderIcon ActiveX object, which leads to an invalid memory copy. | 87% Высокий | почти 4 года назад |
Уязвимостей на страницу