Количество 289 529
Количество 289 529
GHSA-28r9-pq4c-wp3c
personnummer/rust vulnerable to Improper Input Validation
GHSA-28r9-hhcv-7c73
Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X 10.5 before 10.5.8 makes it easier for user-assisted remote attackers to execute arbitrary JavaScript via a web page that offers a download with a Content-Type value that is not on the list of possibly unsafe content types for Safari.
GHSA-28r9-967h-xvcv
Open Information Security Foundation Suricata prior to version 4.1.2 is affected by: Denial of Service - DNS detection bypass. The impact is: An attacker can evade a signature detection with a specialy formed network packet. The component is: app-layer-detect-proto.c, decode.c, decode-teredo.c and decode-ipv6.c (https://github.com/OISF/suricata/pull/3590/commits/11f3659f64a4e42e90cb3c09fcef66894205aefe, https://github.com/OISF/suricata/pull/3590/commits/8357ef3f8ffc7d99ef6571350724160de356158b). The attack vector is: An attacker can trigger the vulnerability by sending a specifically crafted network request. The fixed version is: 4.1.2.
GHSA-28r9-5f3v-j8fw
When a user opens manipulated Portable Document Format (.pdf, PDFView.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.
GHSA-28r9-4273-pm3w
An insecure transport protocol used by Drobo Dashboard API on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to intercept network traffic.
GHSA-28r8-9g34-2x25
A vulnerability in the web UI of Cisco Umbrella could allow an unauthenticated, remote attacker to negatively affect the performance of this service. The vulnerability exists due to insufficient rate limiting controls in the web UI. An attacker could exploit this vulnerability by sending crafted HTTPS packets at a high and sustained rate. A successful exploit could allow the attacker to negatively affect the performance of the web UI. Cisco has addressed this vulnerability.
GHSA-28r8-6q2m-x9g4
The XD Forum (aka com.tapatalk.xdforumcomforum) application 3.9.17 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
GHSA-28r6-jm5h-mrgg
Access control bypass in Beego
GHSA-28r4-58h5-m5rr
In JetBrains YouTrack before 2021.3.21051, a user could see boards without having corresponding permissions.
GHSA-28r2-q6m8-9hpx
HashiCorp go-getter unsafe downloads could lead to asymmetric resource exhaustion
GHSA-28qw-8jmg-32wx
Transient DOS when processing a NULL buffer while parsing WLAN vdev.
GHSA-28qr-hqrv-mhvr
libdwarf 2016-10-21 allows context-dependent attackers to obtain sensitive information or cause a denial of service by using the "malformed dwarf file" approach, related to a "Heap Buffer Over-read" issue affecting the dwarf_util.c component, aka DW201611-006.
GHSA-28qq-773c-49rf
SQL injection vulnerability in view_reviews.php in Prozilla Cheat Script (aka Cheats) 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
GHSA-28qp-wgp5-fp7m
Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4-pl4 allow remote attackers to inject arbitrary web script or HTML via (1) the cookie-based login panel, (2) the title parameter and (3) the table creation dialog.
GHSA-28qp-rcr7-xp4g
IBM TXSeries for Multiplatforms 9.1 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
GHSA-28qp-98vv-5xqx
The OTR plugin for Gajim sends information in cleartext when using XHTML, which allows remote attackers to obtain sensitive information via unspecified vectors.
GHSA-28qp-8c7m-wc33
Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity (XXE) declaration and reference in an RDF document.
GHSA-28qm-wmpf-4vwh
The extract function in PHP before 5.2.15 does not prevent use of the EXTR_OVERWRITE parameter to overwrite (1) the GLOBALS superglobal array and (2) the this variable, which allows context-dependent attackers to bypass intended access restrictions by modifying data structures that were not intended to depend on external input, a related issue to CVE-2005-2691 and CVE-2006-3758.
GHSA-28qm-6v7q-2wqv
Unspecified vulnerability in Oracle MySQL 5.6.30 and earlier and 5.7.12 and earlier allows remote authenticated users to affect availability via vectors related to Server: FTS.
GHSA-28qj-gvxv-p5g9
Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
GHSA-28r9-pq4c-wp3c personnummer/rust vulnerable to Improper Input Validation | почти 3 года назад | |||
GHSA-28r9-hhcv-7c73 Incomplete blacklist vulnerability in CoreTypes in Apple Mac OS X 10.5 before 10.5.8 makes it easier for user-assisted remote attackers to execute arbitrary JavaScript via a web page that offers a download with a Content-Type value that is not on the list of possibly unsafe content types for Safari. | 1% Низкий | больше 3 лет назад | ||
GHSA-28r9-967h-xvcv Open Information Security Foundation Suricata prior to version 4.1.2 is affected by: Denial of Service - DNS detection bypass. The impact is: An attacker can evade a signature detection with a specialy formed network packet. The component is: app-layer-detect-proto.c, decode.c, decode-teredo.c and decode-ipv6.c (https://github.com/OISF/suricata/pull/3590/commits/11f3659f64a4e42e90cb3c09fcef66894205aefe, https://github.com/OISF/suricata/pull/3590/commits/8357ef3f8ffc7d99ef6571350724160de356158b). The attack vector is: An attacker can trigger the vulnerability by sending a specifically crafted network request. The fixed version is: 4.1.2. | CVSS3: 7.5 | 0% Низкий | около 3 лет назад | |
GHSA-28r9-5f3v-j8fw When a user opens manipulated Portable Document Format (.pdf, PDFView.x3d) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application. | CVSS3: 5.5 | 0% Низкий | около 3 лет назад | |
GHSA-28r9-4273-pm3w An insecure transport protocol used by Drobo Dashboard API on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to intercept network traffic. | CVSS3: 9.8 | 0% Низкий | больше 3 лет назад | |
GHSA-28r8-9g34-2x25 A vulnerability in the web UI of Cisco Umbrella could allow an unauthenticated, remote attacker to negatively affect the performance of this service. The vulnerability exists due to insufficient rate limiting controls in the web UI. An attacker could exploit this vulnerability by sending crafted HTTPS packets at a high and sustained rate. A successful exploit could allow the attacker to negatively affect the performance of the web UI. Cisco has addressed this vulnerability. | 0% Низкий | около 3 лет назад | ||
GHSA-28r8-6q2m-x9g4 The XD Forum (aka com.tapatalk.xdforumcomforum) application 3.9.17 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 0% Низкий | больше 3 лет назад | ||
GHSA-28r6-jm5h-mrgg Access control bypass in Beego | 0% Низкий | больше 3 лет назад | ||
GHSA-28r4-58h5-m5rr In JetBrains YouTrack before 2021.3.21051, a user could see boards without having corresponding permissions. | CVSS3: 4.3 | 0% Низкий | около 3 лет назад | |
GHSA-28r2-q6m8-9hpx HashiCorp go-getter unsafe downloads could lead to asymmetric resource exhaustion | CVSS3: 8.6 | 0% Низкий | около 3 лет назад | |
GHSA-28qw-8jmg-32wx Transient DOS when processing a NULL buffer while parsing WLAN vdev. | CVSS3: 7.5 | 0% Низкий | больше 1 года назад | |
GHSA-28qr-hqrv-mhvr libdwarf 2016-10-21 allows context-dependent attackers to obtain sensitive information or cause a denial of service by using the "malformed dwarf file" approach, related to a "Heap Buffer Over-read" issue affecting the dwarf_util.c component, aka DW201611-006. | CVSS3: 9.1 | 0% Низкий | больше 3 лет назад | |
GHSA-28qq-773c-49rf SQL injection vulnerability in view_reviews.php in Prozilla Cheat Script (aka Cheats) 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | 0% Низкий | больше 3 лет назад | ||
GHSA-28qp-wgp5-fp7m Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.6.4-pl4 allow remote attackers to inject arbitrary web script or HTML via (1) the cookie-based login panel, (2) the title parameter and (3) the table creation dialog. | 0% Низкий | больше 3 лет назад | ||
GHSA-28qp-rcr7-xp4g IBM TXSeries for Multiplatforms 9.1 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | CVSS3: 5.4 | 0% Низкий | 5 месяцев назад | |
GHSA-28qp-98vv-5xqx The OTR plugin for Gajim sends information in cleartext when using XHTML, which allows remote attackers to obtain sensitive information via unspecified vectors. | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | |
GHSA-28qp-8c7m-wc33 Redland Raptor (aka libraptor) before 2.0.7, as used by OpenOffice 3.3 and 3.4 Beta, LibreOffice before 3.4.6 and 3.5.x before 3.5.1, and other products, allows user-assisted remote attackers to read arbitrary files via a crafted XML external entity (XXE) declaration and reference in an RDF document. | CVSS3: 6.5 | 1% Низкий | больше 3 лет назад | |
GHSA-28qm-wmpf-4vwh The extract function in PHP before 5.2.15 does not prevent use of the EXTR_OVERWRITE parameter to overwrite (1) the GLOBALS superglobal array and (2) the this variable, which allows context-dependent attackers to bypass intended access restrictions by modifying data structures that were not intended to depend on external input, a related issue to CVE-2005-2691 and CVE-2006-3758. | 1% Низкий | больше 3 лет назад | ||
GHSA-28qm-6v7q-2wqv Unspecified vulnerability in Oracle MySQL 5.6.30 and earlier and 5.7.12 and earlier allows remote authenticated users to affect availability via vectors related to Server: FTS. | CVSS3: 6.5 | 5% Низкий | больше 3 лет назад | |
GHSA-28qj-gvxv-p5g9 Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting | CVSS3: 5 | 27% Средний | больше 1 года назад |
Уязвимостей на страницу