Количество 314 458
Количество 314 458
GHSA-3v72-4xqg-8rpf
Session fixation vulnerability in the web interface in Pattern Insight 2.3 allows remote attackers to hijack web sessions via a jsession_id cookie.
GHSA-3v6x-x9qx-ccmh
An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, create, update, and delete the database, through the 'data%5BPage%5D%5Bname%5D' parameter in /apprain/page/manage-dynamic-pages/create.
GHSA-3v6x-g643-6gw7
Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
GHSA-3v6x-9mfm-xp5x
Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable memory corruption vulnerability in the image conversion module when handling malformed TIFF images. Successful exploitation could lead to arbitrary code execution.
GHSA-3v6x-9jmh-gp3w
Windows Mobile Device Management Remote Code Execution Vulnerability.
GHSA-3v6w-vg3j-g58f
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Pdfcrowd Save as Image plugin by Pdfcrowd plugin <= 2.16.0 versions.
GHSA-3v6w-73q2-w9pg
In OpenBSD 7.2, a TCP packet with destination port 0 that matches a pf divert-to rule can crash the kernel.
GHSA-3v6v-w2x6-55vq
Privilege escalation vulnerability in McAfee Agent (MA) before 5.6.1 HF3, allows local administrator users to potentially disable some McAfee processes by manipulating the MA directory control and placing a carefully constructed file in the MA directory.
GHSA-3v6v-2x6p-32mc
pgadmin4 vulnerable to Code Injection
GHSA-3v6r-vhg4-9m9j
IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.
GHSA-3v6r-pw5p-6hc2
An elevation of privilege exists in Windows Audio Service, aka 'Windows Audio Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1021, CVE-2019-1022, CVE-2019-1026, CVE-2019-1027, CVE-2019-1028.
GHSA-3v6q-chwv-xhhp
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Smplug-in Social Like Box and Page by WpDevArt plugin <= 0.8.39 versions.
GHSA-3v6p-5m88-xqx6
Integer overflow in the wrestool program in icoutils before 0.31.1 allows remote attackers to cause a denial of service (memory corruption) via a crafted executable, which triggers a denial of service (application crash) or the possibility of execution of arbitrary code.
GHSA-3v6p-5g46-w432
Improper input validation in some Intel(R) Neural Compressor software before version v3.0 may allow an authenticated user to potentially enable escalation of privilege via adjacent access.
GHSA-3v6m-8v49-4vvq
Race condition in the administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows remote attackers to obtain privileged-account access, and consequently provide ZipDownload.jsp input containing directory traversal sequences to read arbitrary files, via a request to port 40080 or 40443.
GHSA-3v6j-v3qc-cxff
Denial of service from unlimited password lengths
GHSA-3v6j-pmgg-8c38
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) private JPEG data. Successful exploitation could lead to arbitrary code execution.
GHSA-3v6j-9mf5-wv3f
The default password for the web application’s root user (the vendor’s private account) was weak and the MD5 hash was used to crack the password using a widely available open-source tool.
GHSA-3v6h-ww3h-9h87
SQL injection vulnerability in poll_frame.php in Vote! Pro 4.0 and earlier allows remote attackers to execute arbitrary SQL commands via the poll_id parameter.
GHSA-3v6h-m7q4-2c4g
A directory traversal vulnerability exists in the BIG-IP Configuration Utility that may allow an authenticated attacker to execute commands on the BIG-IP system. For BIG-IP system running in Appliance mode, a successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3v72-4xqg-8rpf Session fixation vulnerability in the web interface in Pattern Insight 2.3 allows remote attackers to hijack web sessions via a jsession_id cookie. | 1% Низкий | больше 3 лет назад | ||
GHSA-3v6x-x9qx-ccmh An SQL injection vulnerability has been found in appRain CMF 4.0.5. This vulnerability allows an attacker to retrieve, create, update, and delete the database, through the 'data%5BPage%5D%5Bname%5D' parameter in /apprain/page/manage-dynamic-pages/create. | CVSS3: 9.8 | 0% Низкий | 5 месяцев назад | |
GHSA-3v6x-g643-6gw7 Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability." | 15% Средний | больше 3 лет назад | ||
GHSA-3v6x-9mfm-xp5x Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable memory corruption vulnerability in the image conversion module when handling malformed TIFF images. Successful exploitation could lead to arbitrary code execution. | CVSS3: 7.8 | 2% Низкий | больше 3 лет назад | |
GHSA-3v6x-9jmh-gp3w Windows Mobile Device Management Remote Code Execution Vulnerability. | CVSS3: 7.8 | 1% Низкий | почти 4 года назад | |
GHSA-3v6w-vg3j-g58f Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Pdfcrowd Save as Image plugin by Pdfcrowd plugin <= 2.16.0 versions. | CVSS3: 5.9 | 0% Низкий | больше 2 лет назад | |
GHSA-3v6w-73q2-w9pg In OpenBSD 7.2, a TCP packet with destination port 0 that matches a pf divert-to rule can crash the kernel. | CVSS3: 7.5 | 0% Низкий | почти 3 года назад | |
GHSA-3v6v-w2x6-55vq Privilege escalation vulnerability in McAfee Agent (MA) before 5.6.1 HF3, allows local administrator users to potentially disable some McAfee processes by manipulating the MA directory control and placing a carefully constructed file in the MA directory. | 0% Низкий | больше 3 лет назад | ||
GHSA-3v6v-2x6p-32mc pgadmin4 vulnerable to Code Injection | CVSS3: 8.8 | 87% Высокий | около 3 лет назад | |
GHSA-3v6r-vhg4-9m9j IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server. | CVSS3: 8.8 | 2% Низкий | больше 3 лет назад | |
GHSA-3v6r-pw5p-6hc2 An elevation of privilege exists in Windows Audio Service, aka 'Windows Audio Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1021, CVE-2019-1022, CVE-2019-1026, CVE-2019-1027, CVE-2019-1028. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-3v6q-chwv-xhhp Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Smplug-in Social Like Box and Page by WpDevArt plugin <= 0.8.39 versions. | CVSS3: 4.8 | 0% Низкий | почти 3 года назад | |
GHSA-3v6p-5m88-xqx6 Integer overflow in the wrestool program in icoutils before 0.31.1 allows remote attackers to cause a denial of service (memory corruption) via a crafted executable, which triggers a denial of service (application crash) or the possibility of execution of arbitrary code. | CVSS3: 8.8 | 2% Низкий | больше 3 лет назад | |
GHSA-3v6p-5g46-w432 Improper input validation in some Intel(R) Neural Compressor software before version v3.0 may allow an authenticated user to potentially enable escalation of privilege via adjacent access. | CVSS3: 5.5 | 0% Низкий | около 1 года назад | |
GHSA-3v6m-8v49-4vvq Race condition in the administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows remote attackers to obtain privileged-account access, and consequently provide ZipDownload.jsp input containing directory traversal sequences to read arbitrary files, via a request to port 40080 or 40443. | 0% Низкий | больше 3 лет назад | ||
GHSA-3v6j-v3qc-cxff Denial of service from unlimited password lengths | CVSS3: 5.3 | 0% Низкий | больше 2 лет назад | |
GHSA-3v6j-pmgg-8c38 Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) private JPEG data. Successful exploitation could lead to arbitrary code execution. | CVSS3: 8.8 | 8% Низкий | больше 3 лет назад | |
GHSA-3v6j-9mf5-wv3f The default password for the web application’s root user (the vendor’s private account) was weak and the MD5 hash was used to crack the password using a widely available open-source tool. | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад | |
GHSA-3v6h-ww3h-9h87 SQL injection vulnerability in poll_frame.php in Vote! Pro 4.0 and earlier allows remote attackers to execute arbitrary SQL commands via the poll_id parameter. | 1% Низкий | почти 4 года назад | ||
GHSA-3v6h-m7q4-2c4g A directory traversal vulnerability exists in the BIG-IP Configuration Utility that may allow an authenticated attacker to execute commands on the BIG-IP system. For BIG-IP system running in Appliance mode, a successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | CVSS3: 9.9 | 3% Низкий | больше 2 лет назад |
Уязвимостей на страницу