Количество 314 458
Количество 314 458
GHSA-3qf3-2r2j-47g4
The ASPEED ast2400 and ast2500 Baseband Management Controller (BMC) hardware and firmware implement Advanced High-performance Bus (AHB) bridges, which allow arbitrary read and write access to the BMC's physical address space from the host (or from the network in unusual cases where the BMC console uart is attached to a serial concentrator). This CVE applies to the specific cases of iLPC2AHB bridge Pt I, iLPC2AHB bridge Pt II, PCIe VGA P2A bridge, DMA from/to arbitrary BMC memory via X-DMA, UART-based SoC Debug interface, LPC2AHB bridge, PCIe BMC P2A bridge, and Watchdog setup.
GHSA-3qf2-xr2w-rc3p
Unspecified vulnerability in IBM Tivoli Monitoring Agent (ITMA), as used in IBM DB2 9.5 before FP9 on UNIX, allows local users to gain privileges via unknown vectors.
GHSA-3qf2-m7p9-w73v
Brocade BigIron RX switches allow remote attackers to bypass ACL rules by using 179 as the source port of a packet.
GHSA-3qf2-c4pc-rv85
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate project keys via an Information Disclosure vulnerability in the /browse.PROJECTKEY endpoint. The affected versions are before version 7.13.7, from version 8.0.0 before 8.5.8, and from version 8.6.0 before 8.12.0.
GHSA-3qf2-7xvh-j2fx
Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and 22.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web ...
GHSA-3qcx-rj23-g86q
A vulnerability classified as critical has been found in thautwarm vscode-diana 0.0.1. Affected is an unknown function of the file Gen.py of the component Jinja2 Template Handler. The manipulation leads to injection. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.
GHSA-3qcx-c93v-59hr
Windows Secure Kernel Mode Elevation of Privilege Vulnerability
GHSA-3qcx-4983-xfxp
HP Color LaserJet Pro M280-M281 Multifunction Printer series (before v. 20190419), HP LaserJet Pro MFP M28-M31 Printer series (before v. 20190426) may have embedded web server attributes which may be potentially vulnerable to Buffer Overflow.
GHSA-3qcw-xpj5-x29h
Microsoft Dynamics 365 (on-premises) Spoofing Vulnerability
GHSA-3qcw-gv72-ccfg
Safari 1.2.4 on Mac OS X 10.3.6 allows remote attackers to cause a denial of service (application crash from memory exhaustion), as demonstrated using Javascript code that continuously creates nested arrays and then sorts the newly created arrays.
GHSA-3qcw-5j3f-5872
Use-after-free vulnerability in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, might allow attackers to execute arbitrary code via unspecified vectors related to an unspecified "image type within a certain function."
GHSA-3qcv-2mv7-28qv
DUware DUpoll 3.0 and 3.1 stores _private/Dupoll.mdb under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as usernames and passwords.
GHSA-3qcr-p3xq-5c4r
RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users to achieve a pool overflow (leading to Escalation of Privileges, Denial of Service, and Code Execution) via a crafted Device IO Control packet to a device.
GHSA-3qcq-w2m6-vwwx
An interaction between the AS/400 shared folders feature and Microsoft SNA Server 3.0 and earlier allows users to view each other's folders when the users share the same Local APPC LU.
GHSA-3qcq-p3m2-3c4p
Missing Authorization vulnerability in Select-Themes Don Peppe donpeppe allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Don Peppe: from n/a through <= 1.3.
GHSA-3qcq-28jc-g3f4
The Download Manager WordPress plugin before 3.2.83 does not protect file download's passwords, leaking it upon receiving an invalid one.
GHSA-3qcp-g78m-7jv9
A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.
GHSA-3qcp-9v8c-6jp7
Piranha CMS vulnerable to stored cross-site scripting (XSS)
GHSA-3qcj-r6mr-vw7f
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer allows DOM-Based XSS.This issue affects tagDiv Composer: from n/a through <= 5.4.2.
GHSA-3qch-fgcw-x72h
In phNxpNciHal_ext_process_nfc_init_rsp of phNxpNciHal_ext.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the NFC server with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-169258455
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3qf3-2r2j-47g4 The ASPEED ast2400 and ast2500 Baseband Management Controller (BMC) hardware and firmware implement Advanced High-performance Bus (AHB) bridges, which allow arbitrary read and write access to the BMC's physical address space from the host (or from the network in unusual cases where the BMC console uart is attached to a serial concentrator). This CVE applies to the specific cases of iLPC2AHB bridge Pt I, iLPC2AHB bridge Pt II, PCIe VGA P2A bridge, DMA from/to arbitrary BMC memory via X-DMA, UART-based SoC Debug interface, LPC2AHB bridge, PCIe BMC P2A bridge, and Watchdog setup. | CVSS3: 9.8 | 2% Низкий | больше 3 лет назад | |
GHSA-3qf2-xr2w-rc3p Unspecified vulnerability in IBM Tivoli Monitoring Agent (ITMA), as used in IBM DB2 9.5 before FP9 on UNIX, allows local users to gain privileges via unknown vectors. | 0% Низкий | больше 3 лет назад | ||
GHSA-3qf2-m7p9-w73v Brocade BigIron RX switches allow remote attackers to bypass ACL rules by using 179 as the source port of a packet. | 1% Низкий | больше 3 лет назад | ||
GHSA-3qf2-c4pc-rv85 Affected versions of Atlassian Jira Server and Data Center allow remote attackers to enumerate project keys via an Information Disclosure vulnerability in the /browse.PROJECTKEY endpoint. The affected versions are before version 7.13.7, from version 8.0.0 before 8.5.8, and from version 8.6.0 before 8.12.0. | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | |
GHSA-3qf2-7xvh-j2fx Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Libraries). Supported versions that are affected are Oracle Java SE: 7u331, 8u321, 11.0.14, 17.0.2, 18; Oracle GraalVM Enterprise Edition: 20.3.5, 21.3.1 and 22.0.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Oracle Java SE, Oracle GraalVM Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Java SE, Oracle GraalVM Enterprise Edition accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets, that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web ... | CVSS3: 5.3 | 0% Низкий | почти 4 года назад | |
GHSA-3qcx-rj23-g86q A vulnerability classified as critical has been found in thautwarm vscode-diana 0.0.1. Affected is an unknown function of the file Gen.py of the component Jinja2 Template Handler. The manipulation leads to injection. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. | CVSS3: 5.3 | 0% Низкий | 10 месяцев назад | |
GHSA-3qcx-c93v-59hr Windows Secure Kernel Mode Elevation of Privilege Vulnerability | CVSS3: 7.8 | 0% Низкий | больше 1 года назад | |
GHSA-3qcx-4983-xfxp HP Color LaserJet Pro M280-M281 Multifunction Printer series (before v. 20190419), HP LaserJet Pro MFP M28-M31 Printer series (before v. 20190426) may have embedded web server attributes which may be potentially vulnerable to Buffer Overflow. | CVSS3: 7.2 | 1% Низкий | больше 3 лет назад | |
GHSA-3qcw-xpj5-x29h Microsoft Dynamics 365 (on-premises) Spoofing Vulnerability | CVSS3: 5.4 | 1% Низкий | больше 3 лет назад | |
GHSA-3qcw-gv72-ccfg Safari 1.2.4 on Mac OS X 10.3.6 allows remote attackers to cause a denial of service (application crash from memory exhaustion), as demonstrated using Javascript code that continuously creates nested arrays and then sorts the newly created arrays. | 1% Низкий | почти 4 года назад | ||
GHSA-3qcw-5j3f-5872 Use-after-free vulnerability in Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64, and Adobe AIR before 2.0.2.12610, might allow attackers to execute arbitrary code via unspecified vectors related to an unspecified "image type within a certain function." | 1% Низкий | больше 3 лет назад | ||
GHSA-3qcv-2mv7-28qv DUware DUpoll 3.0 and 3.1 stores _private/Dupoll.mdb under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as usernames and passwords. | 1% Низкий | почти 4 года назад | ||
GHSA-3qcr-p3xq-5c4r RtsUpx.sys in Realtek RtsUpx USB Utility Driver for Camera/Hub/Audio through 1.14.0.0 allows local low-privileged users to achieve a pool overflow (leading to Escalation of Privileges, Denial of Service, and Code Execution) via a crafted Device IO Control packet to a device. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-3qcq-w2m6-vwwx An interaction between the AS/400 shared folders feature and Microsoft SNA Server 3.0 and earlier allows users to view each other's folders when the users share the same Local APPC LU. | 14% Средний | почти 4 года назад | ||
GHSA-3qcq-p3m2-3c4p Missing Authorization vulnerability in Select-Themes Don Peppe donpeppe allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Don Peppe: from n/a through <= 1.3. | CVSS3: 4.3 | 0% Низкий | 17 дней назад | |
GHSA-3qcq-28jc-g3f4 The Download Manager WordPress plugin before 3.2.83 does not protect file download's passwords, leaking it upon receiving an invalid one. | CVSS3: 7.5 | 81% Высокий | около 2 лет назад | |
GHSA-3qcp-g78m-7jv9 A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux. | CVSS3: 8.8 | 53% Средний | больше 3 лет назад | |
GHSA-3qcp-9v8c-6jp7 Piranha CMS vulnerable to stored cross-site scripting (XSS) | 0% Низкий | 4 месяца назад | ||
GHSA-3qcj-r6mr-vw7f Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tagDiv tagDiv Composer td-composer allows DOM-Based XSS.This issue affects tagDiv Composer: from n/a through <= 5.4.2. | CVSS3: 6.1 | 0% Низкий | 17 дней назад | |
GHSA-3qch-fgcw-x72h In phNxpNciHal_ext_process_nfc_init_rsp of phNxpNciHal_ext.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure in the NFC server with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-11Android ID: A-169258455 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу