Количество 314 458
Количество 314 458
GHSA-3pc3-3mfc-x5vj
The Connection Conversation Manager (aka CuCsMgr) process in Cisco Unity Connection 8.5 before 8.5(1)SU7, 8.6 before 8.6(2a)SU4, 9.x before 9.1(2)SU2, and 10.0 before 10.0(1)SU1, when SIP trunk integration is enabled, allows remote attackers to cause a denial of service (core dump and restart) via crafted SIP INVITE messages, aka Bug ID CSCul26267.
GHSA-3pc2-fm7p-q2vg
Cross-site Scripting in October
GHSA-3pc2-c878-63rj
A path traversal vulnerability in the “account_print.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow a remote authenticated attacker with administrator privileges to execute unauthorized OS commands in the “tmp” directory by uploading a crafted file if the hotspot function were enabled.
GHSA-3p9x-xxx6-2w4p
Broken Access Control in 3rd party TYPO3 extension "femanager"
GHSA-3p9x-xxjc-hw5p
The Qards plugin through 2017-10-11 for WordPress has XSS via a remote document specified in the url parameter to html2canvasproxy.php.
GHSA-3p9x-fj5f-w25c
A vulnerability in the remote access VPN session manager of Cisco Adaptive Security Appliance (ASA) Software could allow a unauthenticated, remote attacker to cause a denial of service (DoS) condition on the remote access VPN services. The vulnerability is due to an issue with the remote access VPN session manager. An attacker could exploit this vulnerability by requesting an excessive number of remote access VPN sessions. An exploit could allow the attacker to cause a DoS condition.
GHSA-3p9x-34w6-f58v
Cross-site scripting (XSS) vulnerability in the Webform Framework API in IBM Forms Server 4.0.x, 8.0.x, 8.1, and 8.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 110006.
GHSA-3p9w-wq67-w93f
libgadu before 1.8.2 allows remote servers to cause a denial of service (crash) via a contact description with a large length, which triggers a buffer over-read.
GHSA-3p9w-w3x4-vc62
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5 and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-Force ID: 140973.
GHSA-3p9w-w3g3-89rg
Open redirect vulnerability in the Login Page (index.php) in ownCloud before 5.0.6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect_url parameter.
GHSA-3p9w-pv5h-crrp
The Contact Form Advanced Database WordPress plugin through 1.0.8 does not have any authorisation as well as CSRF checks in its delete_cf7_data and export_cf7_data AJAX actions, available to any authenticated users, which could allow users with a role as low as subscriber to call them. The delete_cf7_data would lead to arbitrary metadata deletion, as well as PHP Object Injection if a suitable gadget chain is present in another plugin, as user data is passed to the maybe_unserialize() function without being first validated.
GHSA-3p9w-cf27-62fv
Microsoft Message Queuing Remote Code Execution Vulnerability
GHSA-3p9w-7x8w-2m9v
PHP remote file inclusion vulnerability in index.php in GrapAgenda 0.11 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the page parameter.
GHSA-3p9v-xp6w-wcmc
QuickAppsCMS Cross-Site Request Forgery (CSRF)
GHSA-3p9v-8h44-8rrr
The WP Spell Check WordPress plugin before 9.13 does not escape ignored words, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
GHSA-3p9v-2c3q-cf4v
A SQL Injection vulnerability was found in /admin/index.php in phpgurukul Online Nurse Hiring System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the username parameter.
GHSA-3p9r-x2jj-qm7x
Bento4 v1.6.0-639 was discovered to contain a memory leak via the AP4_Processor::Process function in the mp4encrypt binary.
GHSA-3p9r-g8j3-8wq4
Cross-site scripting (XSS) vulnerability in assets/player.swf in the Audio Player plugin before 2.0.4.6 for Wordpress allows remote attackers to inject arbitrary web script or HTML via the playerID parameter.
GHSA-3p9r-c4wp-v55p
** DISPUTED ** An issue was discovered in Halvotec RaQuest 10.23.10801.0. It allows session fixation. NOTE: the vendor does not recognize this issue and will not patch it.
GHSA-3p9r-c4f8-vv7m
Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromVirtualSer function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3pc3-3mfc-x5vj The Connection Conversation Manager (aka CuCsMgr) process in Cisco Unity Connection 8.5 before 8.5(1)SU7, 8.6 before 8.6(2a)SU4, 9.x before 9.1(2)SU2, and 10.0 before 10.0(1)SU1, when SIP trunk integration is enabled, allows remote attackers to cause a denial of service (core dump and restart) via crafted SIP INVITE messages, aka Bug ID CSCul26267. | 0% Низкий | больше 3 лет назад | ||
GHSA-3pc2-fm7p-q2vg Cross-site Scripting in October | CVSS3: 3.7 | 0% Низкий | больше 5 лет назад | |
GHSA-3pc2-c878-63rj A path traversal vulnerability in the “account_print.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow a remote authenticated attacker with administrator privileges to execute unauthorized OS commands in the “tmp” directory by uploading a crafted file if the hotspot function were enabled. | CVSS3: 7.2 | 1% Низкий | больше 2 лет назад | |
GHSA-3p9x-xxx6-2w4p Broken Access Control in 3rd party TYPO3 extension "femanager" | CVSS3: 8.6 | 1% Низкий | около 3 лет назад | |
GHSA-3p9x-xxjc-hw5p The Qards plugin through 2017-10-11 for WordPress has XSS via a remote document specified in the url parameter to html2canvasproxy.php. | 1% Низкий | больше 3 лет назад | ||
GHSA-3p9x-fj5f-w25c A vulnerability in the remote access VPN session manager of Cisco Adaptive Security Appliance (ASA) Software could allow a unauthenticated, remote attacker to cause a denial of service (DoS) condition on the remote access VPN services. The vulnerability is due to an issue with the remote access VPN session manager. An attacker could exploit this vulnerability by requesting an excessive number of remote access VPN sessions. An exploit could allow the attacker to cause a DoS condition. | CVSS3: 5.9 | 0% Низкий | больше 3 лет назад | |
GHSA-3p9x-34w6-f58v Cross-site scripting (XSS) vulnerability in the Webform Framework API in IBM Forms Server 4.0.x, 8.0.x, 8.1, and 8.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 110006. | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-3p9w-wq67-w93f libgadu before 1.8.2 allows remote servers to cause a denial of service (crash) via a contact description with a large length, which triggers a buffer over-read. | 1% Низкий | больше 3 лет назад | ||
GHSA-3p9w-w3x4-vc62 IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5 and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-Force ID: 140973. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-3p9w-w3g3-89rg Open redirect vulnerability in the Login Page (index.php) in ownCloud before 5.0.6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect_url parameter. | 0% Низкий | больше 3 лет назад | ||
GHSA-3p9w-pv5h-crrp The Contact Form Advanced Database WordPress plugin through 1.0.8 does not have any authorisation as well as CSRF checks in its delete_cf7_data and export_cf7_data AJAX actions, available to any authenticated users, which could allow users with a role as low as subscriber to call them. The delete_cf7_data would lead to arbitrary metadata deletion, as well as PHP Object Injection if a suitable gadget chain is present in another plugin, as user data is passed to the maybe_unserialize() function without being first validated. | CVSS3: 4.3 | 0% Низкий | около 4 лет назад | |
GHSA-3p9w-cf27-62fv Microsoft Message Queuing Remote Code Execution Vulnerability | CVSS3: 9.8 | 3% Низкий | больше 2 лет назад | |
GHSA-3p9w-7x8w-2m9v PHP remote file inclusion vulnerability in index.php in GrapAgenda 0.11 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the page parameter. | 17% Средний | почти 4 года назад | ||
GHSA-3p9v-xp6w-wcmc QuickAppsCMS Cross-Site Request Forgery (CSRF) | CVSS3: 8.8 | 0% Низкий | больше 3 лет назад | |
GHSA-3p9v-8h44-8rrr The WP Spell Check WordPress plugin before 9.13 does not escape ignored words, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | CVSS3: 4.8 | 0% Низкий | около 3 лет назад | |
GHSA-3p9v-2c3q-cf4v A SQL Injection vulnerability was found in /admin/index.php in phpgurukul Online Nurse Hiring System v1.0, which allows remote attackers to execute arbitrary SQL commands to get unauthorized database access via the username parameter. | CVSS3: 9.8 | 11% Средний | около 1 года назад | |
GHSA-3p9r-x2jj-qm7x Bento4 v1.6.0-639 was discovered to contain a memory leak via the AP4_Processor::Process function in the mp4encrypt binary. | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад | |
GHSA-3p9r-g8j3-8wq4 Cross-site scripting (XSS) vulnerability in assets/player.swf in the Audio Player plugin before 2.0.4.6 for Wordpress allows remote attackers to inject arbitrary web script or HTML via the playerID parameter. | 4% Низкий | больше 3 лет назад | ||
GHSA-3p9r-c4wp-v55p ** DISPUTED ** An issue was discovered in Halvotec RaQuest 10.23.10801.0. It allows session fixation. NOTE: the vendor does not recognize this issue and will not patch it. | 0% Низкий | больше 3 лет назад | ||
GHSA-3p9r-c4f8-vv7m Tenda FH1201 v1.2.0.14 (408) was discovered to contain a stack overflow via the page parameter in the fromVirtualSer function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | CVSS3: 7.5 | 0% Низкий | больше 1 года назад |
Уязвимостей на страницу