Количество 314 375
Количество 314 375
GHSA-3mjx-h33f-j53j
A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Meeting Room Booking System v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.
GHSA-3mjx-fvq9-8vm2
BPC SmartVista 2 has Improper Access Control in the SVFE module, where it fails to appropriately restrict access: a normal user is able to access the SVFE2/pages/finadmin/currconvrate/currconvrate.jsf functionality that should be only accessible to an admin.
GHSA-3mjw-wv6f-4q2v
Multiple unspecified vulnerabilities in NetApp Data ONTAP, as used on NetApp and IBM eServer platforms, allow remote attackers to execute arbitrary commands, cause a denial of service (system crash), or obtain sensitive information, probably related to insufficient access control for HTTP requests. NOTE: this may overlap CVE-2008-3160.
GHSA-3mjv-89c5-xc65
In jpg driver, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with System execution privileges needed
GHSA-3mjr-8v4p-9qf4
A code execution vulnerability exists in the Xiaomi App market product. The vulnerability is caused by unsafe configuration and can be exploited by attackers to execute arbitrary code.
GHSA-3mjr-5fr9-2r8m
The setup_cifs_sb function in fs/cifs/connect.c in the Linux kernel before 2.6.39 does not properly handle DFS referrals, which allows remote CIFS servers to cause a denial of service (system crash) by placing a referral at the root of a share.
GHSA-3mjq-qmqc-xrrv
Microsoft Windows Media Player 7 executes scripts in custom skin (.WMS) files, which could allow remote attackers to gain privileges via a skin that contains a malicious script, aka the ".WMS Script Execution" vulnerability.
GHSA-3mjq-gr7r-h6x3
An XML External Entity (XXE) vulnerability in the Import object and Translation Memory import functionalities of WorldServer v11.8.2 to access sensitive information and execute arbitrary commands via supplying a crafted .tmx file.
GHSA-3mjq-8c52-rc5f
A vulnerability was found in SourceCodester Car Driving School Management System 1.0. It has been declared as problematic. Affected by this vulnerability is the function update_settings_info of the file /classes/SystemSettings.php?f=update_settings. The manipulation of the argument contact/address leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
GHSA-3mjp-p938-4329
Apache Tomcat vulnerable to SecurityManager bypass
GHSA-3mjp-86xg-ff9v
Improper Restriction of XML External Entity Reference vulnerability in DLP Endpoint for Windows prior to 11.9.100 and 11.6.600 allows a remote attacker to cause the DLP Agent to access a local service that the attacker wouldn't usually have access to via a carefully constructed XML file, which the DLP Agent doesn't parse correctly.
GHSA-3mjj-mr4f-qxmx
Mercurial mishandles integer addition and subtraction
GHSA-3mjj-j5cv-mf5p
Cross-site request forgery (CSRF) vulnerability in admin/conf_users_edit.php in PHP Link Directory (phpLD) 4.1.0 allows remote attackers to hijack the authentication of administrators for requests that add an administrator via the N action.
GHSA-3mjj-cjvr-532f
Unspecified vulnerability in Reservation.class.php for phpScheduleIt 1.01 and earlier allows attackers to modify or delete reservations.
GHSA-3mjh-87v6-2677
Unspecified vulnerability in McAfee Encrypted USB Manager 3.1.0.0, when the Re-use Threshold for passwords is nonzero, allows remote attackers to conduct offline brute force attacks via unknown vectors.
GHSA-3mjh-34gx-h2r7
Symantec Endpoint Protection Manager, prior to 14.3, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program.
GHSA-3mjg-gvfx-f783
Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 allow remote attackers to execute arbitrary code by changing an element's style from position:relative to position:static, which causes Gecko to operate on freed memory.
GHSA-3mjg-59rv-9hm8
In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can use the `printf` SPL function to perform a denial of service (DoS) against the Splunk Enterprise instance.
GHSA-3mjg-24q2-wgh5
In InputMethodInfo of InputMethodInfo.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
GHSA-3mjf-7c4r-qw77
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3mjx-h33f-j53j A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Meeting Room Booking System v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages. | CVSS3: 4.3 | 0% Низкий | 12 месяцев назад | |
GHSA-3mjx-fvq9-8vm2 BPC SmartVista 2 has Improper Access Control in the SVFE module, where it fails to appropriately restrict access: a normal user is able to access the SVFE2/pages/finadmin/currconvrate/currconvrate.jsf functionality that should be only accessible to an admin. | CVSS3: 7.2 | 0% Низкий | больше 3 лет назад | |
GHSA-3mjw-wv6f-4q2v Multiple unspecified vulnerabilities in NetApp Data ONTAP, as used on NetApp and IBM eServer platforms, allow remote attackers to execute arbitrary commands, cause a denial of service (system crash), or obtain sensitive information, probably related to insufficient access control for HTTP requests. NOTE: this may overlap CVE-2008-3160. | 5% Низкий | почти 4 года назад | ||
GHSA-3mjv-89c5-xc65 In jpg driver, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with System execution privileges needed | CVSS3: 4.4 | 0% Низкий | больше 2 лет назад | |
GHSA-3mjr-8v4p-9qf4 A code execution vulnerability exists in the Xiaomi App market product. The vulnerability is caused by unsafe configuration and can be exploited by attackers to execute arbitrary code. | CVSS3: 7.6 | 0% Низкий | больше 1 года назад | |
GHSA-3mjr-5fr9-2r8m The setup_cifs_sb function in fs/cifs/connect.c in the Linux kernel before 2.6.39 does not properly handle DFS referrals, which allows remote CIFS servers to cause a denial of service (system crash) by placing a referral at the root of a share. | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад | |
GHSA-3mjq-qmqc-xrrv Microsoft Windows Media Player 7 executes scripts in custom skin (.WMS) files, which could allow remote attackers to gain privileges via a skin that contains a malicious script, aka the ".WMS Script Execution" vulnerability. | 2% Низкий | почти 4 года назад | ||
GHSA-3mjq-gr7r-h6x3 An XML External Entity (XXE) vulnerability in the Import object and Translation Memory import functionalities of WorldServer v11.8.2 to access sensitive information and execute arbitrary commands via supplying a crafted .tmx file. | CVSS3: 6.5 | 8% Низкий | около 1 года назад | |
GHSA-3mjq-8c52-rc5f A vulnerability was found in SourceCodester Car Driving School Management System 1.0. It has been declared as problematic. Affected by this vulnerability is the function update_settings_info of the file /classes/SystemSettings.php?f=update_settings. The manipulation of the argument contact/address leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 3.5 | 0% Низкий | больше 1 года назад | |
GHSA-3mjp-p938-4329 Apache Tomcat vulnerable to SecurityManager bypass | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | |
GHSA-3mjp-86xg-ff9v Improper Restriction of XML External Entity Reference vulnerability in DLP Endpoint for Windows prior to 11.9.100 and 11.6.600 allows a remote attacker to cause the DLP Agent to access a local service that the attacker wouldn't usually have access to via a carefully constructed XML file, which the DLP Agent doesn't parse correctly. | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад | |
GHSA-3mjj-mr4f-qxmx Mercurial mishandles integer addition and subtraction | CVSS3: 9.8 | 1% Низкий | больше 3 лет назад | |
GHSA-3mjj-j5cv-mf5p Cross-site request forgery (CSRF) vulnerability in admin/conf_users_edit.php in PHP Link Directory (phpLD) 4.1.0 allows remote attackers to hijack the authentication of administrators for requests that add an administrator via the N action. | 0% Низкий | больше 3 лет назад | ||
GHSA-3mjj-cjvr-532f Unspecified vulnerability in Reservation.class.php for phpScheduleIt 1.01 and earlier allows attackers to modify or delete reservations. | 0% Низкий | почти 4 года назад | ||
GHSA-3mjh-87v6-2677 Unspecified vulnerability in McAfee Encrypted USB Manager 3.1.0.0, when the Re-use Threshold for passwords is nonzero, allows remote attackers to conduct offline brute force attacks via unknown vectors. | 1% Низкий | почти 4 года назад | ||
GHSA-3mjh-34gx-h2r7 Symantec Endpoint Protection Manager, prior to 14.3, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program. | 0% Низкий | больше 3 лет назад | ||
GHSA-3mjg-gvfx-f783 Mozilla Firefox before 1.5.0.1, Thunderbird 1.5 if running Javascript in mail, and SeaMonkey before 1.0 allow remote attackers to execute arbitrary code by changing an element's style from position:relative to position:static, which causes Gecko to operate on freed memory. | 8% Низкий | почти 4 года назад | ||
GHSA-3mjg-59rv-9hm8 In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can use the `printf` SPL function to perform a denial of service (DoS) against the Splunk Enterprise instance. | CVSS3: 6.5 | 0% Низкий | больше 2 лет назад | |
GHSA-3mjg-24q2-wgh5 In InputMethodInfo of InputMethodInfo.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. | CVSS3: 5.5 | 0% Низкий | 2 месяца назад | |
GHSA-3mjf-7c4r-qw77 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | CVSS3: 5.5 | 0% Низкий | больше 2 лет назад |
Уязвимостей на страницу