Количество 314 458
Количество 314 458
GHSA-3mm6-vwmh-qm9c
The hardware VPN client in Viprinet MultichannelVPN Router 300 version 2013070830/2013080900 does not validate the remote VPN endpoint identity (through the checking of the endpoint's SSL key) before initiating the exchange, which allows an attacker to perform a Man in the Middle attack.
GHSA-3mm6-mv5c-6hfv
LastPass prior to 2.5.1 has an insecure PIN implementation.
GHSA-3mm6-hc5r-p5rx
Premisys Identicard version 3.1.190 stores user credentials and other sensitive information with a known weak encryption method (MD5 hash of a salt and password).
GHSA-3mm6-4hpm-pgrc
Elementor 2.9.5 and below WordPress plugin allows authenticated users to activate its safe mode feature. This can be exploited to disable all security plugins on the blog.
GHSA-3mm5-rh7g-ph5j
A command injection remote code execution vulnerability was discovered on Western Digital My Cloud Devices that could allow an attacker to execute arbitrary system commands on the device. The vulnerability was addressed by escaping individual arguments to shell functions coming from user input.
GHSA-3mm5-fxrj-9334
SQL injection vulnerability in standings.php in Elite Gaming Ladders 3.5 allows remote attackers to execute arbitrary SQL commands via the ladder[id] parameter.
GHSA-3mm4-w7v6-4rhv
android-gif-drawable vulerable to denial of service due to unrestricted comment length
GHSA-3mm4-v52x-x9rw
WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1.
GHSA-3mm4-jwgr-q6c5
Directory traversal vulnerability in the FTP client in AceFTP Freeware 3.80.3 and AceFTP Pro 3.80.3 allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a response to a LIST command, a related issue to CVE-2002-1345.
GHSA-3mm3-wfpv-q85g
Clerk-js vulnerable to bypass of OAuth authentication flow by manipulating request at OTP verification stage
GHSA-3mm3-c684-p47h
The server in EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.5 does not properly process certificate chains, which allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors.
GHSA-3mm2-hvqw-hxq3
This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the configuration of poller resources. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to escalate privileges to the level of an administrator. Was ZDI-CAN-16335.
GHSA-3mjx-h33f-j53j
A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Meeting Room Booking System v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages.
GHSA-3mjx-fvq9-8vm2
BPC SmartVista 2 has Improper Access Control in the SVFE module, where it fails to appropriately restrict access: a normal user is able to access the SVFE2/pages/finadmin/currconvrate/currconvrate.jsf functionality that should be only accessible to an admin.
GHSA-3mjw-wv6f-4q2v
Multiple unspecified vulnerabilities in NetApp Data ONTAP, as used on NetApp and IBM eServer platforms, allow remote attackers to execute arbitrary commands, cause a denial of service (system crash), or obtain sensitive information, probably related to insufficient access control for HTTP requests. NOTE: this may overlap CVE-2008-3160.
GHSA-3mjv-89c5-xc65
In jpg driver, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with System execution privileges needed
GHSA-3mjr-8v4p-9qf4
A code execution vulnerability exists in the Xiaomi App market product. The vulnerability is caused by unsafe configuration and can be exploited by attackers to execute arbitrary code.
GHSA-3mjr-5fr9-2r8m
The setup_cifs_sb function in fs/cifs/connect.c in the Linux kernel before 2.6.39 does not properly handle DFS referrals, which allows remote CIFS servers to cause a denial of service (system crash) by placing a referral at the root of a share.
GHSA-3mjq-qmqc-xrrv
Microsoft Windows Media Player 7 executes scripts in custom skin (.WMS) files, which could allow remote attackers to gain privileges via a skin that contains a malicious script, aka the ".WMS Script Execution" vulnerability.
GHSA-3mjq-gr7r-h6x3
An XML External Entity (XXE) vulnerability in the Import object and Translation Memory import functionalities of WorldServer v11.8.2 to access sensitive information and execute arbitrary commands via supplying a crafted .tmx file.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3mm6-vwmh-qm9c The hardware VPN client in Viprinet MultichannelVPN Router 300 version 2013070830/2013080900 does not validate the remote VPN endpoint identity (through the checking of the endpoint's SSL key) before initiating the exchange, which allows an attacker to perform a Man in the Middle attack. | CVSS3: 5.9 | 0% Низкий | больше 3 лет назад | |
GHSA-3mm6-mv5c-6hfv LastPass prior to 2.5.1 has an insecure PIN implementation. | 0% Низкий | почти 4 года назад | ||
GHSA-3mm6-hc5r-p5rx Premisys Identicard version 3.1.190 stores user credentials and other sensitive information with a known weak encryption method (MD5 hash of a salt and password). | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
GHSA-3mm6-4hpm-pgrc Elementor 2.9.5 and below WordPress plugin allows authenticated users to activate its safe mode feature. This can be exploited to disable all security plugins on the blog. | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад | |
GHSA-3mm5-rh7g-ph5j A command injection remote code execution vulnerability was discovered on Western Digital My Cloud Devices that could allow an attacker to execute arbitrary system commands on the device. The vulnerability was addressed by escaping individual arguments to shell functions coming from user input. | CVSS3: 9.8 | 1% Низкий | около 4 лет назад | |
GHSA-3mm5-fxrj-9334 SQL injection vulnerability in standings.php in Elite Gaming Ladders 3.5 allows remote attackers to execute arbitrary SQL commands via the ladder[id] parameter. | 0% Низкий | больше 3 лет назад | ||
GHSA-3mm4-w7v6-4rhv android-gif-drawable vulerable to denial of service due to unrestricted comment length | CVSS3: 7.5 | 0% Низкий | около 4 лет назад | |
GHSA-3mm4-v52x-x9rw WebKit, as used in Apple Safari before 6.0, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2012-07-25-1. | 3% Низкий | больше 3 лет назад | ||
GHSA-3mm4-jwgr-q6c5 Directory traversal vulnerability in the FTP client in AceFTP Freeware 3.80.3 and AceFTP Pro 3.80.3 allows remote FTP servers to create or overwrite arbitrary files via a .. (dot dot) in a response to a LIST command, a related issue to CVE-2002-1345. | 2% Низкий | больше 3 лет назад | ||
GHSA-3mm3-wfpv-q85g Clerk-js vulnerable to bypass of OAuth authentication flow by manipulating request at OTP verification stage | CVSS3: 7.5 | 3 месяца назад | ||
GHSA-3mm3-c684-p47h The server in EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.5 does not properly process certificate chains, which allows remote attackers to cause a denial of service (daemon crash) via unspecified vectors. | 0% Низкий | больше 3 лет назад | ||
GHSA-3mm2-hvqw-hxq3 This vulnerability allows remote attackers to escalate privileges on affected installations of Centreon. Authentication is required to exploit this vulnerability. The specific flaw exists within the configuration of poller resources. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to escalate privileges to the level of an administrator. Was ZDI-CAN-16335. | CVSS3: 7.2 | 4% Низкий | больше 3 лет назад | |
GHSA-3mjx-h33f-j53j A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Meeting Room Booking System v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages. | CVSS3: 4.3 | 0% Низкий | 12 месяцев назад | |
GHSA-3mjx-fvq9-8vm2 BPC SmartVista 2 has Improper Access Control in the SVFE module, where it fails to appropriately restrict access: a normal user is able to access the SVFE2/pages/finadmin/currconvrate/currconvrate.jsf functionality that should be only accessible to an admin. | CVSS3: 7.2 | 0% Низкий | больше 3 лет назад | |
GHSA-3mjw-wv6f-4q2v Multiple unspecified vulnerabilities in NetApp Data ONTAP, as used on NetApp and IBM eServer platforms, allow remote attackers to execute arbitrary commands, cause a denial of service (system crash), or obtain sensitive information, probably related to insufficient access control for HTTP requests. NOTE: this may overlap CVE-2008-3160. | 5% Низкий | почти 4 года назад | ||
GHSA-3mjv-89c5-xc65 In jpg driver, there is a possible out of bounds write due to improper input validation. This could lead to local denial of service with System execution privileges needed | CVSS3: 4.4 | 0% Низкий | больше 2 лет назад | |
GHSA-3mjr-8v4p-9qf4 A code execution vulnerability exists in the Xiaomi App market product. The vulnerability is caused by unsafe configuration and can be exploited by attackers to execute arbitrary code. | CVSS3: 7.6 | 0% Низкий | больше 1 года назад | |
GHSA-3mjr-5fr9-2r8m The setup_cifs_sb function in fs/cifs/connect.c in the Linux kernel before 2.6.39 does not properly handle DFS referrals, which allows remote CIFS servers to cause a denial of service (system crash) by placing a referral at the root of a share. | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад | |
GHSA-3mjq-qmqc-xrrv Microsoft Windows Media Player 7 executes scripts in custom skin (.WMS) files, which could allow remote attackers to gain privileges via a skin that contains a malicious script, aka the ".WMS Script Execution" vulnerability. | 2% Низкий | почти 4 года назад | ||
GHSA-3mjq-gr7r-h6x3 An XML External Entity (XXE) vulnerability in the Import object and Translation Memory import functionalities of WorldServer v11.8.2 to access sensitive information and execute arbitrary commands via supplying a crafted .tmx file. | CVSS3: 6.5 | 8% Низкий | около 1 года назад |
Уязвимостей на страницу