Количество 314 529
Количество 314 529
GHSA-399c-25pm-72mj
A file write vulnerability exists in the httpd upload.cgi functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to arbitrary file upload. An attacker can upload a malicious file to trigger this vulnerability.
GHSA-3999-5ffv-wp2r
Yamux Memory Exhaustion Vulnerability via Active::pending_frames property
GHSA-3997-cwm3-9wpp
Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allow remote attackers to execute arbitrary code via a font.
GHSA-3997-6wvq-mg36
Improper Access Control vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows local users to access files which the user otherwise would not have access to via manipulating symbolic links to redirect McAfee file operations to an unintended file.
GHSA-3996-4m5r-mmwf
An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Change Avatar function.
GHSA-3995-cwrc-82pq
IBM Maximo Asset Management 7.6.1.3 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
GHSA-3993-w4q6-qwmf
Buffer overflows in lpspooler in the fileset PrinterMgmt.LP-SPOOL of HP-UX 11.0 and earlier allows local users to gain privileges.
GHSA-3993-q22g-mw33
A vulnerability within the Endpoint Learning feature of Cisco Nexus 9000 Series Switches running in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an endpoint device in certain circumstances. The vulnerability is due to improper endpoint learning when packets are received on a specific port from outside the ACI fabric and destined to an endpoint located on a border leaf when Disable Remote Endpoint Learning has been enabled. This can result in a Remote (XR) entry being created for the impacted endpoint that will become stale if the endpoint migrates to a different port or leaf switch. This results in traffic not reaching the impacted endpoint until the Remote entry can be relearned by another mechanism.
GHSA-3993-mq32-jgqq
Cross-site scripting (XSS) vulnerability in the User Karma module 5.x before 5.x-1.13 and 6.x before 6.x-1.0-beta1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified messages.
GHSA-3993-5r92-h3rg
An improper input validation in saped_rec_silence in libsaped prior to SMR Nov-2023 Release 1 allows attacker to cause out-of-bounds read and write.
GHSA-3992-5mfp-43q5
The Gravity Forms Google Sheet Connector WordPress plugin before 1.3.5, gsheetconnector-gravityforms-pro WordPress plugin through 1.3.5 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack
GHSA-398x-qm59-5hfg
Insecure permissions in the file database.sdb of BatFlat CMS v1.3.6 allows attackers to dump the entire database.
GHSA-398x-j3p9-ffhp
Missing Authorization vulnerability in Schema App Schema App Structured Data allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Schema App Structured Data: from n/a through 1.23.1.
GHSA-398w-ffjm-vc8f
websitebaker prior to and including 2.8.1 has an authentication error in backup module.
GHSA-398w-8vvx-7rh5
An issue was discovered in /bin/goahead on D-Link DIR-823G devices with firmware 1.02B03. There is incorrect access control allowing remote attackers to get sensitive information (such as MAC address) about all clients in the WLAN via the GetClientInfo HNAP API. Consequently, an attacker can achieve information disclosure without authentication.
GHSA-398v-cx4g-hhxc
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: msft: Fix memory leak Fix leaking buffer allocated to send MSFT_OP_LE_MONITOR_ADVERTISEMENT.
GHSA-398v-9vhq-3gg5
Insufficient input validation in Intel(R) Active Management Technology (Intel(R) AMT) before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20 may allow an unauthenticated user to potentially cause a denial of service via network access.
GHSA-398v-9qw7-49xj
SQL injection vulnerability in the libpam-pgsql library before 0.5.2 allows attackers to execute arbitrary SQL statements.
GHSA-398v-5g69-w972
IBM Aspera Faspex 4.4.1 and 5.0.0 could allow unauthorized access due to an incorrectly computed security token. IBM X-Force ID: 226951.
GHSA-398r-g5cv-mwh7
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Satos Satos Mobile allows SQL Injection through SOAP Parameter Tampering.This issue affects Satos Mobile: before 20230607.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-399c-25pm-72mj A file write vulnerability exists in the httpd upload.cgi functionality of InHand Networks InRouter302 V3.5.4. A specially-crafted HTTP request can lead to arbitrary file upload. An attacker can upload a malicious file to trigger this vulnerability. | CVSS3: 8.1 | 1% Низкий | больше 3 лет назад | |
GHSA-3999-5ffv-wp2r Yamux Memory Exhaustion Vulnerability via Active::pending_frames property | CVSS3: 7.5 | 0% Низкий | почти 2 года назад | |
GHSA-3997-cwm3-9wpp Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allow remote attackers to execute arbitrary code via a font. | 10% Низкий | больше 3 лет назад | ||
GHSA-3997-6wvq-mg36 Improper Access Control vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows local users to access files which the user otherwise would not have access to via manipulating symbolic links to redirect McAfee file operations to an unintended file. | 0% Низкий | больше 3 лет назад | ||
GHSA-3996-4m5r-mmwf An issue in MyBB 1.8.38 allows a remote attacker to obtain sensitive information via the Change Avatar function. | CVSS3: 7.6 | 0% Низкий | 10 месяцев назад | |
GHSA-3995-cwrc-82pq IBM Maximo Asset Management 7.6.1.3 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. | CVSS3: 3.8 | 0% Низкий | 10 месяцев назад | |
GHSA-3993-w4q6-qwmf Buffer overflows in lpspooler in the fileset PrinterMgmt.LP-SPOOL of HP-UX 11.0 and earlier allows local users to gain privileges. | 0% Низкий | почти 4 года назад | ||
GHSA-3993-q22g-mw33 A vulnerability within the Endpoint Learning feature of Cisco Nexus 9000 Series Switches running in Application Centric Infrastructure (ACI) mode could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an endpoint device in certain circumstances. The vulnerability is due to improper endpoint learning when packets are received on a specific port from outside the ACI fabric and destined to an endpoint located on a border leaf when Disable Remote Endpoint Learning has been enabled. This can result in a Remote (XR) entry being created for the impacted endpoint that will become stale if the endpoint migrates to a different port or leaf switch. This results in traffic not reaching the impacted endpoint until the Remote entry can be relearned by another mechanism. | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | |
GHSA-3993-mq32-jgqq Cross-site scripting (XSS) vulnerability in the User Karma module 5.x before 5.x-1.13 and 6.x before 6.x-1.0-beta1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified messages. | 0% Низкий | больше 3 лет назад | ||
GHSA-3993-5r92-h3rg An improper input validation in saped_rec_silence in libsaped prior to SMR Nov-2023 Release 1 allows attacker to cause out-of-bounds read and write. | CVSS3: 9.8 | 0% Низкий | около 2 лет назад | |
GHSA-3992-5mfp-43q5 The Gravity Forms Google Sheet Connector WordPress plugin before 1.3.5, gsheetconnector-gravityforms-pro WordPress plugin through 1.3.5 does not have CSRF check when updating its Access Code, which could allow attackers to make logged in admin change the access code to an arbitrary one via a CSRF attack | CVSS3: 6.5 | 0% Низкий | больше 2 лет назад | |
GHSA-398x-qm59-5hfg Insecure permissions in the file database.sdb of BatFlat CMS v1.3.6 allows attackers to dump the entire database. | CVSS3: 7.5 | 0% Низкий | почти 4 года назад | |
GHSA-398x-j3p9-ffhp Missing Authorization vulnerability in Schema App Schema App Structured Data allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Schema App Structured Data: from n/a through 1.23.1. | CVSS3: 5.3 | 0% Низкий | около 1 года назад | |
GHSA-398w-ffjm-vc8f websitebaker prior to and including 2.8.1 has an authentication error in backup module. | CVSS3: 7.5 | 0% Низкий | почти 4 года назад | |
GHSA-398w-8vvx-7rh5 An issue was discovered in /bin/goahead on D-Link DIR-823G devices with firmware 1.02B03. There is incorrect access control allowing remote attackers to get sensitive information (such as MAC address) about all clients in the WLAN via the GetClientInfo HNAP API. Consequently, an attacker can achieve information disclosure without authentication. | CVSS3: 7.5 | 2% Низкий | больше 3 лет назад | |
GHSA-398v-cx4g-hhxc In the Linux kernel, the following vulnerability has been resolved: Bluetooth: msft: Fix memory leak Fix leaking buffer allocated to send MSFT_OP_LE_MONITOR_ADVERTISEMENT. | CVSS3: 5.5 | 0% Низкий | почти 2 года назад | |
GHSA-398v-9vhq-3gg5 Insufficient input validation in Intel(R) Active Management Technology (Intel(R) AMT) before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20 may allow an unauthenticated user to potentially cause a denial of service via network access. | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
GHSA-398v-9qw7-49xj SQL injection vulnerability in the libpam-pgsql library before 0.5.2 allows attackers to execute arbitrary SQL statements. | 1% Низкий | почти 4 года назад | ||
GHSA-398v-5g69-w972 IBM Aspera Faspex 4.4.1 and 5.0.0 could allow unauthorized access due to an incorrectly computed security token. IBM X-Force ID: 226951. | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
GHSA-398r-g5cv-mwh7 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Satos Satos Mobile allows SQL Injection through SOAP Parameter Tampering.This issue affects Satos Mobile: before 20230607. | CVSS3: 9.8 | 0% Низкий | больше 2 лет назад |
Уязвимостей на страницу