Количество 314 928
Количество 314 928
GHSA-363q-mrhx-5q4w
Rejected reason: Not used
GHSA-363q-j92x-7543
Snipe-IT vulnerable to Cross Site Scripting for View Assigned Assets
GHSA-363q-g58w-9xvh
IBM Rational DOORS Next Generation 5.0 and 6.0 discloses sensitive information in error response messages that could be used for further attacks against the system.
GHSA-363q-54cj-prgf
Pacemaker before 1.1.6 configure script creates temporary files insecurely
GHSA-363p-mgpx-cphf
nslookup.exe in Microsoft Windows XP SP2 allows user-assisted remote attackers to execute arbitrary code, as demonstrated by an attempted DNS zone transfer, and as exploited in the wild in August 2008.
GHSA-363m-v2j8-gf6w
Multiple unspecified vulnerabilities in FFmpeg 0.4.x through 0.6.x, as used in MPlayer 1.0 and other products, in Mandriva Linux 2009.0, 2010.0, and 2010.1; Corporate Server 4.0 (aka CS4.0); and Mandriva Enterprise Server 5 (aka MES5) have unknown impact and attack vectors, related to issues "originally discovered by Google Chrome developers."
GHSA-363m-j8q4-hfrx
Unspecified vulnerability in Oracle Secure Backup 10.3.0.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.
GHSA-363m-f7wv-qpfm
Flatnotes <v5.3.1 is vulnerable to denial of service through the upload image function.
GHSA-363m-9h8j-6gw4
Cisco IOS 9.1 and earlier does not properly handle extended IP access lists when the IP route cache is enabled and the "established" keyword is set, which could allow attackers to bypass filters.
GHSA-363m-3jp4-qg24
Themify WordPress plugin before 1.4.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin
GHSA-363j-w49v-cj57
Directory traversal vulnerability in the File Manager component in DevExpress ASPxFileManager Control for ASP.NET WebForms and MVC before 13.1.10 and 13.2.x before 13.2.9 allows remote authenticated users to read or write arbitrary files via a .. (dot dot) in the __EVENTARGUMENT parameter.
GHSA-363j-9xx8-29r4
Use after free in audio in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
GHSA-363j-7w3w-3w9g
A vulnerability in the web portal of the Cisco Prime Collaboration Provisioning Tool could allow an unauthenticated, remote attacker to create a denial of service (DoS) condition for individual users. The vulnerability is due to weak login controls. An attacker could exploit this vulnerability by using a brute-force attack (Repeated Bad Login Attempts). A successful exploit could allow the attacker to restrict user access. Manual administrative intervention is required to restore access. Cisco Bug IDs: CSCvd07264.
GHSA-363j-27mr-4whg
Multiple memory leaks in the DataGrid control implementation in Microsoft Silverlight 4 before 4.0.60310.0 allow remote attackers to cause a denial of service (memory consumption) via an application involving (1) subscriptions to an INotifyDataErrorInfo.ErrorsChanged event or (2) a TextBlock or TextBox element.
GHSA-363h-vj6q-3cmj
Rosetta-Flash JSONP Vulnerability in hapi
GHSA-363h-22w6-hcrm
Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail attachment. For ESG 5.0 a fix has been released in 5.0.31. For ESG 5.1 a fix has been released in 5.1.20. For ESG 5.2 a fix has been released in 5.2.31. For ESG 5.4 a fix has been released in 5.4.8. For ESG 5.5. a fix has been released in 5.5.7.
GHSA-363g-vch7-x5j4
In lsx_aiffstartread in aiff.c in Sound eXchange (SoX) 14.4.2, there is a Use-After-Free vulnerability triggered by supplying a malformed AIFF file.
GHSA-363f-hg5g-qwpf
A vulnerability classified as critical was found in Project Worlds Car Rental Project 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/approve.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
GHSA-363f-897q-jph9
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FolioVision FV Antispam fv-antispam allows Reflected XSS.This issue affects FV Antispam: from n/a through <= 2.7.
GHSA-363f-7q84-2cr6
A permissions issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.5. A malicious application may be able to access data about the accounts the user is using Family Sharing with.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-363q-mrhx-5q4w Rejected reason: Not used | 10 месяцев назад | |||
GHSA-363q-j92x-7543 Snipe-IT vulnerable to Cross Site Scripting for View Assigned Assets | CVSS3: 5.4 | 0% Низкий | около 3 лет назад | |
GHSA-363q-g58w-9xvh IBM Rational DOORS Next Generation 5.0 and 6.0 discloses sensitive information in error response messages that could be used for further attacks against the system. | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад | |
GHSA-363q-54cj-prgf Pacemaker before 1.1.6 configure script creates temporary files insecurely | CVSS3: 5.5 | 0% Низкий | почти 4 года назад | |
GHSA-363p-mgpx-cphf nslookup.exe in Microsoft Windows XP SP2 allows user-assisted remote attackers to execute arbitrary code, as demonstrated by an attempted DNS zone transfer, and as exploited in the wild in August 2008. | 41% Средний | почти 4 года назад | ||
GHSA-363m-v2j8-gf6w Multiple unspecified vulnerabilities in FFmpeg 0.4.x through 0.6.x, as used in MPlayer 1.0 and other products, in Mandriva Linux 2009.0, 2010.0, and 2010.1; Corporate Server 4.0 (aka CS4.0); and Mandriva Enterprise Server 5 (aka MES5) have unknown impact and attack vectors, related to issues "originally discovered by Google Chrome developers." | 1% Низкий | больше 3 лет назад | ||
GHSA-363m-j8q4-hfrx Unspecified vulnerability in Oracle Secure Backup 10.3.0.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors. | 0% Низкий | почти 4 года назад | ||
GHSA-363m-f7wv-qpfm Flatnotes <v5.3.1 is vulnerable to denial of service through the upload image function. | CVSS3: 7.5 | 0% Низкий | около 1 года назад | |
GHSA-363m-9h8j-6gw4 Cisco IOS 9.1 and earlier does not properly handle extended IP access lists when the IP route cache is enabled and the "established" keyword is set, which could allow attackers to bypass filters. | 0% Низкий | почти 4 года назад | ||
GHSA-363m-3jp4-qg24 Themify WordPress plugin before 1.4.4 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | CVSS3: 4.8 | 0% Низкий | почти 2 года назад | |
GHSA-363j-w49v-cj57 Directory traversal vulnerability in the File Manager component in DevExpress ASPxFileManager Control for ASP.NET WebForms and MVC before 13.1.10 and 13.2.x before 13.2.9 allows remote authenticated users to read or write arbitrary files via a .. (dot dot) in the __EVENTARGUMENT parameter. | 10% Низкий | больше 3 лет назад | ||
GHSA-363j-9xx8-29r4 Use after free in audio in Google Chrome prior to 87.0.4280.141 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. | 1% Низкий | больше 3 лет назад | ||
GHSA-363j-7w3w-3w9g A vulnerability in the web portal of the Cisco Prime Collaboration Provisioning Tool could allow an unauthenticated, remote attacker to create a denial of service (DoS) condition for individual users. The vulnerability is due to weak login controls. An attacker could exploit this vulnerability by using a brute-force attack (Repeated Bad Login Attempts). A successful exploit could allow the attacker to restrict user access. Manual administrative intervention is required to restore access. Cisco Bug IDs: CSCvd07264. | CVSS3: 7.5 | 2% Низкий | больше 3 лет назад | |
GHSA-363j-27mr-4whg Multiple memory leaks in the DataGrid control implementation in Microsoft Silverlight 4 before 4.0.60310.0 allow remote attackers to cause a denial of service (memory consumption) via an application involving (1) subscriptions to an INotifyDataErrorInfo.ErrorsChanged event or (2) a TextBlock or TextBox element. | 20% Средний | больше 3 лет назад | ||
GHSA-363h-vj6q-3cmj Rosetta-Flash JSONP Vulnerability in hapi | 36% Средний | больше 5 лет назад | ||
GHSA-363h-22w6-hcrm Libraesva ESG 4.5 through 5.5.x before 5.5.7 allows command injection via a compressed e-mail attachment. For ESG 5.0 a fix has been released in 5.0.31. For ESG 5.1 a fix has been released in 5.1.20. For ESG 5.2 a fix has been released in 5.2.31. For ESG 5.4 a fix has been released in 5.4.8. For ESG 5.5. a fix has been released in 5.5.7. | CVSS3: 6.1 | 5% Низкий | 5 месяцев назад | |
GHSA-363g-vch7-x5j4 In lsx_aiffstartread in aiff.c in Sound eXchange (SoX) 14.4.2, there is a Use-After-Free vulnerability triggered by supplying a malformed AIFF file. | CVSS3: 5.5 | 1% Низкий | больше 3 лет назад | |
GHSA-363f-hg5g-qwpf A vulnerability classified as critical was found in Project Worlds Car Rental Project 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/approve.php. The manipulation of the argument ID leads to sql injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 7.3 | 0% Низкий | 9 месяцев назад | |
GHSA-363f-897q-jph9 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FolioVision FV Antispam fv-antispam allows Reflected XSS.This issue affects FV Antispam: from n/a through <= 2.7. | CVSS3: 7.5 | 0% Низкий | около 2 месяцев назад | |
GHSA-363f-7q84-2cr6 A permissions issue was addressed with improved validation. This issue is fixed in macOS Big Sur 11.5. A malicious application may be able to access data about the accounts the user is using Family Sharing with. | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу