Количество 314 458
Количество 314 458
GHSA-33mm-7q99-mpgc
An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service agents could allow a local attacker to escalate privileges on affected installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
GHSA-33mj-c75m-m568
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.adminlog.php.
GHSA-33mh-qwc8-jxxx
A heap-based buffer overflow vulnerability exists in the vpnserver WpcParsePacket() functionality of SoftEther VPN 4.41-9782-beta, 5.01.9674 and 5.02. A specially crafted network packet can lead to arbitrary code execution. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.
GHSA-33mh-74gh-7rp5
Improper validation of maximum size of data write to EFS file can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables
GHSA-33mh-4657-92h5
Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.2.
GHSA-33mg-w6qx-r88m
Huawei DP300 V500R002C00, RP200 V500R002C00, V600R006C00, TE30 V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00, V600R006C00, TE50 V500R002C00, V600R006C00, TE60 V100R001C10, V500R002C00, V600R006C00 have a out-of-bounds read vulnerability. Due to insufficient input validation, an authenticated, remote attacker could send malformed SOAP packets to the target device. Successful exploit could make the device access invalid memory and might reset a process.
GHSA-33mg-r278-fh2j
Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to execute arbitrary OS commands by navigating to the Diagnostics Ping page and entering shell metacharacters in the Target IP address field. (In some cases, authentication can be achieved with the comtech password for the comtech account.)
GHSA-33mf-x5r5-qqmj
TPview.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mode before 5.4.2 on Windows does not properly allocate memory, which allows guest OS users to cause a host OS denial of service via unspecified vectors, a different vulnerability than CVE-2015-2339.
GHSA-33mf-v24m-432m
In Dell EMC Isilon OneFS, the compadmin is able to run tcpdump binary with root privileges. In versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, the tcpdump binary, being run with sudo, may potentially be used by compadmin to execute arbitrary code with root privileges.
GHSA-33mf-fw4p-7m8h
The frame scheduling module has a Use After Free (UAF) vulnerability.Successful exploitation of this vulnerability will affect data integrity, availability, and confidentiality.
GHSA-33mf-f48h-g743
Multiple cross-site scripting (XSS) vulnerabilities in Yblog allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter in (a) funk.php, or the (2) action parameter in (b) tem.php and (c) uss.php.
GHSA-33m9-pm4r-23hx
Race condition in Apple iOS 4.0 through 4.1 for iPhone 3G and later allows physically proximate attackers to bypass the passcode lock by making a call from the Emergency Call screen, then quickly pressing the Sleep/Wake button.
GHSA-33m9-pfw5-gmf2
In Xiaomi router R3600, ROM version<1.0.20, the connection service can be injected through the web interface, resulting in stack overflow or remote code execution.
GHSA-33m8-f4hw-wm3q
usememos/memos Denial of Service vulnerability
GHSA-33m7-qmp2-vj6x
ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/ URI.
GHSA-33m7-2r3h-jgfx
Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally.
GHSA-33m6-wpwp-3cw5
Multiple unspecified vulnerabilities in the Vsftpd Webmin module before 1.3b for the Vsftpd server have unknown impact and attack vectors related to "Some security issues."
GHSA-33m6-q9v5-62r7
go.uuid has Predictable UUID Identifiers
GHSA-33m5-rgm6-r8x3
Microsoft Business Central Information Disclosure Vulnerability.
GHSA-33m4-frvp-3wr7
An information disclosure vulnerability in Web Vulnerability Scan profile of Fortinet's FortiWeb version 6.2.x below 6.2.4 and version 6.3.x below 6.3.5 may allow a remote authenticated attacker to read the password used by the FortiWeb scanner to access the device defined in the scan profile.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-33mm-7q99-mpgc An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service agents could allow a local attacker to escalate privileges on affected installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | 0% Низкий | больше 3 лет назад | ||
GHSA-33mj-c75m-m568 In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.adminlog.php. | CVSS3: 8.8 | 0% Низкий | больше 3 лет назад | |
GHSA-33mh-qwc8-jxxx A heap-based buffer overflow vulnerability exists in the vpnserver WpcParsePacket() functionality of SoftEther VPN 4.41-9782-beta, 5.01.9674 and 5.02. A specially crafted network packet can lead to arbitrary code execution. An attacker can perform a man-in-the-middle attack to trigger this vulnerability. | CVSS3: 9 | 1% Низкий | больше 2 лет назад | |
GHSA-33mh-74gh-7rp5 Improper validation of maximum size of data write to EFS file can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables | 0% Низкий | почти 4 года назад | ||
GHSA-33mh-4657-92h5 Cross-site Scripting (XSS) - Reflected in GitHub repository openemr/openemr prior to 7.0.0.2. | CVSS3: 6.1 | 4% Низкий | около 3 лет назад | |
GHSA-33mg-w6qx-r88m Huawei DP300 V500R002C00, RP200 V500R002C00, V600R006C00, TE30 V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00, V600R006C00, TE50 V500R002C00, V600R006C00, TE60 V100R001C10, V500R002C00, V600R006C00 have a out-of-bounds read vulnerability. Due to insufficient input validation, an authenticated, remote attacker could send malformed SOAP packets to the target device. Successful exploit could make the device access invalid memory and might reset a process. | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад | |
GHSA-33mg-r278-fh2j Comtech Stampede FX-1010 7.4.3 devices allow remote authenticated administrators to execute arbitrary OS commands by navigating to the Diagnostics Ping page and entering shell metacharacters in the Target IP address field. (In some cases, authentication can be achieved with the comtech password for the comtech account.) | CVSS3: 7.2 | 2% Низкий | больше 3 лет назад | |
GHSA-33mf-x5r5-qqmj TPview.dll in VMware Workstation 10.x before 10.0.6 and 11.x before 11.1.1, VMware Player 6.x before 6.0.6 and 7.x before 7.1.1, and VMware Horizon Client 3.2.x before 3.2.1, 3.3.x, and 5.x local-mode before 5.4.2 on Windows does not properly allocate memory, which allows guest OS users to cause a host OS denial of service via unspecified vectors, a different vulnerability than CVE-2015-2339. | 0% Низкий | больше 3 лет назад | ||
GHSA-33mf-v24m-432m In Dell EMC Isilon OneFS, the compadmin is able to run tcpdump binary with root privileges. In versions between 8.1.0.0 - 8.1.0.1, 8.0.1.0 - 8.0.1.2, and 8.0.0.0 - 8.0.0.6, the tcpdump binary, being run with sudo, may potentially be used by compadmin to execute arbitrary code with root privileges. | CVSS3: 6.7 | 1% Низкий | больше 3 лет назад | |
GHSA-33mf-fw4p-7m8h The frame scheduling module has a Use After Free (UAF) vulnerability.Successful exploitation of this vulnerability will affect data integrity, availability, and confidentiality. | CVSS3: 9.8 | 0% Низкий | больше 3 лет назад | |
GHSA-33mf-f48h-g743 Multiple cross-site scripting (XSS) vulnerabilities in Yblog allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter in (a) funk.php, or the (2) action parameter in (b) tem.php and (c) uss.php. | 1% Низкий | почти 4 года назад | ||
GHSA-33m9-pm4r-23hx Race condition in Apple iOS 4.0 through 4.1 for iPhone 3G and later allows physically proximate attackers to bypass the passcode lock by making a call from the Emergency Call screen, then quickly pressing the Sleep/Wake button. | 0% Низкий | больше 3 лет назад | ||
GHSA-33m9-pfw5-gmf2 In Xiaomi router R3600, ROM version<1.0.20, the connection service can be injected through the web interface, resulting in stack overflow or remote code execution. | 2% Низкий | больше 3 лет назад | ||
GHSA-33m8-f4hw-wm3q usememos/memos Denial of Service vulnerability | CVSS3: 7.5 | 0% Низкий | около 3 лет назад | |
GHSA-33m7-qmp2-vj6x ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/ URI. | 0% Низкий | больше 3 лет назад | ||
GHSA-33m7-2r3h-jgfx Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information locally. | CVSS3: 5.5 | 0% Низкий | 11 месяцев назад | |
GHSA-33m6-wpwp-3cw5 Multiple unspecified vulnerabilities in the Vsftpd Webmin module before 1.3b for the Vsftpd server have unknown impact and attack vectors related to "Some security issues." | 0% Низкий | почти 4 года назад | ||
GHSA-33m6-q9v5-62r7 go.uuid has Predictable UUID Identifiers | CVSS3: 9.8 | 0% Низкий | около 3 лет назад | |
GHSA-33m5-rgm6-r8x3 Microsoft Business Central Information Disclosure Vulnerability. | CVSS3: 4.4 | 2% Низкий | около 3 лет назад | |
GHSA-33m4-frvp-3wr7 An information disclosure vulnerability in Web Vulnerability Scan profile of Fortinet's FortiWeb version 6.2.x below 6.2.4 and version 6.3.x below 6.3.5 may allow a remote authenticated attacker to read the password used by the FortiWeb scanner to access the device defined in the scan profile. | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу