Количество 314 458
Количество 314 458
GHSA-2xq2-3g36-329g
Possible memory corruption in BSI module due to improper validation of parameter count in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Mobile
GHSA-2xq2-2q9r-hfmv
Cross-site scripting (XSS) vulnerability in Antville 1.1 allows remote attackers to inject arbitrary web script or HTML via the notfound.skin error document.
GHSA-2xpx-vcmq-5f72
Unlimited number of NTS-KE connections can crash ntpd-rs server
GHSA-2xpw-w6gg-jr37
urllib3 streaming API improperly handles highly compressed data
GHSA-2xpw-9gj4-3f8g
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083.
GHSA-2xpv-7mpx-xj47
FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6976, CVE-2015-6977, CVE-2015-6978, CVE-2015-6990, CVE-2015-6991, CVE-2015-6993, CVE-2015-7008, CVE-2015-7009, and CVE-2015-7010.
GHSA-2xpr-684m-v738
Unspecified vulnerability in the Oracle Email Center component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect integrity via vectors related to Email Center Agent Console, a different vulnerability than CVE-2016-3559.
GHSA-2xpr-38wh-m8g5
Incorrect access control in the /mysql/api/droboapp/data endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve the MySQL database root password.
GHSA-2xpq-xp6c-5mgj
Contao affected by insert tag injection via canonical URL
GHSA-2xpq-p284-h385
Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used.
GHSA-2xpq-5952-38w3
Jenkins MSTeams Webhook Trigger Plugin uses non-constant time webhook token comparison
GHSA-2xpp-rgp2-5r6f
A vulnerability was found in master-nan Sweet-CMS up to 5f441e022b8876f07cde709c77b5be6d2f262e3f. It has been declared as critical. This vulnerability affects unknown code of the file /table/index. The manipulation leads to sql injection. The attack can be initiated remotely. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The name of the patch is 146359646a5a90cb09156dbd0013b7df77f2aa6c. It is recommended to apply a patch to fix this issue.
GHSA-2xpp-qx4m-56h3
Watchguard Firebox II firewall allows users with read-only access to gain read-write access, and administrative privileges, by accessing a file that contains hashed passphrases, and using the hashes during authentication.
GHSA-2xpp-q4gq-7cc3
The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apache HTTP Server before 2.4.8 does not properly remove whitespace characters from CDATA sections, which allows remote attackers to cause a denial of service (daemon crash) via a crafted DAV WRITE request.
GHSA-2xpp-75vr-22vq
Improper Restriction of Rendered UI Layers or Frames in Apache nifif
GHSA-2xpm-w5mr-rm8m
Xen 4.2.x and 4.3.x, when using Intel VT-d for PCI passthrough, does not properly flush the TLB after clearing a present translation table entry, which allows local guest administrators to cause a denial of service or gain privileges via unspecified vectors related to an "inverted boolean parameter."
GHSA-2xpm-cmvw-3jcc
Reflected XSS in Application Logger module
GHSA-2xpj-rm54-gp8w
XSS vulnerability in htdocs/webinc/body/bsc_sms_send.php in D-Link DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-865L DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions, and DIR-860L DIR860LA1_FW110b04 and previous versions allows remote attackers to read a cookie via a crafted receiver parameter to soap.cgi.
GHSA-2xpj-f5g2-8p7m
Asyncpg Arbitrary Code Execution Via Access to an Uninitialized Pointer
GHSA-2xpj-7m85-mm88
Missing Authorization vulnerability in Themeum WP Crowdfunding allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Crowdfunding: from n/a through 2.1.10.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2xq2-3g36-329g Possible memory corruption in BSI module due to improper validation of parameter count in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Mobile | 0% Низкий | больше 3 лет назад | ||
GHSA-2xq2-2q9r-hfmv Cross-site scripting (XSS) vulnerability in Antville 1.1 allows remote attackers to inject arbitrary web script or HTML via the notfound.skin error document. | 1% Низкий | почти 4 года назад | ||
GHSA-2xpx-vcmq-5f72 Unlimited number of NTS-KE connections can crash ntpd-rs server | CVSS3: 7.5 | 0% Низкий | больше 1 года назад | |
GHSA-2xpw-w6gg-jr37 urllib3 streaming API improperly handles highly compressed data | 0% Низкий | 2 месяца назад | ||
GHSA-2xpw-9gj4-3f8g Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsoft Internet Explorer 10 and 11 and Microsoft Edge, has unknown impact and attack vectors, a different vulnerability than other CVEs listed in MS16-083. | CVSS3: 8.8 | 4% Низкий | больше 3 лет назад | |
GHSA-2xpv-7mpx-xj47 FontParser in Apple iOS before 9.1 and OS X before 10.11.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted font file, a different vulnerability than CVE-2015-6976, CVE-2015-6977, CVE-2015-6978, CVE-2015-6990, CVE-2015-6991, CVE-2015-6993, CVE-2015-7008, CVE-2015-7009, and CVE-2015-7010. | 2% Низкий | больше 3 лет назад | ||
GHSA-2xpr-684m-v738 Unspecified vulnerability in the Oracle Email Center component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect integrity via vectors related to Email Center Agent Console, a different vulnerability than CVE-2016-3559. | CVSS3: 4.7 | 0% Низкий | больше 3 лет назад | |
GHSA-2xpr-38wh-m8g5 Incorrect access control in the /mysql/api/droboapp/data endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to retrieve the MySQL database root password. | CVSS3: 9.8 | 2% Низкий | больше 3 лет назад | |
GHSA-2xpq-xp6c-5mgj Contao affected by insert tag injection via canonical URL | CVSS3: 5.3 | 1% Низкий | больше 1 года назад | |
GHSA-2xpq-p284-h385 Rejected reason: To maintain compliance with CNA rules, we have rejected this CVE record because it has not been used. | около 1 года назад | |||
GHSA-2xpq-5952-38w3 Jenkins MSTeams Webhook Trigger Plugin uses non-constant time webhook token comparison | CVSS3: 3.7 | 0% Низкий | больше 2 лет назад | |
GHSA-2xpp-rgp2-5r6f A vulnerability was found in master-nan Sweet-CMS up to 5f441e022b8876f07cde709c77b5be6d2f262e3f. It has been declared as critical. This vulnerability affects unknown code of the file /table/index. The manipulation leads to sql injection. The attack can be initiated remotely. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The name of the patch is 146359646a5a90cb09156dbd0013b7df77f2aa6c. It is recommended to apply a patch to fix this issue. | CVSS3: 6.3 | 0% Низкий | больше 1 года назад | |
GHSA-2xpp-qx4m-56h3 Watchguard Firebox II firewall allows users with read-only access to gain read-write access, and administrative privileges, by accessing a file that contains hashed passphrases, and using the hashes during authentication. | 0% Низкий | почти 4 года назад | ||
GHSA-2xpp-q4gq-7cc3 The dav_xml_get_cdata function in main/util.c in the mod_dav module in the Apache HTTP Server before 2.4.8 does not properly remove whitespace characters from CDATA sections, which allows remote attackers to cause a denial of service (daemon crash) via a crafted DAV WRITE request. | 47% Средний | больше 3 лет назад | ||
GHSA-2xpp-75vr-22vq Improper Restriction of Rendered UI Layers or Frames in Apache nifif | CVSS3: 6.5 | 0% Низкий | около 7 лет назад | |
GHSA-2xpm-w5mr-rm8m Xen 4.2.x and 4.3.x, when using Intel VT-d for PCI passthrough, does not properly flush the TLB after clearing a present translation table entry, which allows local guest administrators to cause a denial of service or gain privileges via unspecified vectors related to an "inverted boolean parameter." | 1% Низкий | больше 3 лет назад | ||
GHSA-2xpm-cmvw-3jcc Reflected XSS in Application Logger module | CVSS3: 4.8 | почти 3 года назад | ||
GHSA-2xpj-rm54-gp8w XSS vulnerability in htdocs/webinc/body/bsc_sms_send.php in D-Link DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-865L DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions, and DIR-860L DIR860LA1_FW110b04 and previous versions allows remote attackers to read a cookie via a crafted receiver parameter to soap.cgi. | CVSS3: 6.1 | 1% Низкий | больше 3 лет назад | |
GHSA-2xpj-f5g2-8p7m Asyncpg Arbitrary Code Execution Via Access to an Uninitialized Pointer | CVSS3: 9.8 | 2% Низкий | почти 5 лет назад | |
GHSA-2xpj-7m85-mm88 Missing Authorization vulnerability in Themeum WP Crowdfunding allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Crowdfunding: from n/a through 2.1.10. | CVSS3: 6.4 | 0% Низкий | больше 1 года назад |
Уязвимостей на страницу