Количество 314 458
Количество 314 458
GHSA-2x38-j7v9-v23r
Unchecked output buffer may allowed arbitrary code execution in SMM and potentially result in SMM memory corruption.
GHSA-2x38-f53p-2wp3
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile, Snapdragon Wear, and Small Cell SoC FSM9055, MDM9206, MDM9607, MDM9635M, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 808, SD 810, and SD 835, improper input validation can occur while parsing an image.
GHSA-2x38-7mv7-h86v
A CWE-20: Improper Input Validation vulnerability exists that could cause potential remote code execution when an attacker is able to intercept and modify a request on the same network or has configuration access to an ION device on the network. Affected Products: Wiser Smart, EER21000 & EER21001 (V4.5 and prior)
GHSA-2x38-48vp-w23x
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.2.11, FortiManager 7.0.0 through 7.0.15, FortiOS 7.6.0 through 7.6.5, FortiOS 7.4.0 through 7.4.10, FortiOS 7.2.0 through 7.2.12, FortiOS 7.0.0 through 7.0.18 may allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices.
GHSA-2x37-xp38-hq9m
A cross site scripting (XSS) vulnerability on ASUS RT-AC58U 3.0.0.4.380_6516 devices allows remote attackers to inject arbitrary web script or HTML via Advanced_ASUSDDNS_Content.asp, Advanced_WSecurity_Content.asp, Advanced_Wireless_Content.asp, Logout.asp, Main_Login.asp, MobileQIS_Login.asp, QIS_wizard.htma, YandexDNS.asp, ajax_status.xml, apply.cgi, clients.asp, disk.asp, disk_utility.asp, or internet.asp.
GHSA-2x37-ffq7-5322
MonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the `people:id/relationships` endpoint and first_name and last_name parameter.
GHSA-2x36-vr7v-9hpm
Incorrect default permissions in the Intel(R) ITS sofware before version 3.1 may allow authenticated user to potentially enable escalation of privilege via local access.
GHSA-2x36-qhx3-7m5f
ZendFramework1 Potential SQL injection in the ORDER implementation of Zend_Db_Select
GHSA-2x36-7xfm-pgm7
Moodle default permissions too permissive
GHSA-2x35-j3p2-5qfh
A vulnerability in the Cisco Intercloud Fabric (ICF) Director could allow an unauthenticated, remote attacker to connect to internal services with an internal account. Affected Products: Cisco Nexus 1000V InterCloud is affected. More Information: CSCus99379. Known Affected Releases: 2.2(1).
GHSA-2x35-3575-64cp
Vulnerability of signature verification in the iaware system being initialized later than the time when the system broadcasts are sent. Successful exploitation of this vulnerability may cause malicious apps to start upon power-on by spoofing the package names of apps in the startup trustlist, which affects system performance.
GHSA-2x34-p5xr-4cq8
User enumeration in Nagvis' Checkmk MultisiteAuth before version 1.9.48 allows an unauthenticated attacker to enumerate Checkmk usernames.
GHSA-2x34-7fj8-wmcv
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0060, CVE-2016-0063, CVE-2016-0067, and CVE-2016-0072.
GHSA-2x34-356c-v9qp
TeamViewer before 14.7.48644 on Windows loads untrusted DLLs in certain situations.
GHSA-2x33-pfvq-675c
The 'Your Name' field in the Submit Score section of Sourcecodester Math Game with Leaderboard v1.0 is vulnerable to Cross-Site Scripting (XSS) attacks.
GHSA-2x32-mwgm-xpr7
Directory Traversal in the function SSL_accept in nostromo nhttpd through 1.9.6 allows an attacker to trigger a denial of service via a crafted HTTP request.
GHSA-2x32-jv72-rchp
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nicholaswilson Graceful Email Obfuscation allows Stored XSS. This issue affects Graceful Email Obfuscation: from n/a through 0.2.2.
GHSA-2x32-jm95-2cpx
Authentication Bypass in dex
GHSA-2x32-fffh-53mr
KVM in the Linux kernel before 4.8.12, when I/O APIC is enabled, does not properly restrict the VCPU index, which allows guest OS users to gain host OS privileges or cause a denial of service (out-of-bounds array access and host OS crash) via a crafted interrupt request, related to arch/x86/kvm/ioapic.c and arch/x86/kvm/ioapic.h.
GHSA-2x32-727m-44f2
Denial of service in Linux 2.2.0 running the ldd command on a core file.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2x38-j7v9-v23r Unchecked output buffer may allowed arbitrary code execution in SMM and potentially result in SMM memory corruption. | CVSS3: 8.2 | 0% Низкий | около 2 месяцев назад | |
GHSA-2x38-f53p-2wp3 In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile, Snapdragon Wear, and Small Cell SoC FSM9055, MDM9206, MDM9607, MDM9635M, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 617, SD 625, SD 650/52, SD 800, SD 808, SD 810, and SD 835, improper input validation can occur while parsing an image. | CVSS3: 9.8 | 0% Низкий | больше 3 лет назад | |
GHSA-2x38-7mv7-h86v A CWE-20: Improper Input Validation vulnerability exists that could cause potential remote code execution when an attacker is able to intercept and modify a request on the same network or has configuration access to an ION device on the network. Affected Products: Wiser Smart, EER21000 & EER21001 (V4.5 and prior) | CVSS3: 8.8 | 1% Низкий | больше 3 лет назад | |
GHSA-2x38-48vp-w23x An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9, FortiManager 7.2.0 through 7.2.11, FortiManager 7.0.0 through 7.0.15, FortiOS 7.6.0 through 7.6.5, FortiOS 7.4.0 through 7.4.10, FortiOS 7.2.0 through 7.2.12, FortiOS 7.0.0 through 7.0.18 may allow an attacker with a FortiCloud account and a registered device to log into other devices registered to other accounts, if FortiCloud SSO authentication is enabled on those devices. | CVSS3: 9.8 | 3% Низкий | 12 дней назад | |
GHSA-2x37-xp38-hq9m A cross site scripting (XSS) vulnerability on ASUS RT-AC58U 3.0.0.4.380_6516 devices allows remote attackers to inject arbitrary web script or HTML via Advanced_ASUSDDNS_Content.asp, Advanced_WSecurity_Content.asp, Advanced_Wireless_Content.asp, Logout.asp, Main_Login.asp, MobileQIS_Login.asp, QIS_wizard.htma, YandexDNS.asp, ajax_status.xml, apply.cgi, clients.asp, disk.asp, disk_utility.asp, or internet.asp. | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-2x37-ffq7-5322 MonicaHQ version 4.0.0 allows an authenticated remote attacker to execute malicious code in the application via CSTI in the `people:id/relationships` endpoint and first_name and last_name parameter. | CVSS3: 5.4 | 0% Низкий | больше 2 лет назад | |
GHSA-2x36-vr7v-9hpm Incorrect default permissions in the Intel(R) ITS sofware before version 3.1 may allow authenticated user to potentially enable escalation of privilege via local access. | CVSS3: 6.7 | 0% Низкий | больше 2 лет назад | |
GHSA-2x36-qhx3-7m5f ZendFramework1 Potential SQL injection in the ORDER implementation of Zend_Db_Select | CVSS3: 9.8 | больше 1 года назад | ||
GHSA-2x36-7xfm-pgm7 Moodle default permissions too permissive | CVSS3: 4.3 | 1% Низкий | почти 4 года назад | |
GHSA-2x35-j3p2-5qfh A vulnerability in the Cisco Intercloud Fabric (ICF) Director could allow an unauthenticated, remote attacker to connect to internal services with an internal account. Affected Products: Cisco Nexus 1000V InterCloud is affected. More Information: CSCus99379. Known Affected Releases: 2.2(1). | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад | |
GHSA-2x35-3575-64cp Vulnerability of signature verification in the iaware system being initialized later than the time when the system broadcasts are sent. Successful exploitation of this vulnerability may cause malicious apps to start upon power-on by spoofing the package names of apps in the startup trustlist, which affects system performance. | CVSS3: 5.5 | 0% Низкий | больше 2 лет назад | |
GHSA-2x34-p5xr-4cq8 User enumeration in Nagvis' Checkmk MultisiteAuth before version 1.9.48 allows an unauthenticated attacker to enumerate Checkmk usernames. | CVSS3: 5.3 | 0% Низкий | 2 месяца назад | |
GHSA-2x34-7fj8-wmcv Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0060, CVE-2016-0063, CVE-2016-0067, and CVE-2016-0072. | CVSS3: 8.8 | 17% Средний | больше 3 лет назад | |
GHSA-2x34-356c-v9qp TeamViewer before 14.7.48644 on Windows loads untrusted DLLs in certain situations. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-2x33-pfvq-675c The 'Your Name' field in the Submit Score section of Sourcecodester Math Game with Leaderboard v1.0 is vulnerable to Cross-Site Scripting (XSS) attacks. | CVSS3: 6.1 | 1% Низкий | около 2 лет назад | |
GHSA-2x32-mwgm-xpr7 Directory Traversal in the function SSL_accept in nostromo nhttpd through 1.9.6 allows an attacker to trigger a denial of service via a crafted HTTP request. | CVSS3: 7.5 | 90% Критический | больше 3 лет назад | |
GHSA-2x32-jv72-rchp Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nicholaswilson Graceful Email Obfuscation allows Stored XSS. This issue affects Graceful Email Obfuscation: from n/a through 0.2.2. | CVSS3: 6.5 | 0% Низкий | около 1 года назад | |
GHSA-2x32-jm95-2cpx Authentication Bypass in dex | CVSS3: 9.8 | 0% Низкий | около 4 лет назад | |
GHSA-2x32-fffh-53mr KVM in the Linux kernel before 4.8.12, when I/O APIC is enabled, does not properly restrict the VCPU index, which allows guest OS users to gain host OS privileges or cause a denial of service (out-of-bounds array access and host OS crash) via a crafted interrupt request, related to arch/x86/kvm/ioapic.c and arch/x86/kvm/ioapic.h. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-2x32-727m-44f2 Denial of service in Linux 2.2.0 running the ldd command on a core file. | 1% Низкий | почти 4 года назад |
Уязвимостей на страницу