Количество 314 458
Количество 314 458
GHSA-2jw5-w5pg-58h8
Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, 9.5 before 9.5.2-P1, 9.6 before 9.6.1-P2, and 9.7 beta before 9.7.0b3, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains an Additional section with crafted data, which is not properly handled when the response is processed "at the same time as requesting DNSSEC records (DO)," aka Bug 20438.
GHSA-2jw4-8qc2-wm33
File Upload vulnerability in openeclass v.3.15 and before allows an attacker to execute arbitrary code via a crafted file to the certbadge.php endpoint.
GHSA-2jw4-27vv-49jx
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Andy Moyle Church Admin.This issue affects Church Admin: from n/a through 4.0.27.
GHSA-2jw2-w8hc-jqch
An external config control vulnerability exists in the openvpn.cgi openvpn_client_setup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
GHSA-2jw2-fcpf-pj3x
When the isula export command is used to export a container to an image and the container is controlled by an attacker, the attacker can escape the container.
GHSA-2jw2-8v9p-h7mp
Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before build 80293 allows remote attackers to execute arbitrary code by uploading a file with a jsp extension, then accessing it via a direct request to the file in the webroot.
GHSA-2jw2-755p-5gqq
Digital Watchdog DW Spectrum Server 4.2.0.32842 allows attackers to access sensitive infromation via a crafted API call.
GHSA-2jvx-x849-7gfm
A vulnerability classified as critical was found in UTT HiPER 840G up to 3.1.1-190328. This vulnerability affects unknown code of the file /goform/websWhiteList. The manipulation of the argument addHostFilter leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
GHSA-2jvx-f9f6-89cv
Improper input validation for the Intel(R) Easy Streaming Wizard software may allow an authenticated user to potentially enable escalation of privilege via local access.
GHSA-2jvx-947v-x43p
Using XMLHttpRequest, an attacker could have identified installed applications by probing error messages for loading external protocols. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95.
GHSA-2jvx-42cx-5ggp
Audimexee v14.1.7 was discovered to contain a SQL injection vulnerability via the p_table_name parameter.
GHSA-2jvx-3h5f-w2j7
An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the user to access the ManageEngine product database.
GHSA-2jvw-hf8m-phpv
In the Linux kernel, the following vulnerability has been resolved: net: phy: xgmiitorgmii: Fix refcount leak in xgmiitorgmii_probe of_phy_find_device() return device node with refcount incremented. Call put_device() to relese it when not needed anymore.
GHSA-2jvw-9p97-g4qj
An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_genre in Kashipara Music Management System v1.0. This vulnerability allows an unauthenticated attacker to delete the valid music genre entries.
GHSA-2jvv-ppmq-fvgf
NCH Express Invoice 8.06 to 8.24 is vulnerable to Reflected XSS in the Quotes List module.
GHSA-2jvq-qwww-m6j5
The vhci_hcd driver in the Linux Kernel before version 4.14.8 and 4.4.114 allows allows local attackers to disclose kernel memory addresses. Successful exploitation requires that a USB device is attached over IP.
GHSA-2jvq-3rhr-97x9
Microsoft Office Graphics Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-38660.
GHSA-2jvp-r7m9-xhpr
An issue in account management interface in Netsweeper Server v.8.2.6 and earlier (fixed in v.8.2.7) allows unauthorized changes to the "Account Owner" field due to client-side-only restrictions and a lack of server-side validation. This vulnerability enables account ownership reassignment to or away from any user.
GHSA-2jvm-wg52-7h4f
ilbo App (ilbo App for Android prior to version 1.1.8 and ilbo App for iOS prior to version 1.2.01) allows an attacker on the same network segment to bypass authentication and to view the images which were recorded by the other ilbo user's device via unspecified vectors.
GHSA-2jvm-jgg9-h383
Out-of-bounds array write in Xpdf 4.05 and earlier, due to incorrect integer overflow checking in the PostScript function interpreter code.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2jw5-w5pg-58h8 Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, 9.5 before 9.5.2-P1, 9.6 before 9.6.1-P2, and 9.7 beta before 9.7.0b3, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains an Additional section with crafted data, which is not properly handled when the response is processed "at the same time as requesting DNSSEC records (DO)," aka Bug 20438. | 20% Средний | почти 4 года назад | ||
GHSA-2jw4-8qc2-wm33 File Upload vulnerability in openeclass v.3.15 and before allows an attacker to execute arbitrary code via a crafted file to the certbadge.php endpoint. | CVSS3: 9.8 | 30% Средний | больше 1 года назад | |
GHSA-2jw4-27vv-49jx Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Andy Moyle Church Admin.This issue affects Church Admin: from n/a through 4.0.27. | CVSS3: 8.5 | 0% Низкий | почти 2 года назад | |
GHSA-2jw2-w8hc-jqch An external config control vulnerability exists in the openvpn.cgi openvpn_client_setup() functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability. | CVSS3: 9.1 | 2% Низкий | около 1 года назад | |
GHSA-2jw2-fcpf-pj3x When the isula export command is used to export a container to an image and the container is controlled by an attacker, the attacker can escape the container. | CVSS3: 8.4 | 0% Низкий | больше 2 лет назад | |
GHSA-2jw2-8v9p-h7mp Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before build 80293 allows remote attackers to execute arbitrary code by uploading a file with a jsp extension, then accessing it via a direct request to the file in the webroot. | 67% Средний | почти 4 года назад | ||
GHSA-2jw2-755p-5gqq Digital Watchdog DW Spectrum Server 4.2.0.32842 allows attackers to access sensitive infromation via a crafted API call. | CVSS3: 7.5 | 29% Средний | больше 3 лет назад | |
GHSA-2jvx-x849-7gfm A vulnerability classified as critical was found in UTT HiPER 840G up to 3.1.1-190328. This vulnerability affects unknown code of the file /goform/websWhiteList. The manipulation of the argument addHostFilter leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 8.8 | 0% Низкий | 7 месяцев назад | |
GHSA-2jvx-f9f6-89cv Improper input validation for the Intel(R) Easy Streaming Wizard software may allow an authenticated user to potentially enable escalation of privilege via local access. | CVSS3: 7.8 | 0% Низкий | больше 2 лет назад | |
GHSA-2jvx-947v-x43p Using XMLHttpRequest, an attacker could have identified installed applications by probing error messages for loading external protocols. This vulnerability affects Thunderbird < 91.4.0, Firefox ESR < 91.4.0, and Firefox < 95. | CVSS3: 6.5 | 1% Низкий | около 4 лет назад | |
GHSA-2jvx-42cx-5ggp Audimexee v14.1.7 was discovered to contain a SQL injection vulnerability via the p_table_name parameter. | CVSS3: 9.8 | 0% Низкий | больше 2 лет назад | |
GHSA-2jvx-3h5f-w2j7 An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the user to access the ManageEngine product database. | CVSS3: 5.5 | 0% Низкий | около 2 лет назад | |
GHSA-2jvw-hf8m-phpv In the Linux kernel, the following vulnerability has been resolved: net: phy: xgmiitorgmii: Fix refcount leak in xgmiitorgmii_probe of_phy_find_device() return device node with refcount incremented. Call put_device() to relese it when not needed anymore. | 0% Низкий | около 2 месяцев назад | ||
GHSA-2jvw-9p97-g4qj An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_genre in Kashipara Music Management System v1.0. This vulnerability allows an unauthenticated attacker to delete the valid music genre entries. | CVSS3: 5.9 | 0% Низкий | больше 1 года назад | |
GHSA-2jvv-ppmq-fvgf NCH Express Invoice 8.06 to 8.24 is vulnerable to Reflected XSS in the Quotes List module. | 0% Низкий | больше 3 лет назад | ||
GHSA-2jvq-qwww-m6j5 The vhci_hcd driver in the Linux Kernel before version 4.14.8 and 4.4.114 allows allows local attackers to disclose kernel memory addresses. Successful exploitation requires that a USB device is attached over IP. | CVSS3: 4.7 | 0% Низкий | больше 3 лет назад | |
GHSA-2jvq-3rhr-97x9 Microsoft Office Graphics Remote Code Execution Vulnerability This CVE ID is unique from CVE-2021-38660. | CVSS3: 7.8 | 4% Низкий | больше 3 лет назад | |
GHSA-2jvp-r7m9-xhpr An issue in account management interface in Netsweeper Server v.8.2.6 and earlier (fixed in v.8.2.7) allows unauthorized changes to the "Account Owner" field due to client-side-only restrictions and a lack of server-side validation. This vulnerability enables account ownership reassignment to or away from any user. | CVSS3: 8.1 | 0% Низкий | 11 месяцев назад | |
GHSA-2jvm-wg52-7h4f ilbo App (ilbo App for Android prior to version 1.1.8 and ilbo App for iOS prior to version 1.2.01) allows an attacker on the same network segment to bypass authentication and to view the images which were recorded by the other ilbo user's device via unspecified vectors. | 0% Низкий | больше 3 лет назад | ||
GHSA-2jvm-jgg9-h383 Out-of-bounds array write in Xpdf 4.05 and earlier, due to incorrect integer overflow checking in the PostScript function interpreter code. | 0% Низкий | 11 месяцев назад |
Уязвимостей на страницу