Количество 314 458
Количество 314 458
GHSA-2h44-jj8j-mm3c
IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to obtain sensitive information via an unspecified brute-force attack.
GHSA-2h43-q8jc-xrgf
Zomato Clone Script allows SQL Injection via the restaurant-menu.php resid parameter.
GHSA-2h43-p8w8-3pq4
An issue was discovered in gpac through 20200801. A NULL pointer dereference exists in the function nhmldump_send_header located in write_nhml.c. It allows an attacker to cause Denial of Service.
GHSA-2h43-m2j2-437h
Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."
GHSA-2h42-qmq7-j2qx
Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allow remote attackers to inject arbitrary web script or HTML via certain character encodings, including (1) a backspace character that is treated as whitespace, (2) 0x80 with Shift_JIS encoding, and (3) "zero-length non-ASCII sequences" in certain Asian character sets.
GHSA-2h42-pg53-gv5w
An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Heap-based buffer overflow in w3m allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted HTML page.
GHSA-2h42-5wxm-jmgg
Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.68 and earlier, 5.5.30 and earlier, and 5.6.10 allows remote authenticated users to affect availability via unknown vectors related to Server Options.
GHSA-2h3x-95c6-885r
Malicious Package in river-mock
GHSA-2h3x-87v9-5cx9
Heap-based buffer overflow in Adobe Reader and Acrobat 10.x before 10.1.12 and 11.x before 11.0.09 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-0561.
GHSA-2h3w-wpc8-4ggf
Uncontrolled search path for some Intel(R) oneAPI Level Zero software may allow an authenticated user to potentially enable escalation of privilege via local access.
GHSA-2h3w-9mqf-3gfh
The ffmpeg lavf demuxer allows user-assisted attackers to cause a denial of service (application crash) via a crafted GIF file, possibly related to gstreamer, as demonstrated by lol-giftopnm.gif.
GHSA-2h3w-869c-mmjh
SZ NetChat before 7.9 has XSS in the MyName input field of the Options module. Attackers are able to inject commands to compromise the enabled HTTP server web frontend.
GHSA-2h3v-mhq3-rf2w
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
GHSA-2h3v-8xgc-fcxp
Improper Verification of Cryptographic Signature in AVM FRITZ!Box 6810 LTE after firmware 5.22, FRITZ!Box 6840 LTE after firmware 5.23, and other models with firmware 5.50.
GHSA-2h3v-3p73-36m3
A Unauthenticated Remote Denial of Service vulnerability was identified in HPE Integrated Lights-Out 3 (iLO 3) version v1.88 only. The vulnerability is resolved in iLO3 v1.89 or subsequent versions.
GHSA-2h3q-v47h-f4rc
Ejabberd DoS via malformed stanza
GHSA-2h3q-jf7q-6jvh
A vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the web service contains a hidden system account with a hardcoded password. An attacker can use this information to log into the system with high-privilege credentials.
GHSA-2h3p-557r-42m3
MariaDB Server v10.7 and below was discovered to contain a segmentation fault via the component sql/sql_class.cc.
GHSA-2h3j-wfg4-fwg5
Geist WatchDog Console 3.2.2 uses a weak ACL for the C:\ProgramData\WatchDog Console directory, which allows local users to modify configuration data by updating (1) config.xml or (2) servers.xml.
GHSA-2h3j-m7gr-25xj
Excessive Iteration Denial of Service in Apache PDFBox
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2h44-jj8j-mm3c IBM Connections 4.x through 4.5 CR5, 5.0 before CR4, and 5.5 before CR1 allows remote authenticated users to obtain sensitive information via an unspecified brute-force attack. | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад | |
GHSA-2h43-q8jc-xrgf Zomato Clone Script allows SQL Injection via the restaurant-menu.php resid parameter. | CVSS3: 9.8 | 1% Низкий | больше 3 лет назад | |
GHSA-2h43-p8w8-3pq4 An issue was discovered in gpac through 20200801. A NULL pointer dereference exists in the function nhmldump_send_header located in write_nhml.c. It allows an attacker to cause Denial of Service. | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
GHSA-2h43-m2j2-437h Microsoft Word 2007 SP3, Office 2010 SP2, Word 2010 SP2, Word 2013 SP1, Word 2013 RT SP1, Word 2016, Word for Mac 2011, Word 2016 for Mac, Office Compatibility Pack SP3, and Word Viewer allow remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability." | CVSS3: 7.8 | 24% Средний | больше 3 лет назад | |
GHSA-2h42-qmq7-j2qx Multiple cross-site scripting (XSS) vulnerabilities in Mozilla Firefox before 2.0.0.12, Thunderbird before 2.0.0.12, and SeaMonkey before 1.1.8 allow remote attackers to inject arbitrary web script or HTML via certain character encodings, including (1) a backspace character that is treated as whitespace, (2) 0x80 with Shift_JIS encoding, and (3) "zero-length non-ASCII sequences" in certain Asian character sets. | 7% Низкий | почти 4 года назад | ||
GHSA-2h42-pg53-gv5w An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Heap-based buffer overflow in w3m allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted HTML page. | CVSS3: 8.8 | 1% Низкий | больше 3 лет назад | |
GHSA-2h42-5wxm-jmgg Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.1.68 and earlier, 5.5.30 and earlier, and 5.6.10 allows remote authenticated users to affect availability via unknown vectors related to Server Options. | 0% Низкий | больше 3 лет назад | ||
GHSA-2h3x-95c6-885r Malicious Package in river-mock | CVSS3: 9.8 | больше 5 лет назад | ||
GHSA-2h3x-87v9-5cx9 Heap-based buffer overflow in Adobe Reader and Acrobat 10.x before 10.1.12 and 11.x before 11.0.09 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-0561. | 34% Средний | больше 3 лет назад | ||
GHSA-2h3w-wpc8-4ggf Uncontrolled search path for some Intel(R) oneAPI Level Zero software may allow an authenticated user to potentially enable escalation of privilege via local access. | CVSS3: 6.7 | 0% Низкий | 9 месяцев назад | |
GHSA-2h3w-9mqf-3gfh The ffmpeg lavf demuxer allows user-assisted attackers to cause a denial of service (application crash) via a crafted GIF file, possibly related to gstreamer, as demonstrated by lol-giftopnm.gif. | 0% Низкий | почти 4 года назад | ||
GHSA-2h3w-869c-mmjh SZ NetChat before 7.9 has XSS in the MyName input field of the Options module. Attackers are able to inject commands to compromise the enabled HTTP server web frontend. | CVSS3: 5.4 | 0% Низкий | больше 3 лет назад | |
GHSA-2h3v-mhq3-rf2w Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | CVSS3: 9.8 | 2% Низкий | больше 2 лет назад | |
GHSA-2h3v-8xgc-fcxp Improper Verification of Cryptographic Signature in AVM FRITZ!Box 6810 LTE after firmware 5.22, FRITZ!Box 6840 LTE after firmware 5.23, and other models with firmware 5.50. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-2h3v-3p73-36m3 A Unauthenticated Remote Denial of Service vulnerability was identified in HPE Integrated Lights-Out 3 (iLO 3) version v1.88 only. The vulnerability is resolved in iLO3 v1.89 or subsequent versions. | CVSS3: 8.6 | 4% Низкий | больше 3 лет назад | |
GHSA-2h3q-v47h-f4rc Ejabberd DoS via malformed stanza | 1% Низкий | больше 3 лет назад | ||
GHSA-2h3q-jf7q-6jvh A vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the web service contains a hidden system account with a hardcoded password. An attacker can use this information to log into the system with high-privilege credentials. | CVSS3: 9.8 | 0% Низкий | больше 3 лет назад | |
GHSA-2h3p-557r-42m3 MariaDB Server v10.7 and below was discovered to contain a segmentation fault via the component sql/sql_class.cc. | CVSS3: 7.5 | 0% Низкий | почти 4 года назад | |
GHSA-2h3j-wfg4-fwg5 Geist WatchDog Console 3.2.2 uses a weak ACL for the C:\ProgramData\WatchDog Console directory, which allows local users to modify configuration data by updating (1) config.xml or (2) servers.xml. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-2h3j-m7gr-25xj Excessive Iteration Denial of Service in Apache PDFBox | CVSS3: 5.5 | 1% Низкий | больше 4 лет назад |
Уязвимостей на страницу