Количество 314 458
Количество 314 458
GHSA-2fxf-fm4p-24xh
An out-of-bounds read in JPXStream::readTilePart in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file, as demonstrated by pdftohtml.
GHSA-2fxf-8pw8-gh64
Unspecified vulnerability in Sun ONE (aka iPlanet) Web Server 6.0 SP3 through SP5 on Windows allows remote attackers to cause a denial of service (daemon crash) via unknown vectors.
GHSA-2fxc-vhrx-cqc7
Dell PowerScale OneFS, versions 8.2.2 and above, contain a password disclosure vulnerability. An unprivileged local attacker could potentially exploit this vulnerability, leading to account take over.
GHSA-2fx9-jj4f-fr73
Vulnerability in the Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Security). Supported versions that are affected are 16.0, 17.0 and 18.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Customer Management and Segmentation Foundation. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Customer Management and Segmentation Foundation accessible data as well as unauthorized read access to a subset of Customer Management and Segmentation Foundation accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N).
GHSA-2fx9-2g54-566x
Double Precision Courier e-mail MTA allows remote attackers to cause a denial of service (CPU consumption) via a message with an extremely large or negative value for the year, which causes a tight loop.
GHSA-2fx8-gx73-p72f
DirectX Elevation of Privilege Vulnerability
GHSA-2fx8-69v9-25f6
A elevation of privilege vulnerability in the MediaTek libmtkomxvdec. Product: Android. Versions: Android kernel. Android ID: A-38447970. References: M-ALPS03337980.
GHSA-2fx8-5w8c-86ff
The MPD package included in TwinCAT/BSD allows an authenticated, low-privileged local attacker to induce a Denial-of-Service (DoS) condition on the daemon and execute code in the context of user “root” via a crafted HTTP request.
GHSA-2fx7-q8g7-wxwg
The BigBuy Dropshipping Connector for WooCommerce plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 2.0.5 due to insufficient IP address validation and use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible for unauthenticated attackers to retrieve the output of phpinfo().
GHSA-2fx7-mf6r-pff9
A low-privileged remote attacker could exploit the vulnerability and inject additional system commands via file system libraries which could give the attacker full control of the device.
GHSA-2fx7-3mgv-p2gp
A vulnerability has been found in Campcodes Online Examination System 1.0 and classified as critical. This vulnerability affects unknown code of the file /adminpanel/admin/query/deleteExamExe.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-258034 is the identifier assigned to this vulnerability.
GHSA-2fx6-wf22-3rf5
The Downloads feature in Apple Safari before 9.1 mishandles file expansion, which allows remote attackers to cause a denial of service via a crafted web site.
GHSA-2fx6-r6qx-3c7h
Path Traversal in Apache Oozie
GHSA-2fx6-86r8-c487
Prima Systems FlexAir devices have Hard-coded Credentials.
GHSA-2fx6-2pm7-cwvm
Server-Side Request Forgery (SSRF) vulnerability in Vova Anokhin WP Shortcodes Plugin — Shortcodes Ultimate.This issue affects WP Shortcodes Plugin — Shortcodes Ultimate: from n/a through 5.12.6.
GHSA-2fx5-pggv-6jjr
TYPO3 Potential Open Redirect via Parsing Differences
GHSA-2fx4-qxwh-34x6
Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote authenticated users to affect integrity via unknown vectors.
GHSA-2fx4-8cc3-3383
In ImageMagick, a crafted file could trigger an assertion failure when a call to WriteImages was made in MagickWand/operation.c, due to a NULL image list. This could potentially cause a denial of service. This was fixed in upstream ImageMagick version 7.1.0-30.
GHSA-2fx4-27pj-8f74
ISC DHCP 4.1.2 through 4.2.4 and 4.1-ESV before 4.1-ESV-R6 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a malformed client identifier.
GHSA-2fx2-v8hh-86v7
Curl before 7.49.1 in Apple OS X before macOS Sierra prior to 10.12 allows remote or local attackers to execute arbitrary code, gain sensitive information, cause denial-of-service conditions, bypass security restrictions, and perform unauthorized actions. This may aid in other attacks.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2fxf-fm4p-24xh An out-of-bounds read in JPXStream::readTilePart in JPXStream.cc in xpdf 4.00 allows attackers to launch denial of service via a specific pdf file, as demonstrated by pdftohtml. | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
GHSA-2fxf-8pw8-gh64 Unspecified vulnerability in Sun ONE (aka iPlanet) Web Server 6.0 SP3 through SP5 on Windows allows remote attackers to cause a denial of service (daemon crash) via unknown vectors. | 0% Низкий | почти 4 года назад | ||
GHSA-2fxc-vhrx-cqc7 Dell PowerScale OneFS, versions 8.2.2 and above, contain a password disclosure vulnerability. An unprivileged local attacker could potentially exploit this vulnerability, leading to account take over. | CVSS3: 6.7 | 0% Низкий | почти 4 года назад | |
GHSA-2fx9-jj4f-fr73 Vulnerability in the Customer Management and Segmentation Foundation product of Oracle Retail Applications (component: Security). Supported versions that are affected are 16.0, 17.0 and 18.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Customer Management and Segmentation Foundation. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Customer Management and Segmentation Foundation accessible data as well as unauthorized read access to a subset of Customer Management and Segmentation Foundation accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N). | 0% Низкий | больше 3 лет назад | ||
GHSA-2fx9-2g54-566x Double Precision Courier e-mail MTA allows remote attackers to cause a denial of service (CPU consumption) via a message with an extremely large or negative value for the year, which causes a tight loop. | 1% Низкий | почти 4 года назад | ||
GHSA-2fx8-gx73-p72f DirectX Elevation of Privilege Vulnerability | CVSS3: 7 | 0% Низкий | больше 3 лет назад | |
GHSA-2fx8-69v9-25f6 A elevation of privilege vulnerability in the MediaTek libmtkomxvdec. Product: Android. Versions: Android kernel. Android ID: A-38447970. References: M-ALPS03337980. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-2fx8-5w8c-86ff The MPD package included in TwinCAT/BSD allows an authenticated, low-privileged local attacker to induce a Denial-of-Service (DoS) condition on the daemon and execute code in the context of user “root” via a crafted HTTP request. | CVSS3: 6.5 | 0% Низкий | больше 1 года назад | |
GHSA-2fx7-q8g7-wxwg The BigBuy Dropshipping Connector for WooCommerce plugin for WordPress is vulnerable to IP Address Spoofing in all versions up to, and including, 2.0.5 due to insufficient IP address validation and use of user-supplied HTTP headers as a primary method for IP retrieval. This makes it possible for unauthenticated attackers to retrieve the output of phpinfo(). | CVSS3: 5.3 | 0% Низкий | 3 месяца назад | |
GHSA-2fx7-mf6r-pff9 A low-privileged remote attacker could exploit the vulnerability and inject additional system commands via file system libraries which could give the attacker full control of the device. | CVSS3: 8.8 | 0% Низкий | около 2 лет назад | |
GHSA-2fx7-3mgv-p2gp A vulnerability has been found in Campcodes Online Examination System 1.0 and classified as critical. This vulnerability affects unknown code of the file /adminpanel/admin/query/deleteExamExe.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-258034 is the identifier assigned to this vulnerability. | CVSS3: 6.3 | 0% Низкий | почти 2 года назад | |
GHSA-2fx6-wf22-3rf5 The Downloads feature in Apple Safari before 9.1 mishandles file expansion, which allows remote attackers to cause a denial of service via a crafted web site. | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад | |
GHSA-2fx6-r6qx-3c7h Path Traversal in Apache Oozie | CVSS3: 6.5 | 1% Низкий | больше 3 лет назад | |
GHSA-2fx6-86r8-c487 Prima Systems FlexAir devices have Hard-coded Credentials. | CVSS3: 8.8 | 1% Низкий | больше 3 лет назад | |
GHSA-2fx6-2pm7-cwvm Server-Side Request Forgery (SSRF) vulnerability in Vova Anokhin WP Shortcodes Plugin — Shortcodes Ultimate.This issue affects WP Shortcodes Plugin — Shortcodes Ultimate: from n/a through 5.12.6. | CVSS3: 7.1 | 0% Низкий | около 2 лет назад | |
GHSA-2fx5-pggv-6jjr TYPO3 Potential Open Redirect via Parsing Differences | CVSS3: 4.8 | 0% Низкий | около 1 года назад | |
GHSA-2fx4-qxwh-34x6 Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote authenticated users to affect integrity via unknown vectors. | 0% Низкий | больше 3 лет назад | ||
GHSA-2fx4-8cc3-3383 In ImageMagick, a crafted file could trigger an assertion failure when a call to WriteImages was made in MagickWand/operation.c, due to a NULL image list. This could potentially cause a denial of service. This was fixed in upstream ImageMagick version 7.1.0-30. | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
GHSA-2fx4-27pj-8f74 ISC DHCP 4.1.2 through 4.2.4 and 4.1-ESV before 4.1-ESV-R6 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a malformed client identifier. | 22% Средний | больше 3 лет назад | ||
GHSA-2fx2-v8hh-86v7 Curl before 7.49.1 in Apple OS X before macOS Sierra prior to 10.12 allows remote or local attackers to execute arbitrary code, gain sensitive information, cause denial-of-service conditions, bypass security restrictions, and perform unauthorized actions. This may aid in other attacks. | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу