Количество 314 458
Количество 314 458
GHSA-2fw8-6c95-mmp8
Uninitialized data in endianness conversion in the XEvent handling of the X.Org X Server before 2017-06-19 allowed authenticated malicious users to access potentially privileged data from the X server.
GHSA-2fw7-6f7r-fx94
Permissive Cross-domain Security Policy with Untrusted Domains vulnerability in Drupal Next.Js allows Cross-Site Scripting (XSS).This issue affects Next.Js: from 0.0.0 before 1.6.4, from 2.0.0 before 2.0.1.
GHSA-2fw6-rcj8-hfw7
A potential DLL hijacking vulnerability was reported in Lenovo One Client during an internal security assessment that could allow a local authenticated user to execute code with elevated privileges.
GHSA-2fw5-rvf2-jq56
Apache Camel's XSLT component allows remote attackers to read arbitrary files
GHSA-2fw5-hcch-p3cj
A vulnerability has been found in Zorlan SkyCaiji 2.9 and classified as critical. This vulnerability affects the function fileAction of the file vendor/skycaiji/app/admin/controller/Tool.php. The manipulation of the argument save_data leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
GHSA-2fw4-mgq9-39cx
Code Injection in oauth2-server
GHSA-2fw3-wc2h-wv2q
PHP remote file inclusion vulnerability in news_show.php in Newanz NewsOffice 1.0 and 1.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the newsoffice_directory parameter.
GHSA-2fw3-jw4x-3m5f
Buffer overflow in k9filter.exe in BlueCoat K9 Web Protection 3.2.36, and probably other versions before 3.2.44, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request to port 2372.
GHSA-2fw2-jxh6-36cg
Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the time parameter in the setSmartPowerManagement function.
GHSA-2fw2-hj8q-m4ff
Cisco Unified Web and E-Mail Interaction Manager 9.0(2) and 11.0(1) improperly performs authorization, which allows remote authenticated users to read or write to stored data via unspecified vectors, aka Bug ID CSCuo89056.
GHSA-2fvx-vhr6-r4cv
Unrestricted File Upload in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 in the File Upload Functions allows an authenticated remote attacker with Upload privileges to upload files with any file type, enabling client-side attacks.
GHSA-2fvx-fjcj-g5x8
An information disclosure vulnerability in the HTC sound codec driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10. Android ID: A-33547247.
GHSA-2fvx-54hx-6r34
A vulnerability was found in DedeCMS 5.7. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /src/dede/mytag_edit.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263311. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
GHSA-2fvx-46rg-mf9q
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
GHSA-2fvw-qmcc-8m37
An issue was discovered in Atos Eviden BullSequana XH2140 BMC before C4EM-125: OMF_C4E 101.05.0014. Some BullSequana XH products were shipped without proper hardware programming, leading to a potential denial-of-service with privileged access.
GHSA-2fvw-ppfc-cm77
In JetBrains Ktor before 2.3.5 server certificates were not verified
GHSA-2fvw-mmpv-h962
The Groupama toujours la (aka com.groupama.toujoursla) application 1.3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
GHSA-2fvw-6h8p-qwr7
This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a victim can lead to arbitrary JavaScript code execution.
GHSA-2fvw-3vhp-2m2r
The administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to cause a denial of service (web outage) via an HTTP POST request to cgi-bin/firmwarecfg.
GHSA-2fvv-qxrq-7jq6
apollo-server-core vulnerable to URL-based XSS attack affecting IE11 on default landing page
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2fw8-6c95-mmp8 Uninitialized data in endianness conversion in the XEvent handling of the X.Org X Server before 2017-06-19 allowed authenticated malicious users to access potentially privileged data from the X server. | CVSS3: 6.5 | 1% Низкий | больше 3 лет назад | |
GHSA-2fw7-6f7r-fx94 Permissive Cross-domain Security Policy with Untrusted Domains vulnerability in Drupal Next.Js allows Cross-Site Scripting (XSS).This issue affects Next.Js: from 0.0.0 before 1.6.4, from 2.0.0 before 2.0.1. | CVSS3: 6.1 | 0% Низкий | 11 дней назад | |
GHSA-2fw6-rcj8-hfw7 A potential DLL hijacking vulnerability was reported in Lenovo One Client during an internal security assessment that could allow a local authenticated user to execute code with elevated privileges. | CVSS3: 7.8 | 0% Низкий | 2 месяца назад | |
GHSA-2fw5-rvf2-jq56 Apache Camel's XSLT component allows remote attackers to read arbitrary files | 29% Средний | больше 7 лет назад | ||
GHSA-2fw5-hcch-p3cj A vulnerability has been found in Zorlan SkyCaiji 2.9 and classified as critical. This vulnerability affects the function fileAction of the file vendor/skycaiji/app/admin/controller/Tool.php. The manipulation of the argument save_data leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 6.3 | 0% Низкий | 11 месяцев назад | |
GHSA-2fw4-mgq9-39cx Code Injection in oauth2-server | CVSS3: 7.5 | 0% Низкий | почти 5 лет назад | |
GHSA-2fw3-wc2h-wv2q PHP remote file inclusion vulnerability in news_show.php in Newanz NewsOffice 1.0 and 1.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the newsoffice_directory parameter. | 72% Высокий | почти 4 года назад | ||
GHSA-2fw3-jw4x-3m5f Buffer overflow in k9filter.exe in BlueCoat K9 Web Protection 3.2.36, and probably other versions before 3.2.44, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long HTTP GET request to port 2372. | 55% Средний | почти 4 года назад | ||
GHSA-2fw2-jxh6-36cg Tenda AC6V1.0 V15.03.05.19 was discovered to contain a buffer overflow via the time parameter in the setSmartPowerManagement function. | CVSS3: 7.5 | 0% Низкий | около 3 лет назад | |
GHSA-2fw2-hj8q-m4ff Cisco Unified Web and E-Mail Interaction Manager 9.0(2) and 11.0(1) improperly performs authorization, which allows remote authenticated users to read or write to stored data via unspecified vectors, aka Bug ID CSCuo89056. | 1% Низкий | больше 3 лет назад | ||
GHSA-2fvx-vhr6-r4cv Unrestricted File Upload in Web Applications operating on Business-DNA Solutions GmbH’s TopEase® Platform Version <= 7.1.27 in the File Upload Functions allows an authenticated remote attacker with Upload privileges to upload files with any file type, enabling client-side attacks. | 0% Низкий | около 4 лет назад | ||
GHSA-2fvx-fjcj-g5x8 An information disclosure vulnerability in the HTC sound codec driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: Kernel-3.10. Android ID: A-33547247. | CVSS3: 4.7 | 0% Низкий | больше 3 лет назад | |
GHSA-2fvx-54hx-6r34 A vulnerability was found in DedeCMS 5.7. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /src/dede/mytag_edit.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-263311. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 4.3 | 0% Низкий | почти 2 года назад | |
GHSA-2fvx-46rg-mf9q Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none. | около 2 лет назад | |||
GHSA-2fvw-qmcc-8m37 An issue was discovered in Atos Eviden BullSequana XH2140 BMC before C4EM-125: OMF_C4E 101.05.0014. Some BullSequana XH products were shipped without proper hardware programming, leading to a potential denial-of-service with privileged access. | CVSS3: 7.7 | 0% Низкий | 12 месяцев назад | |
GHSA-2fvw-ppfc-cm77 In JetBrains Ktor before 2.3.5 server certificates were not verified | CVSS3: 6.8 | 0% Низкий | больше 2 лет назад | |
GHSA-2fvw-mmpv-h962 The Groupama toujours la (aka com.groupama.toujoursla) application 1.3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 0% Низкий | больше 3 лет назад | ||
GHSA-2fvw-6h8p-qwr7 This vulnerability is present in device_graph_page.php script, which is a part of the Advantech R-SeeNet web applications. A specially crafted URL by an attacker and visited by a victim can lead to arbitrary JavaScript code execution. | CVSS3: 6.1 | 74% Высокий | больше 3 лет назад | |
GHSA-2fvw-3vhp-2m2r The administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to cause a denial of service (web outage) via an HTTP POST request to cgi-bin/firmwarecfg. | 5% Низкий | почти 4 года назад | ||
GHSA-2fvv-qxrq-7jq6 apollo-server-core vulnerable to URL-based XSS attack affecting IE11 on default landing page | больше 3 лет назад |
Уязвимостей на страницу