Количество 315 253
Количество 315 253
GHSA-296m-rvp8-vc89
Artica Web Proxy before 3.06.112911 allows remote attackers to execute arbitrary code as root by conducting a cross-site scripting (XSS) attack involving the username-form-id parameter to freeradius.users.php.
GHSA-296m-g577-qvpq
Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.2100 respectively, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program.
GHSA-296j-r9gr-7w2c
Dell Dock Firmware and Dell Client Platform contain an Improper Link Resolution vulnerability during installation resulting in arbitrary folder deletion, which could lead to Privilege Escalation or Denial of Service.
GHSA-296j-2h87-8rxh
Visual Studio Code ESLint Extension Remote Code Execution Vulnerability
GHSA-296j-266h-6jc4
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
GHSA-296h-f7c6-qrvp
Stack-based buffer overflow in Jasc Paint Shop Pro 8.10 (aka Corel Paint Shop Pro) allows user-assisted remote attackers to execute arbitrary code via a crafted PNG file. NOTE: this might be the same issue as CVE-2007-2366.
GHSA-296g-m5cw-f8p9
A vulnerability in Cisco AMP for Endpoints Linux Connector Software and Cisco AMP for Endpoints Mac Connector Software could allow an authenticated, local attacker to cause a buffer overflow on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted packet to an affected device. A successful exploit could allow the attacker to cause the Cisco AMP for Endpoints service to crash and restart.
GHSA-296f-j97f-9r25
IOHIDFamily in Apple OS X before 10.10 allows attackers to cause denial of service (out-of-bounds read operation) via a crafted application.
GHSA-296f-cx2x-g274
SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the userService API model.
GHSA-296f-9hr7-4mwq
Stored Cross-Site Scripting in the Access Request History in Omada Identity before version 15 update 1 allows an authenticated attacker to execute arbitrary code in the browser of a victim via a specially crafted link or by viewing a manipulated Access Request History
GHSA-296f-4hq2-5r99
Web authoring command in Microsoft Content Management Server (MCMS) 2001 allows attackers to authenticate and upload executable content, by modifying the upload location, aka "Program Execution via MCMS Authoring Function."
GHSA-296c-8m99-q77p
Memory corruption when preparing a shared memory notification for a memparcel in Resource Manager.
GHSA-2969-8hh9-57jc
Allocation of Resources Without Limits or Throttling in ckb
GHSA-2969-2qqp-g57c
cPanel before 67.9999.103 allows code execution in the context of the mailman account because of incorrect environment-variable filtering (SEC-302).
GHSA-2968-xc5j-q436
The OC_Util::getUrlContent function in ownCloud Server before 5.0.18, 6.x before 6.0.6, and 7.x before 7.0.3 allows remote attackers to read arbitrary files via a file:// protocol.
GHSA-2968-wv79-2wqf
HCL BigFix Mobile 3.3 and earlier is affected by improper access control. Unauthorized users can access a small subset of endpoint actions, potentially allowing access to select internal functions.
GHSA-2968-fmvc-r6gw
Signal Handler Race Condition vulnerability in Mitsubishi Electric India GC-ENET-COM whose first 2 digits of 11-digit serial number of unit are "16" allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition in Ethernet communication by sending a large number of specially crafted packets to any UDP port when GC-ENET-COM is configured as a Modbus TCP Server. The communication resumes only when the power of the main unit is turned off and on or when the GC-ENET-COM is hot-swapped from the main unit.
GHSA-2968-6vjj-whq8
Phicomm K2G v22.6.3.20 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the automatic upgrade function.
GHSA-2967-w8m2-xw7h
PHP remote file inclusion vulnerability in class.cs_phpmailer.php in CS-Cart 1.3.3 allows remote attackers to execute arbitrary PHP code via a URL in the classes_dir parameter.
GHSA-2966-gh5h-j633
The session extension in PHP 4 before 4.4.5, and PHP 5 before 5.2.1, calculates the reference count for the session variables without considering the internal pointer from the session globals, which allows context-dependent attackers to execute arbitrary code via a crafted string in the session_register after unsetting HTTP_SESSION_VARS and _SESSION, which destroys the session data Hashtable.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-296m-rvp8-vc89 Artica Web Proxy before 3.06.112911 allows remote attackers to execute arbitrary code as root by conducting a cross-site scripting (XSS) attack involving the username-form-id parameter to freeradius.users.php. | CVSS3: 9 | 5% Низкий | больше 3 лет назад | |
GHSA-296m-g577-qvpq Symantec Endpoint Protection (SEP) and Symantec Endpoint Protection Small Business Edition (SEP SBE), prior to 14.2 RU2 MP1 and prior to 14.2.5569.2100 respectively, may be susceptible to an out of bounds vulnerability, which is a type of issue that results in an existing application reading memory outside of the bounds of the memory that had been allocated to the program. | 0% Низкий | больше 3 лет назад | ||
GHSA-296j-r9gr-7w2c Dell Dock Firmware and Dell Client Platform contain an Improper Link Resolution vulnerability during installation resulting in arbitrary folder deletion, which could lead to Privilege Escalation or Denial of Service. | CVSS3: 6.7 | 0% Низкий | больше 1 года назад | |
GHSA-296j-2h87-8rxh Visual Studio Code ESLint Extension Remote Code Execution Vulnerability | CVSS3: 7.8 | 12% Средний | больше 3 лет назад | |
GHSA-296j-266h-6jc4 Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-296h-f7c6-qrvp Stack-based buffer overflow in Jasc Paint Shop Pro 8.10 (aka Corel Paint Shop Pro) allows user-assisted remote attackers to execute arbitrary code via a crafted PNG file. NOTE: this might be the same issue as CVE-2007-2366. | 8% Низкий | почти 4 года назад | ||
GHSA-296g-m5cw-f8p9 A vulnerability in Cisco AMP for Endpoints Linux Connector Software and Cisco AMP for Endpoints Mac Connector Software could allow an authenticated, local attacker to cause a buffer overflow on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending a crafted packet to an affected device. A successful exploit could allow the attacker to cause the Cisco AMP for Endpoints service to crash and restart. | 0% Низкий | больше 3 лет назад | ||
GHSA-296f-j97f-9r25 IOHIDFamily in Apple OS X before 10.10 allows attackers to cause denial of service (out-of-bounds read operation) via a crafted application. | 0% Низкий | больше 3 лет назад | ||
GHSA-296f-cx2x-g274 SunGrow iSolarCloud before the October 31, 2024 remediation is vulnerable to insecure direct object references (IDOR) via the userService API model. | CVSS3: 9.1 | 0% Низкий | 12 месяцев назад | |
GHSA-296f-9hr7-4mwq Stored Cross-Site Scripting in the Access Request History in Omada Identity before version 15 update 1 allows an authenticated attacker to execute arbitrary code in the browser of a victim via a specially crafted link or by viewing a manipulated Access Request History | CVSS3: 8 | 0% Низкий | около 1 года назад | |
GHSA-296f-4hq2-5r99 Web authoring command in Microsoft Content Management Server (MCMS) 2001 allows attackers to authenticate and upload executable content, by modifying the upload location, aka "Program Execution via MCMS Authoring Function." | 9% Низкий | почти 4 года назад | ||
GHSA-296c-8m99-q77p Memory corruption when preparing a shared memory notification for a memparcel in Resource Manager. | CVSS3: 8.4 | 0% Низкий | больше 1 года назад | |
GHSA-2969-8hh9-57jc Allocation of Resources Without Limits or Throttling in ckb | CVSS3: 7.5 | 1% Низкий | около 4 лет назад | |
GHSA-2969-2qqp-g57c cPanel before 67.9999.103 allows code execution in the context of the mailman account because of incorrect environment-variable filtering (SEC-302). | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-2968-xc5j-q436 The OC_Util::getUrlContent function in ownCloud Server before 5.0.18, 6.x before 6.0.6, and 7.x before 7.0.3 allows remote attackers to read arbitrary files via a file:// protocol. | 0% Низкий | больше 3 лет назад | ||
GHSA-2968-wv79-2wqf HCL BigFix Mobile 3.3 and earlier is affected by improper access control. Unauthorized users can access a small subset of endpoint actions, potentially allowing access to select internal functions. | CVSS3: 5.3 | 0% Низкий | 4 месяца назад | |
GHSA-2968-fmvc-r6gw Signal Handler Race Condition vulnerability in Mitsubishi Electric India GC-ENET-COM whose first 2 digits of 11-digit serial number of unit are "16" allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition in Ethernet communication by sending a large number of specially crafted packets to any UDP port when GC-ENET-COM is configured as a Modbus TCP Server. The communication resumes only when the power of the main unit is turned off and on or when the GC-ENET-COM is hot-swapped from the main unit. | CVSS3: 5.9 | 0% Низкий | почти 3 года назад | |
GHSA-2968-6vjj-whq8 Phicomm K2G v22.6.3.20 was discovered to contain a command injection vulnerability via the autoUpTime parameter in the automatic upgrade function. | CVSS3: 7.8 | 1% Низкий | около 3 лет назад | |
GHSA-2967-w8m2-xw7h PHP remote file inclusion vulnerability in class.cs_phpmailer.php in CS-Cart 1.3.3 allows remote attackers to execute arbitrary PHP code via a URL in the classes_dir parameter. | 9% Низкий | почти 4 года назад | ||
GHSA-2966-gh5h-j633 The session extension in PHP 4 before 4.4.5, and PHP 5 before 5.2.1, calculates the reference count for the session variables without considering the internal pointer from the session globals, which allows context-dependent attackers to execute arbitrary code via a crafted string in the session_register after unsetting HTTP_SESSION_VARS and _SESSION, which destroys the session data Hashtable. | 4% Низкий | почти 4 года назад |
Уязвимостей на страницу