Количество 312 573
Количество 312 573
GHSA-24x2-jv4m-57w2
Rejected reason: Not used
GHSA-24wx-mghc-gchm
A remote attacker via undisclosed measures, may be able to exploit an F5 BIG-IP APM 13.0.0-13.1.0.7 or 12.1.0-12.1.3.5 virtual server configured with an APM per-request policy object and cause a memory leak in the APM module.
GHSA-24wx-m9jq-x9f7
Deserialization of Untrusted Data vulnerability in Tribulant Software Newsletters newsletters-lite allows Object Injection.This issue affects Newsletters: from n/a through <= 4.11.
GHSA-24ww-mc5x-xc43
Man-in-the-middle attack in Apache Cassandra
GHSA-24ww-hqf6-2c58
Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.
GHSA-24ww-94h4-w44f
Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 6.20, 6.4x, 7.01, 7.50, and 7.51 allows remote authenticated users to access certain privileged "facilities" via unspecified vectors.
GHSA-24wv-qqjw-rp9w
Insufficient input validation in the subsystem for Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable information disclosure via physical access.
GHSA-24wv-mv5m-xv4h
redis-py Race Condition vulnerability
GHSA-24wv-9vwj-q352
An out-of-bounds write vulnerability exists in VS6ComFile!CItemExChange::WinFontDynStrCheck of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution.
GHSA-24wv-6c99-f843
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
GHSA-24wv-53mh-2995
Microsoft SharePoint Server Remote Code Execution Vulnerability
GHSA-24wr-gx4f-pwrh
VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port 7443. A malicious actor with network access to port 7443 may attempt user enumeration or brute force the login endpoint, which may or may not be practical based on lockout policy configuration and password complexity for the target account.
GHSA-24wr-95c8-m99w
GetSimpleCMS 3.3.13 has an Open Redirect via the admin/index.php redirect parameter.
GHSA-24wq-x2jh-mcf8
An information disclosure vulnerability in the NVIDIA librm library (libnvrm) could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: Kernel-3.18. Android ID: A-31251599. References: N-CVE-2016-8400.
GHSA-24wq-pwcm-cmqx
Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
GHSA-24wq-mq98-wpxw
Stored cross-site scripting vulnerability which is exploiting a behavior of the XSS Filter exists in GROWI versions prior to v6.0.0. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the site using the product.
GHSA-24wq-3g32-9xrw
fdkaac before 1.0.5 was discovered to contain a stack overflow in read_callback function in src/main.c.
GHSA-24wp-g4q8-wwcx
The ServiceNow driver in NetIQ Identity Manager versions prior to 4.6 are susceptible to an information disclosure vulnerability.
GHSA-24wp-35x7-5hx9
The servlets invoked by httpha-invoker in JBoss Enterprise Application Platform before 5.1.2, SOA Platform before 5.2.0, BRMS Platform before 5.3.0, and Portal Platform before 4.3 CP07 perform access control only for the GET and POST methods, which allow remote attackers to bypass authentication by sending a request with a different method. NOTE: this vulnerability exists because of a CVE-2010-0738 regression.
GHSA-24wp-3277-85vf
An issue in Termius Version 9.9.0 through v.9.16.0 allows a physically proximate attacker to execute arbitrary code via the insecure Electron Fuses configuration.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-24x2-jv4m-57w2 Rejected reason: Not used | около 1 месяца назад | |||
GHSA-24wx-mghc-gchm A remote attacker via undisclosed measures, may be able to exploit an F5 BIG-IP APM 13.0.0-13.1.0.7 or 12.1.0-12.1.3.5 virtual server configured with an APM per-request policy object and cause a memory leak in the APM module. | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | |
GHSA-24wx-m9jq-x9f7 Deserialization of Untrusted Data vulnerability in Tribulant Software Newsletters newsletters-lite allows Object Injection.This issue affects Newsletters: from n/a through <= 4.11. | CVSS3: 9.8 | 0% Низкий | 30 дней назад | |
GHSA-24ww-mc5x-xc43 Man-in-the-middle attack in Apache Cassandra | CVSS3: 5.9 | 0% Низкий | больше 4 лет назад | |
GHSA-24ww-hqf6-2c58 Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure. | около 1 месяца назад | |||
GHSA-24ww-94h4-w44f Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 6.20, 6.4x, 7.01, 7.50, and 7.51 allows remote authenticated users to access certain privileged "facilities" via unspecified vectors. | 1% Низкий | почти 4 года назад | ||
GHSA-24wv-qqjw-rp9w Insufficient input validation in the subsystem for Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable information disclosure via physical access. | CVSS3: 4.6 | 0% Низкий | больше 3 лет назад | |
GHSA-24wv-mv5m-xv4h redis-py Race Condition vulnerability | CVSS3: 3.7 | 1% Низкий | почти 3 года назад | |
GHSA-24wv-9vwj-q352 An out-of-bounds write vulnerability exists in VS6ComFile!CItemExChange::WinFontDynStrCheck of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lead to information disclosure, affected system's abnormal end (ABEND), and arbitrary code execution. | CVSS3: 7.8 | 0% Низкий | 4 месяца назад | |
GHSA-24wv-6c99-f843 Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution | CVSS3: 10 | 35% Средний | 8 месяцев назад | |
GHSA-24wv-53mh-2995 Microsoft SharePoint Server Remote Code Execution Vulnerability | CVSS3: 7.2 | 14% Средний | больше 1 года назад | |
GHSA-24wr-gx4f-pwrh VMware Workspace ONE Access and Identity Manager, unintentionally provide a login interface on port 7443. A malicious actor with network access to port 7443 may attempt user enumeration or brute force the login endpoint, which may or may not be practical based on lockout policy configuration and password complexity for the target account. | 0% Низкий | больше 3 лет назад | ||
GHSA-24wr-95c8-m99w GetSimpleCMS 3.3.13 has an Open Redirect via the admin/index.php redirect parameter. | CVSS3: 6.1 | 14% Средний | больше 3 лет назад | |
GHSA-24wq-x2jh-mcf8 An information disclosure vulnerability in the NVIDIA librm library (libnvrm) could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Product: Android. Versions: Kernel-3.18. Android ID: A-31251599. References: N-CVE-2016-8400. | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
GHSA-24wq-pwcm-cmqx Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | CVSS3: 3.3 | 0% Низкий | около 2 лет назад | |
GHSA-24wq-mq98-wpxw Stored cross-site scripting vulnerability which is exploiting a behavior of the XSS Filter exists in GROWI versions prior to v6.0.0. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who accessed the site using the product. | CVSS3: 5.4 | 2% Низкий | около 2 лет назад | |
GHSA-24wq-3g32-9xrw fdkaac before 1.0.5 was discovered to contain a stack overflow in read_callback function in src/main.c. | CVSS3: 5.5 | 0% Низкий | больше 2 лет назад | |
GHSA-24wp-g4q8-wwcx The ServiceNow driver in NetIQ Identity Manager versions prior to 4.6 are susceptible to an information disclosure vulnerability. | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
GHSA-24wp-35x7-5hx9 The servlets invoked by httpha-invoker in JBoss Enterprise Application Platform before 5.1.2, SOA Platform before 5.2.0, BRMS Platform before 5.3.0, and Portal Platform before 4.3 CP07 perform access control only for the GET and POST methods, which allow remote attackers to bypass authentication by sending a request with a different method. NOTE: this vulnerability exists because of a CVE-2010-0738 regression. | 0% Низкий | больше 3 лет назад | ||
GHSA-24wp-3277-85vf An issue in Termius Version 9.9.0 through v.9.16.0 allows a physically proximate attacker to execute arbitrary code via the insecure Electron Fuses configuration. | CVSS3: 9.8 | 0% Низкий | 11 месяцев назад |
Уязвимостей на страницу