Количество 314 078
Количество 314 078
GHSA-269r-2rrv-62mq
Kerio MailServer 5.0 allows remote attackers to cause a denial of service (hang) via SYN packets to the supported network services.
GHSA-269q-phhx-gq68
Unrestricted file upload vulnerability in lazyseo.php in the Lazy SEO plugin 1.1.9 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a PHP file, then accessing it via a direct request to the file in lazy-seo/.
GHSA-269q-hmxg-m83q
Local Information Disclosure Vulnerability in io.netty:netty-codec-http
GHSA-269p-6jw2-x3jp
Stack-based buffer overflow in the suhosin_encrypt_single_cookie function in the transparent cookie-encryption feature in the Suhosin extension before 0.9.33 for PHP, when suhosin.cookie.encrypt and suhosin.multiheader are enabled, might allow remote attackers to execute arbitrary code via a long string that is used in a Set-Cookie HTTP header.
GHSA-269m-c36j-r834
Infinispan vulnerable to Insertion of Sensitive Information into Log File
GHSA-269m-695x-j34p
Apache Qpid Broker vulnerable to authentication port spoofing
GHSA-269j-rg7r-j5rj
Multiple SQL injection vulnerabilities in Pligg before 1.1.1 allow remote attackers to execute arbitrary SQL commands via the title parameter to (1) storyrss.php or (2) story.php.
GHSA-269j-r79f-hqvp
Active PHP Bookmarks (APB) 1.1.01 allows remote attackers to execute arbitrary PHP code via (1) head.php, (2) apb_common.php, or (3) apb_view_class.php by modifying the APB_SETTINGS parameter to reference a URL on a remote web server that contains the code.
GHSA-269j-j44g-6c79
SQL injection vulnerability in calendar_download.php in BosDates 3.2 and earlier allows remote attackers to obtain sensitive information and gain access via the calendar parameter.
GHSA-269j-j2cg-h6qp
Aruba ClearPass, all versions of 6.6.x prior to 6.6.9 are affected by an authentication bypass vulnerability, an attacker can leverage this vulnerability to gain administrator privileges on the system. The vulnerability is exposed only on ClearPass web interfaces, including administrative, guest captive portal, and API. Customers who do not expose ClearPass web interfaces to untrusted users are impacted to a lesser extent.
GHSA-269j-37ww-cmh3
Mezzanine CMS vulnerable to Cross-site Scripting
GHSA-269h-v9xg-7fq6
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
GHSA-269h-pcpx-q5mj
Use after free in Browser UI in Google Chrome on Chrome OS prior to 99.0.4844.74 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page.
GHSA-269h-hc79-qjpf
LOYTEC electronics GmbH LINX-212 firmware 6.2.4 and LINX-151 Firmware 7.2.4 are vulnerable to Incorrect Access Control via registry.xml file. This vulnerability allows remote attackers to disclose sensitive information on LINX configuration.
GHSA-269h-2wf7-8247
The license-installation module on the Cisco Nexus 1000V switch 4.2(1)SV1(5.2b) and earlier for VMware vSphere, Cisco Nexus 1000V switch 5.2(1)SM1(5.1) for Microsoft Hyper-V, and Cisco Virtual Security Gateway 4.2(1)VSG1(1) for Nexus 1000V switches allows local users to gain privileges and execute arbitrary commands via crafted "install all iso" arguments, aka Bug ID CSCui21340.
GHSA-269g-rg4h-9rr5
Rejected reason: Not used
GHSA-269g-pwp5-87pp
TemporaryFolder on unix-like systems does not limit access to created files
GHSA-269g-6r83-cfhc
Chamilo LMS version 1.11.8 contains XSS in main/social/group_view.php in the social groups tool, allowing authenticated users to affect other users, under specific conditions of permissions granted by administrators. This is considered "low risk" due to the nature of the feature it exploits.
GHSA-269f-h4cx-j3fr
An issue was discovered in the MediaWikiChat extension for MediaWiki through 1.42.1. CSRF can occur in API modules.
GHSA-269f-c6h8-6gv2
A vulnerability was found in saxman maps-js-icoads. It has been classified as problematic. Affected is an unknown function. The manipulation leads to exposure of information through directory listing. It is possible to launch the attack remotely. The name of the patch is 34b8b0cce2807b119f4cffda2ac48fc8f427d69a. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-217644.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-269r-2rrv-62mq Kerio MailServer 5.0 allows remote attackers to cause a denial of service (hang) via SYN packets to the supported network services. | 1% Низкий | почти 4 года назад | ||
GHSA-269q-phhx-gq68 Unrestricted file upload vulnerability in lazyseo.php in the Lazy SEO plugin 1.1.9 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a PHP file, then accessing it via a direct request to the file in lazy-seo/. | 7% Низкий | больше 3 лет назад | ||
GHSA-269q-hmxg-m83q Local Information Disclosure Vulnerability in io.netty:netty-codec-http | CVSS3: 5.5 | 0% Низкий | больше 3 лет назад | |
GHSA-269p-6jw2-x3jp Stack-based buffer overflow in the suhosin_encrypt_single_cookie function in the transparent cookie-encryption feature in the Suhosin extension before 0.9.33 for PHP, when suhosin.cookie.encrypt and suhosin.multiheader are enabled, might allow remote attackers to execute arbitrary code via a long string that is used in a Set-Cookie HTTP header. | 5% Низкий | больше 3 лет назад | ||
GHSA-269m-c36j-r834 Infinispan vulnerable to Insertion of Sensitive Information into Log File | CVSS3: 5.5 | 0% Низкий | около 1 года назад | |
GHSA-269m-695x-j34p Apache Qpid Broker vulnerable to authentication port spoofing | CVSS3: 9.8 | 3% Низкий | больше 7 лет назад | |
GHSA-269j-rg7r-j5rj Multiple SQL injection vulnerabilities in Pligg before 1.1.1 allow remote attackers to execute arbitrary SQL commands via the title parameter to (1) storyrss.php or (2) story.php. | 1% Низкий | больше 3 лет назад | ||
GHSA-269j-r79f-hqvp Active PHP Bookmarks (APB) 1.1.01 allows remote attackers to execute arbitrary PHP code via (1) head.php, (2) apb_common.php, or (3) apb_view_class.php by modifying the APB_SETTINGS parameter to reference a URL on a remote web server that contains the code. | 0% Низкий | почти 4 года назад | ||
GHSA-269j-j44g-6c79 SQL injection vulnerability in calendar_download.php in BosDates 3.2 and earlier allows remote attackers to obtain sensitive information and gain access via the calendar parameter. | 0% Низкий | почти 4 года назад | ||
GHSA-269j-j2cg-h6qp Aruba ClearPass, all versions of 6.6.x prior to 6.6.9 are affected by an authentication bypass vulnerability, an attacker can leverage this vulnerability to gain administrator privileges on the system. The vulnerability is exposed only on ClearPass web interfaces, including administrative, guest captive portal, and API. Customers who do not expose ClearPass web interfaces to untrusted users are impacted to a lesser extent. | CVSS3: 9.8 | 1% Низкий | больше 3 лет назад | |
GHSA-269j-37ww-cmh3 Mezzanine CMS vulnerable to Cross-site Scripting | CVSS3: 4.8 | 0% Низкий | 7 месяцев назад | |
GHSA-269h-v9xg-7fq6 Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | CVSS3: 8.4 | 0% Низкий | 4 месяца назад | |
GHSA-269h-pcpx-q5mj Use after free in Browser UI in Google Chrome on Chrome OS prior to 99.0.4844.74 allowed a remote attacker who convinced a user to engage in specific user interaction to potentially exploit heap corruption via a crafted HTML page. | CVSS3: 9.6 | 1% Низкий | больше 3 лет назад | |
GHSA-269h-hc79-qjpf LOYTEC electronics GmbH LINX-212 firmware 6.2.4 and LINX-151 Firmware 7.2.4 are vulnerable to Incorrect Access Control via registry.xml file. This vulnerability allows remote attackers to disclose sensitive information on LINX configuration. | CVSS3: 7.5 | 1% Низкий | около 2 лет назад | |
GHSA-269h-2wf7-8247 The license-installation module on the Cisco Nexus 1000V switch 4.2(1)SV1(5.2b) and earlier for VMware vSphere, Cisco Nexus 1000V switch 5.2(1)SM1(5.1) for Microsoft Hyper-V, and Cisco Virtual Security Gateway 4.2(1)VSG1(1) for Nexus 1000V switches allows local users to gain privileges and execute arbitrary commands via crafted "install all iso" arguments, aka Bug ID CSCui21340. | 0% Низкий | больше 3 лет назад | ||
GHSA-269g-rg4h-9rr5 Rejected reason: Not used | 4 месяца назад | |||
GHSA-269g-pwp5-87pp TemporaryFolder on unix-like systems does not limit access to created files | CVSS3: 4.4 | 0% Низкий | больше 5 лет назад | |
GHSA-269g-6r83-cfhc Chamilo LMS version 1.11.8 contains XSS in main/social/group_view.php in the social groups tool, allowing authenticated users to affect other users, under specific conditions of permissions granted by administrators. This is considered "low risk" due to the nature of the feature it exploits. | CVSS3: 5.4 | 0% Низкий | больше 3 лет назад | |
GHSA-269f-h4cx-j3fr An issue was discovered in the MediaWikiChat extension for MediaWiki through 1.42.1. CSRF can occur in API modules. | CVSS3: 6.5 | 0% Низкий | больше 1 года назад | |
GHSA-269f-c6h8-6gv2 A vulnerability was found in saxman maps-js-icoads. It has been classified as problematic. Affected is an unknown function. The manipulation leads to exposure of information through directory listing. It is possible to launch the attack remotely. The name of the patch is 34b8b0cce2807b119f4cffda2ac48fc8f427d69a. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-217644. | CVSS3: 5.3 | 0% Низкий | около 3 лет назад |
Уязвимостей на страницу