Количество 311 321
Количество 311 321
GHSA-22f9-g2j6-q686
An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. They implement a series of web services using the SOAP protocol to allow scripting interaction with the backend server. An authenticated user (regardless of privileges) can list all databases connection details and credentials.
GHSA-22f8-fh6h-jjh4
Insecure storage of sensitive information in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
GHSA-22f8-7h52-6pfg
(1) bash before 1.14.7, and (2) tcsh 6.05 allow local users to gain privileges via directory names that contain shell metacharacters (` back-tick), which can cause the commands enclosed in the directory name to be executed when the shell expands filenames using the \w option in the PS1 variable.
GHSA-22f8-6qq6-p38x
Actual Analyzer through 2014-08-29 allows code execution via shell metacharacters because untrusted input is used for part of the input data passed to an eval operation.
GHSA-22f7-crxf-6p65
An issue was discovered in Titan SpamTitan 7.07. Due to improper sanitization of the parameter quid, used in the page mailqueue.php, code injection can occur. The input for this parameter is provided directly by an authenticated user via an HTTP GET request.
GHSA-22f7-6xg7-pq9x
OpenSC OpenSC.tokend has an Arbitrary File Creation/Overwrite Vulnerability
GHSA-22f6-99mv-7p4v
ppl program in HP-UX allows local users to create root files through symlinks.
GHSA-22f5-q5gp-64wx
ThreatSonar Anti-Ransomware from TeamT5 does not properly validate the content of uploaded files. Remote attackers with administrator privileges on the product platform can upload malicious files, which can be used to execute arbitrary system command on the server.
GHSA-22f5-36q8-782w
Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories and achieve remote code execution with system-level permissions.
GHSA-22f3-jcv7-7v3j
Reflected cross-site scripting vulnerability in MAHO-PBX NetDevancer series MAHO-PBX NetDevancer Lite/Uni/Pro/Cloud prior to Ver.1.11.00, MAHO-PBX NetDevancer VSG Lite/Uni prior to Ver.1.11.00, and MAHO-PBX NetDevancer MobileGate Home/Office prior to Ver.1.11.00 allows a remote unauthenticated attacker to inject an arbitrary script.
GHSA-22f3-4r93-w2x5
Vulnerability in the Oracle Commerce Platform component of Oracle Commerce (subcomponent: Dynamo Application Framework). Supported versions that are affected are 10.0.3.5, 10.2.0.5 and 11.2.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Commerce Platform accessible data. CVSS v3.0 Base Score 4.3 (Confidentiality impacts).
GHSA-22f3-2777-6wj4
Judging Management System v1.0.0 was discovered to contain a SQL injection vulnerability via the username parameter.
GHSA-22f2-v57c-j9cx
Rack vulnerable to ReDoS in content type parsing (2nd degree polynomial)
GHSA-22f2-jv6w-6ggr
Missing Authorization vulnerability in Horea Radu One Page Express Companion one-page-express-companion.This issue affects One Page Express Companion: from n/a through <= 1.6.43.
GHSA-22f2-7248-9pxp
The Access Point functionality in eapol_auth_key_handle in eapol.c in iNet wireless daemon (IWD) before 2.14 allows attackers to gain unauthorized access to a protected Wi-Fi network. An attacker can complete the EAPOL handshake by skipping Msg2/4 and instead sending Msg4/4 with an all-zero key.
GHSA-22cx-g984-4v34
Cross-site scripting (XSS) vulnerability in inplview.aspx in Microsoft SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via JavaScript sequences in a URL, aka "XSS in inplview.aspx Vulnerability."
GHSA-22cw-mq2h-w9m7
A use after free in IndexedDB in Google Chrome prior to 60.0.3112.78 for Linux, Android, Windows, and Mac allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.
GHSA-22cw-hj59-vjwv
Improper access control in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to cause local permanent denial of service.
GHSA-22cw-c67j-89mh
Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/classes/Master.php?f=delete_report.
GHSA-22cw-2v9q-5w3r
The Questoes OAB (aka com.pedefeijao.questoesoab) application oab_android_1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-22f9-g2j6-q686 An issue was discovered in Hitachi Vantara Pentaho through 9.1 and Pentaho Business Intelligence Server through 7.x. They implement a series of web services using the SOAP protocol to allow scripting interaction with the backend server. An authenticated user (regardless of privileges) can list all databases connection details and credentials. | CVSS3: 6.5 | 2% Низкий | больше 3 лет назад | |
GHSA-22f8-fh6h-jjh4 Insecure storage of sensitive information in the Intel(R) DCM software before version 5.1 may allow an authenticated user to potentially enable escalation of privilege via local access. | CVSS3: 8.2 | 0% Низкий | больше 2 лет назад | |
GHSA-22f8-7h52-6pfg (1) bash before 1.14.7, and (2) tcsh 6.05 allow local users to gain privileges via directory names that contain shell metacharacters (` back-tick), which can cause the commands enclosed in the directory name to be executed when the shell expands filenames using the \w option in the PS1 variable. | 0% Низкий | почти 4 года назад | ||
GHSA-22f8-6qq6-p38x Actual Analyzer through 2014-08-29 allows code execution via shell metacharacters because untrusted input is used for part of the input data passed to an eval operation. | CVSS3: 9.8 | 78% Высокий | больше 1 года назад | |
GHSA-22f7-crxf-6p65 An issue was discovered in Titan SpamTitan 7.07. Due to improper sanitization of the parameter quid, used in the page mailqueue.php, code injection can occur. The input for this parameter is provided directly by an authenticated user via an HTTP GET request. | 6% Низкий | больше 3 лет назад | ||
GHSA-22f7-6xg7-pq9x OpenSC OpenSC.tokend has an Arbitrary File Creation/Overwrite Vulnerability | 0% Низкий | больше 3 лет назад | ||
GHSA-22f6-99mv-7p4v ppl program in HP-UX allows local users to create root files through symlinks. | 0% Низкий | почти 4 года назад | ||
GHSA-22f5-q5gp-64wx ThreatSonar Anti-Ransomware from TeamT5 does not properly validate the content of uploaded files. Remote attackers with administrator privileges on the product platform can upload malicious files, which can be used to execute arbitrary system command on the server. | CVSS3: 7.2 | 1% Низкий | больше 1 года назад | |
GHSA-22f5-36q8-782w Due to insufficient sanitization, an attacker can upload a specially crafted configuration file to traverse directories and achieve remote code execution with system-level permissions. | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
GHSA-22f3-jcv7-7v3j Reflected cross-site scripting vulnerability in MAHO-PBX NetDevancer series MAHO-PBX NetDevancer Lite/Uni/Pro/Cloud prior to Ver.1.11.00, MAHO-PBX NetDevancer VSG Lite/Uni prior to Ver.1.11.00, and MAHO-PBX NetDevancer MobileGate Home/Office prior to Ver.1.11.00 allows a remote unauthenticated attacker to inject an arbitrary script. | CVSS3: 6.1 | 1% Низкий | около 3 лет назад | |
GHSA-22f3-4r93-w2x5 Vulnerability in the Oracle Commerce Platform component of Oracle Commerce (subcomponent: Dynamo Application Framework). Supported versions that are affected are 10.0.3.5, 10.2.0.5 and 11.2.0.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Commerce Platform. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Commerce Platform accessible data. CVSS v3.0 Base Score 4.3 (Confidentiality impacts). | CVSS3: 4.3 | 1% Низкий | больше 3 лет назад | |
GHSA-22f3-2777-6wj4 Judging Management System v1.0.0 was discovered to contain a SQL injection vulnerability via the username parameter. | CVSS3: 7.8 | 0% Низкий | около 3 лет назад | |
GHSA-22f2-v57c-j9cx Rack vulnerable to ReDoS in content type parsing (2nd degree polynomial) | CVSS3: 5.3 | 0% Низкий | почти 2 года назад | |
GHSA-22f2-jv6w-6ggr Missing Authorization vulnerability in Horea Radu One Page Express Companion one-page-express-companion.This issue affects One Page Express Companion: from n/a through <= 1.6.43. | CVSS3: 4.3 | 0% Низкий | 4 месяца назад | |
GHSA-22f2-7248-9pxp The Access Point functionality in eapol_auth_key_handle in eapol.c in iNet wireless daemon (IWD) before 2.14 allows attackers to gain unauthorized access to a protected Wi-Fi network. An attacker can complete the EAPOL handshake by skipping Msg2/4 and instead sending Msg4/4 with an all-zero key. | CVSS3: 7.5 | 1% Низкий | почти 2 года назад | |
GHSA-22cx-g984-4v34 Cross-site scripting (XSS) vulnerability in inplview.aspx in Microsoft SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via JavaScript sequences in a URL, aka "XSS in inplview.aspx Vulnerability." | 42% Средний | почти 4 года назад | ||
GHSA-22cw-mq2h-w9m7 A use after free in IndexedDB in Google Chrome prior to 60.0.3112.78 for Linux, Android, Windows, and Mac allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. | CVSS3: 8.8 | 1% Низкий | больше 3 лет назад | |
GHSA-22cw-hj59-vjwv Improper access control in DualDarManagerProxy prior to SMR Sep-2024 Release 1 allows local attackers to cause local permanent denial of service. | CVSS3: 6.6 | 0% Низкий | больше 1 года назад | |
GHSA-22cw-c67j-89mh Rescue Dispatch Management System v1.0 is vulnerable to SQL Injection via /rdms/classes/Master.php?f=delete_report. | CVSS3: 9.8 | 0% Низкий | больше 3 лет назад | |
GHSA-22cw-2v9q-5w3r The Questoes OAB (aka com.pedefeijao.questoesoab) application oab_android_1.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 0% Низкий | больше 3 лет назад |
Уязвимостей на страницу