Количество 355 380
Количество 355 380
GHSA-xrc3-9jj6-mqcm
A Path Traversal Information Disclosure vulnerability exists in "Sante PACS Server.exe". An unauthenticated remote attacker can exploit it to download arbitrary files on the disk drive where the application is installed.
GHSA-xrc2-5gr8-655q
GE Communicator, all versions prior to 4.0.517, allows a non-administrative user to place malicious files within the installer file directory, which may allow an attacker to gain administrative privileges on a system during installation or upgrade.
GHSA-xr9x-r78c-5hrm
Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing
GHSA-xr9x-fhcv-6qm7
In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZone 100 (SZ-100) before 3.6.2.0.795, SmartZone 300 (SZ300) before 3.6.2.0.795, Virtual SmartZone (vSZ) before 3.6.2.0.795, ZoneDirector 1100 9.10.2.0.130, ZoneDirector 1200 10.2.1.0.218, ZoneDirector 3000 10.2.1.0.218, ZoneDirector 5000 10.0.1.0.151, a vulnerability allows attackers to exploit the official image signature to force injection unauthorized image signature.
GHSA-xr9w-x6gw-c9mj
Duplicate advisory: Deno vulnerable to Regular Expression Denial of Service
GHSA-xr9w-r8gw-wjhw
IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 stores unencrypted sensitive information in environmental variables files which can be obtained by an authenticated user.
GHSA-xr9r-hxj6-96p6
In the Linux kernel, the following vulnerability has been resolved: cifs: fix small mempool leak in SMB2_negotiate() In some cases of failure (dialect mismatches) in SMB2_negotiate(), after the request is sent, the checks would return -EIO when they should be rather setting rc = -EIO and jumping to neg_exit to free the response buffer from mempool.
GHSA-xr9r-3v5q-97c3
The play/modules component in Cisco WebEx Meetings Server allows remote attackers to obtain administrator access via crafted API requests, aka Bug ID CSCuj40421.
GHSA-xr9q-qqh9-m7h3
The Java Message Service (JMS) in IBM WebSphere Application Server (WAS) before 6.1.0.7 allows attackers to cause a denial of service via unknown vectors involving the "double release [of] a bytebuffer input stream," possibly a double free vulnerability.
GHSA-xr9q-p253-xqxh
In smsSelected of AnswerFragment.java, there is a way to send an SMS from the lock screen due to a permissions bypass. This could lead to local escalation of privilege on the lock screen with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-137102479
GHSA-xr9q-h9c7-xw8q
Rancher allows an unauthenticated stack overflow in /v3-public/authproviders API
GHSA-xr9q-85p6-f6xr
The Premium Age Verification / Restriction for WordPress plugin for WordPress is vulnerable to arbitrary file read and write due to the existence of an insufficiently protected remote support functionality in remote_tunnel.php in all versions up to, and including, 3.0.2. This makes it possible for unauthenticated attackers to read from or write to arbitrary files on the affected site's server which may make the exposure of sensitive information or remote code execution possible.
GHSA-xr9p-wqhw-3w78
Authenticated and encrypted payload MMEs can be forged and remotely sent to any HPAV2 system using a jailbreak key recoverable from code.
GHSA-xr9p-qj4x-c6c7
The ICQ Webserver allows remote attackers to use .. to access arbitrary files outside of the user's personal directory.
GHSA-xr9p-mfhc-2mwc
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality via unknown vectors related to Test Manager for Web Apps. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the DownloadServlet servlet, which allows remote attackers to read arbitrary files via directory traversal sequences in the scriptPath parameter.
GHSA-xr9m-34vg-p986
The Wipe Free Space utility in PGP Desktop Home 8.0 and Desktop Professional 9.0.3 Build 2932 and earlier does not clear file slack space in the last cluster for the file, which allows local users to access the previous contents of the disk.
GHSA-xr9j-c7v6-7542
A use-after-free vulnerability was found in drivers/nvme/target/tcp.c` in `nvmet_tcp_free_crypto` due to a logical bug in the NVMe-oF/TCP subsystem in the Linux kernel. This issue may allow a malicious user to cause a use-after-free and double-free problem, which may permit remote code execution or lead to local privilege escalation in case that the attacker already has local privileges.
GHSA-xr9j-92x7-g2w2
In Afian Filerun 20220202, lack of sanitization of the POST parameter "metadata[]" in `/?module=fileman§ion=get&page=grid` leads to SQL injection.
GHSA-xr9j-2jxx-p2h8
Integer Overflow or Wraparound vulnerability in Ralim IronOS.This issue affects IronOS: before v2.23-rc2.
GHSA-xr9h-p2rc-rpqm
WWBN/AVideo stored XSS vulnerability leads to takeover of any user's account, including admin's account
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xrc3-9jj6-mqcm A Path Traversal Information Disclosure vulnerability exists in "Sante PACS Server.exe". An unauthenticated remote attacker can exploit it to download arbitrary files on the disk drive where the application is installed. | CVSS3: 7.5 | 39% Средний | больше 1 года назад | |
GHSA-xrc2-5gr8-655q GE Communicator, all versions prior to 4.0.517, allows a non-administrative user to place malicious files within the installer file directory, which may allow an attacker to gain administrative privileges on a system during installation or upgrade. | CVSS3: 7.8 | 0% Низкий | около 4 лет назад | |
GHSA-xr9x-r78c-5hrm Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing | 2% Низкий | 8 дней назад | ||
GHSA-xr9x-fhcv-6qm7 In Ruckus R310 10.5.1.0.199, Ruckus R500 10.5.1.0.199, Ruckus R600 10.5.1.0.199, Ruckus T300 10.5.1.0.199, Ruckus T301n 10.5.1.0.199, Ruckus T301s 10.5.1.0.199, SmartCell Gateway 200 (SCG200) before 3.6.2.0.795, SmartZone 100 (SZ-100) before 3.6.2.0.795, SmartZone 300 (SZ300) before 3.6.2.0.795, Virtual SmartZone (vSZ) before 3.6.2.0.795, ZoneDirector 1100 9.10.2.0.130, ZoneDirector 1200 10.2.1.0.218, ZoneDirector 3000 10.2.1.0.218, ZoneDirector 5000 10.0.1.0.151, a vulnerability allows attackers to exploit the official image signature to force injection unauthorized image signature. | CVSS3: 9.8 | 1% Низкий | больше 3 лет назад | |
GHSA-xr9w-x6gw-c9mj Duplicate advisory: Deno vulnerable to Regular Expression Denial of Service | CVSS3: 7.5 | больше 3 лет назад | ||
GHSA-xr9w-r8gw-wjhw IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 stores unencrypted sensitive information in environmental variables files which can be obtained by an authenticated user. | CVSS3: 6.5 | 0% Низкий | 8 месяцев назад | |
GHSA-xr9r-hxj6-96p6 In the Linux kernel, the following vulnerability has been resolved: cifs: fix small mempool leak in SMB2_negotiate() In some cases of failure (dialect mismatches) in SMB2_negotiate(), after the request is sent, the checks would return -EIO when they should be rather setting rc = -EIO and jumping to neg_exit to free the response buffer from mempool. | CVSS3: 5.5 | 0% Низкий | около 1 года назад | |
GHSA-xr9r-3v5q-97c3 The play/modules component in Cisco WebEx Meetings Server allows remote attackers to obtain administrator access via crafted API requests, aka Bug ID CSCuj40421. | 1% Низкий | около 4 лет назад | ||
GHSA-xr9q-qqh9-m7h3 The Java Message Service (JMS) in IBM WebSphere Application Server (WAS) before 6.1.0.7 allows attackers to cause a denial of service via unknown vectors involving the "double release [of] a bytebuffer input stream," possibly a double free vulnerability. | 2% Низкий | больше 4 лет назад | ||
GHSA-xr9q-p253-xqxh In smsSelected of AnswerFragment.java, there is a way to send an SMS from the lock screen due to a permissions bypass. This could lead to local escalation of privilege on the lock screen with no additional execution privileges needed. User interaction is needed for exploitation.Product: AndroidVersions: Android-10Android ID: A-137102479 | 0% Низкий | около 4 лет назад | ||
GHSA-xr9q-h9c7-xw8q Rancher allows an unauthenticated stack overflow in /v3-public/authproviders API | CVSS3: 8.2 | 1% Низкий | больше 1 года назад | |
GHSA-xr9q-85p6-f6xr The Premium Age Verification / Restriction for WordPress plugin for WordPress is vulnerable to arbitrary file read and write due to the existence of an insufficiently protected remote support functionality in remote_tunnel.php in all versions up to, and including, 3.0.2. This makes it possible for unauthenticated attackers to read from or write to arbitrary files on the affected site's server which may make the exposure of sensitive information or remote code execution possible. | CVSS3: 9.8 | 1% Низкий | около 1 года назад | |
GHSA-xr9p-wqhw-3w78 Authenticated and encrypted payload MMEs can be forged and remotely sent to any HPAV2 system using a jailbreak key recoverable from code. | 1% Низкий | около 4 лет назад | ||
GHSA-xr9p-qj4x-c6c7 The ICQ Webserver allows remote attackers to use .. to access arbitrary files outside of the user's personal directory. | 2% Низкий | больше 4 лет назад | ||
GHSA-xr9p-mfhc-2mwc Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality via unknown vectors related to Test Manager for Web Apps. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the DownloadServlet servlet, which allows remote attackers to read arbitrary files via directory traversal sequences in the scriptPath parameter. | 22% Средний | около 4 лет назад | ||
GHSA-xr9m-34vg-p986 The Wipe Free Space utility in PGP Desktop Home 8.0 and Desktop Professional 9.0.3 Build 2932 and earlier does not clear file slack space in the last cluster for the file, which allows local users to access the previous contents of the disk. | 0% Низкий | больше 4 лет назад | ||
GHSA-xr9j-c7v6-7542 A use-after-free vulnerability was found in drivers/nvme/target/tcp.c` in `nvmet_tcp_free_crypto` due to a logical bug in the NVMe-oF/TCP subsystem in the Linux kernel. This issue may allow a malicious user to cause a use-after-free and double-free problem, which may permit remote code execution or lead to local privilege escalation in case that the attacker already has local privileges. | CVSS3: 8.8 | 9% Низкий | почти 3 года назад | |
GHSA-xr9j-92x7-g2w2 In Afian Filerun 20220202, lack of sanitization of the POST parameter "metadata[]" in `/?module=fileman§ion=get&page=grid` leads to SQL injection. | CVSS3: 8.8 | 1% Низкий | около 4 лет назад | |
GHSA-xr9j-2jxx-p2h8 Integer Overflow or Wraparound vulnerability in Ralim IronOS.This issue affects IronOS: before v2.23-rc2. | CVSS3: 9.8 | 0% Низкий | 6 месяцев назад | |
GHSA-xr9h-p2rc-rpqm WWBN/AVideo stored XSS vulnerability leads to takeover of any user's account, including admin's account | CVSS3: 8 | 1% Низкий | больше 3 лет назад |
Уязвимостей на страницу