Количество 375 727
Количество 375 727
GHSA-xrh4-q49w-whmw
A stored cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997) within the voicemail notification template functionality. The submit_modify_voicemail_template endpoint fails to properly sanitize HTML content supplied by authenticated users, allowing malicious JavaScript supplied through the template_text parameter to be stored server-side and subsequently rendered to other users.
GHSA-xrh3-5ph8-43qv
The Disk Images component in Apple OS X before 10.11.2 and tvOS before 9.1 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted disk image.
GHSA-xrh2-ccmq-qj77
Cross-site request forgery (CSRF) vulnerability in the qTranslate plugin 2.5.34 and earlier for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings via unspecified vectors.
GHSA-xrh2-c3rm-35jr
HornetQ REST vulnerable to Improper Restriction of XML External Entity Reference
GHSA-xrh2-77qw-v55j
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPFactory Products, Order & Customers Export for WooCommerce plugin <= 2.0.7 versions.
GHSA-xrgx-x8mj-82rp
drivers/net/ethernet/msm/rndis_ipa.c in the Qualcomm networking driver in Android allows remote attackers to execute arbitrary code via a crafted application compromising a privileged process.
GHSA-xrgw-w7v2-3qp8
A malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbGetMap overflowing the key_sym_map.
GHSA-xrgw-2g7f-5735
Buffer overflow in mDNSResponder in Apple Mac OS X 10.4 up to 10.4.9 allows remote attackers to cause a denial of service (application termination) or execute arbitrary code via a crafted UPnP Internet Gateway Device (IGD) packet.
GHSA-xrgv-hpqj-2pcx
Unspecified vulnerability in HP and H3C VPN Firewall Module products SECPATH1000FE before 5.20.R3177 and SECBLADEFW before 5.20.R3177 allows remote attackers to cause a denial of service via unknown vectors.
GHSA-xrgv-hghj-6jpj
Memory corruption in HAB Memory management due to broad system privileges via physical address.
GHSA-xrgv-34cc-q765
Duplicate Advisory: OpenClaw's system.run allowlist bypass via shell line-continuation command substitution
GHSA-xrgv-2w7g-m84q
IBM WebSphere Commerce 7.0 uses the same cryptographic key for session attributes and merchant data encryption, which has unspecified impact and remote attack vectors.
GHSA-xrgr-fwmm-m4vx
Unspecified vulnerability in Oracle HTTP Server component in Oracle Application Server 10.1.2.0.1, 10.1.2.0.2, and 10.1.2.1.0 has unknown impact and remote attack vectors related to the PHP Module, aka Vuln# OHS03.
GHSA-xrgq-7wvh-c25q
A vulnerability was found in Ruijie BCR810W 2.5.10. It has been rated as critical. This issue affects some unknown processing of the component Tracert Page. The manipulation leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-233477 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
GHSA-xrgp-qvwm-9p29
There is an Insufficient Path Validation Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
GHSA-xrgp-m4m8-gq98
Cross-site scripting (XSS) vulnerability in admin/changedata.php in GetSimple CMS 2.01 allows remote attackers to inject arbitrary web script or HTML via the post-title parameter.
GHSA-xrgp-j4fj-fqwr
A CWE-613 “Insufficient Session Expiration” vulnerability in the web application, due to the session cookie “sessionid” lasting two weeks, facilitates session hijacking attacks against victims. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.
GHSA-xrgp-8cmq-343v
Memory corruption in RIL while trying to send apdu packet.
GHSA-xrgm-w999-2hpq
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows attackers with access to the TX Host to execute code on the RX Host when a MySQL connector is configured.
GHSA-xrgj-4jq4-397w
Vulnerability in the Oracle XML Gateway component of Oracle E-Business Suite (subcomponent: Oracle Transport Agent). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle XML Gateway. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle XML Gateway, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle XML Gateway accessible data as well as unauthorized update, insert or delete access to some of Oracle XML Gateway accessible data. CVSS v3.0 Base Score 8.2 (Confidentiality and Integrity impacts).
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xrh4-q49w-whmw A stored cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997) within the voicemail notification template functionality. The submit_modify_voicemail_template endpoint fails to properly sanitize HTML content supplied by authenticated users, allowing malicious JavaScript supplied through the template_text parameter to be stored server-side and subsequently rendered to other users. | 0% Низкий | 2 месяца назад | ||
GHSA-xrh3-5ph8-43qv The Disk Images component in Apple OS X before 10.11.2 and tvOS before 9.1 allows local users to gain privileges or cause a denial of service (memory corruption) via a crafted disk image. | 1% Низкий | больше 4 лет назад | ||
GHSA-xrh2-ccmq-qj77 Cross-site request forgery (CSRF) vulnerability in the qTranslate plugin 2.5.34 and earlier for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings via unspecified vectors. | 1% Низкий | больше 4 лет назад | ||
GHSA-xrh2-c3rm-35jr HornetQ REST vulnerable to Improper Restriction of XML External Entity Reference | CVSS3: 6.5 | 1% Низкий | больше 4 лет назад | |
GHSA-xrh2-77qw-v55j Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WPFactory Products, Order & Customers Export for WooCommerce plugin <= 2.0.7 versions. | CVSS3: 7.1 | 0% Низкий | почти 3 года назад | |
GHSA-xrgx-x8mj-82rp drivers/net/ethernet/msm/rndis_ipa.c in the Qualcomm networking driver in Android allows remote attackers to execute arbitrary code via a crafted application compromising a privileged process. | CVSS3: 7 | 3% Низкий | больше 4 лет назад | |
GHSA-xrgw-w7v2-3qp8 A malicious X server could exploit a buffer overflow in libX11 before 1.8.14 during handling of XkbGetMap overflowing the key_sym_map. | CVSS3: 7.5 | 1 день назад | ||
GHSA-xrgw-2g7f-5735 Buffer overflow in mDNSResponder in Apple Mac OS X 10.4 up to 10.4.9 allows remote attackers to cause a denial of service (application termination) or execute arbitrary code via a crafted UPnP Internet Gateway Device (IGD) packet. | 50% Средний | больше 4 лет назад | ||
GHSA-xrgv-hpqj-2pcx Unspecified vulnerability in HP and H3C VPN Firewall Module products SECPATH1000FE before 5.20.R3177 and SECBLADEFW before 5.20.R3177 allows remote attackers to cause a denial of service via unknown vectors. | 3% Низкий | больше 4 лет назад | ||
GHSA-xrgv-hghj-6jpj Memory corruption in HAB Memory management due to broad system privileges via physical address. | CVSS3: 8.4 | 0% Низкий | больше 3 лет назад | |
GHSA-xrgv-34cc-q765 Duplicate Advisory: OpenClaw's system.run allowlist bypass via shell line-continuation command substitution | CVSS3: 5.9 | 6 месяцев назад | ||
GHSA-xrgv-2w7g-m84q IBM WebSphere Commerce 7.0 uses the same cryptographic key for session attributes and merchant data encryption, which has unspecified impact and remote attack vectors. | 1% Низкий | больше 4 лет назад | ||
GHSA-xrgr-fwmm-m4vx Unspecified vulnerability in Oracle HTTP Server component in Oracle Application Server 10.1.2.0.1, 10.1.2.0.2, and 10.1.2.1.0 has unknown impact and remote attack vectors related to the PHP Module, aka Vuln# OHS03. | 3% Низкий | больше 4 лет назад | ||
GHSA-xrgq-7wvh-c25q A vulnerability was found in Ruijie BCR810W 2.5.10. It has been rated as critical. This issue affects some unknown processing of the component Tracert Page. The manipulation leads to os command injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-233477 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 4.7 | 12% Средний | около 3 лет назад | |
GHSA-xrgp-qvwm-9p29 There is an Insufficient Path Validation Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3. | CVSS3: 7.8 | 1% Низкий | больше 4 лет назад | |
GHSA-xrgp-m4m8-gq98 Cross-site scripting (XSS) vulnerability in admin/changedata.php in GetSimple CMS 2.01 allows remote attackers to inject arbitrary web script or HTML via the post-title parameter. | 3% Низкий | больше 4 лет назад | ||
GHSA-xrgp-j4fj-fqwr A CWE-613 “Insufficient Session Expiration” vulnerability in the web application, due to the session cookie “sessionid” lasting two weeks, facilitates session hijacking attacks against victims. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2. | CVSS3: 5.6 | 0% Низкий | больше 2 лет назад | |
GHSA-xrgp-8cmq-343v Memory corruption in RIL while trying to send apdu packet. | CVSS3: 6.7 | 0% Низкий | около 3 лет назад | |
GHSA-xrgm-w999-2hpq Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in Waterfall WF-500 RX Host in version 7.9.1.0 R2502171040 that allows attackers with access to the TX Host to execute code on the RX Host when a MySQL connector is configured. | CVSS3: 7.8 | 1% Низкий | 4 месяца назад | |
GHSA-xrgj-4jq4-397w Vulnerability in the Oracle XML Gateway component of Oracle E-Business Suite (subcomponent: Oracle Transport Agent). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle XML Gateway. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle XML Gateway, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle XML Gateway accessible data as well as unauthorized update, insert or delete access to some of Oracle XML Gateway accessible data. CVSS v3.0 Base Score 8.2 (Confidentiality and Integrity impacts). | CVSS3: 8.2 | 2% Низкий | больше 4 лет назад |
Уязвимостей на страницу