Количество 324 922
Количество 324 922
GHSA-29gh-3cpv-qpjp
Check Point Endpoint Security Client E83 through E86 before E86.50 does not protect against a specific registry modification, and thus allows a local administrator to disable endpoint protection.
GHSA-29gg-qvj7-46c7
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
GHSA-29gg-8679-22q3
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Availability Suite Service). Supported versions that are affected are 10 and 11.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this vulnerability can result in takeover of Solaris. CVSS 3.0 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
GHSA-29gc-r2qh-wc5v
A memory initialization issue was addressed with improved memory handling. This issue is fixed in tvOS 26.2, Safari 26.2, watchOS 26.2, visionOS 26.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2. Processing maliciously crafted web content may disclose internal states of the app.
GHSA-29gc-hgfp-33m5
A Blind SQL Injection Vulnerability in Exponent CMS through 2.4.0, with the rerank array parameter, can lead to site database information disclosure and denial of service.
GHSA-29g9-qwhc-hg77
Directory traversal vulnerability in Cybozu Garoon 4.2.4 to 4.2.5 allows an attacker to read arbitrary files via Garoon SOAP API "WorkflowHandleApplications".
GHSA-29g9-48v7-9r7c
Authorization Bypass Through User-Controlled Key vulnerability in Paid Memberships Pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Paid Memberships Pro: from n/a through 3.0.4.
GHSA-29g8-w5j3-pph4
A service which is hosted on port 6998 in HiNet GPON firmware < I040GWR190731 allows an attacker to execute a specific command to read arbitrary files. CVSS 3.0 Base score 9.3. CVSS vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L).
GHSA-29g8-6h62-f7vc
Heap-based buffer overflow in Pedro Lineu Orso chetcpasswd 2.3.3 allows local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long REMOTE_ADDR environment variable. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.
GHSA-29g7-m78g-3fx6
serial_ports administrative program in IRIX 4.x and 5.x trusts the user's PATH environmental variable to find and execute the ls program, which allows local users to gain root privileges via a Trojan horse ls program.
GHSA-29g7-g95p-w4ww
Cross-site scripting (XSS) vulnerability in takeprofedit.php in TBDev.NET DR 11-10-05-BETA-SF1:111005 and earlier allows remote attackers to inject arbitrary web script or HTML via the SRC attribute of a SCRIPT element in the avatar parameter. NOTE: this may be related to the tracker program in the Janitor package. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
GHSA-29g7-9vcg-g9rm
Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to change the passwords of other non-admin users and thus to escalate non-root privileges.
GHSA-29g5-m8v7-v564
Measured is vulnerable to Path Traversal attacks during class initialization
GHSA-29g4-35pw-347h
A buffer overflow vulnerability exists in Symantec Messaging Gateway versions 9.5 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as root.
GHSA-29g3-4frr-8p4r
Cross-site scripting (XSS) vulnerability in BarracudaDrive Web Server before 3.8 allows remote attackers to inject arbitrary web script or HTML via the URI path in an HTTP GET request, which is activated by administrators viewing log files via the Trace page.
GHSA-29g3-3hqg-cw9q
The H2O Human Harmony Organization (aka com.netpia.ha.theh2o) application 1.6.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
GHSA-29g3-2vmh-rhvh
Buffer overflow vulnerability in the sensor service. Successful exploitation of this vulnerability may affect availability.
GHSA-29g2-mrxj-jw38
In Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iCloud for Windows before 7.6, multiple memory corruption issues were addressed with improved memory handling.
GHSA-29g2-j2qf-h8qw
Out of bounds memory access in the gamepad API in Google Chrome prior to 78.0.3904.70 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
GHSA-29g2-g2r5-p4x5
SchedMD Slurm before 17.11.13 and 18.x before 18.08.5 mishandles 32-bit systems.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-29gh-3cpv-qpjp Check Point Endpoint Security Client E83 through E86 before E86.50 does not protect against a specific registry modification, and thus allows a local administrator to disable endpoint protection. | CVSS3: 2.3 | 1% Низкий | больше 3 лет назад | |
GHSA-29gg-qvj7-46c7 Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally. | CVSS3: 7.8 | 1% Низкий | 10 месяцев назад | |
GHSA-29gg-8679-22q3 Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Availability Suite Service). Supported versions that are affected are 10 and 11.3. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Solaris executes to compromise Solaris. Successful attacks of this vulnerability can result in takeover of Solaris. CVSS 3.0 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). | CVSS3: 7.8 | 2% Низкий | почти 4 года назад | |
GHSA-29gc-r2qh-wc5v A memory initialization issue was addressed with improved memory handling. This issue is fixed in tvOS 26.2, Safari 26.2, watchOS 26.2, visionOS 26.2, iOS 26.2 and iPadOS 26.2, macOS Tahoe 26.2. Processing maliciously crafted web content may disclose internal states of the app. | CVSS3: 4.3 | 0% Низкий | 3 месяца назад | |
GHSA-29gc-hgfp-33m5 A Blind SQL Injection Vulnerability in Exponent CMS through 2.4.0, with the rerank array parameter, can lead to site database information disclosure and denial of service. | CVSS3: 9.1 | 1% Низкий | почти 4 года назад | |
GHSA-29g9-qwhc-hg77 Directory traversal vulnerability in Cybozu Garoon 4.2.4 to 4.2.5 allows an attacker to read arbitrary files via Garoon SOAP API "WorkflowHandleApplications". | CVSS3: 4.3 | 1% Низкий | почти 4 года назад | |
GHSA-29g9-48v7-9r7c Authorization Bypass Through User-Controlled Key vulnerability in Paid Memberships Pro allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Paid Memberships Pro: from n/a through 3.0.4. | CVSS3: 7.5 | 0% Низкий | больше 1 года назад | |
GHSA-29g8-w5j3-pph4 A service which is hosted on port 6998 in HiNet GPON firmware < I040GWR190731 allows an attacker to execute a specific command to read arbitrary files. CVSS 3.0 Base score 9.3. CVSS vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:L). | 0% Низкий | почти 4 года назад | ||
GHSA-29g8-6h62-f7vc Heap-based buffer overflow in Pedro Lineu Orso chetcpasswd 2.3.3 allows local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long REMOTE_ADDR environment variable. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. | 0% Низкий | почти 4 года назад | ||
GHSA-29g7-m78g-3fx6 serial_ports administrative program in IRIX 4.x and 5.x trusts the user's PATH environmental variable to find and execute the ls program, which allows local users to gain root privileges via a Trojan horse ls program. | 0% Низкий | почти 4 года назад | ||
GHSA-29g7-g95p-w4ww Cross-site scripting (XSS) vulnerability in takeprofedit.php in TBDev.NET DR 11-10-05-BETA-SF1:111005 and earlier allows remote attackers to inject arbitrary web script or HTML via the SRC attribute of a SCRIPT element in the avatar parameter. NOTE: this may be related to the tracker program in the Janitor package. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 3% Низкий | почти 4 года назад | ||
GHSA-29g7-9vcg-g9rm Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to change the passwords of other non-admin users and thus to escalate non-root privileges. | CVSS3: 5.3 | 0% Низкий | больше 2 лет назад | |
GHSA-29g5-m8v7-v564 Measured is vulnerable to Path Traversal attacks during class initialization | 9 месяцев назад | |||
GHSA-29g4-35pw-347h A buffer overflow vulnerability exists in Symantec Messaging Gateway versions 9.5 and before. A remote, anonymous attacker can exploit this vulnerability to achieve remote code execution as root. | CVSS3: 10 | 2% Низкий | около 2 лет назад | |
GHSA-29g3-4frr-8p4r Cross-site scripting (XSS) vulnerability in BarracudaDrive Web Server before 3.8 allows remote attackers to inject arbitrary web script or HTML via the URI path in an HTTP GET request, which is activated by administrators viewing log files via the Trace page. | 4% Низкий | почти 4 года назад | ||
GHSA-29g3-3hqg-cw9q The H2O Human Harmony Organization (aka com.netpia.ha.theh2o) application 1.6.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 0% Низкий | почти 4 года назад | ||
GHSA-29g3-2vmh-rhvh Buffer overflow vulnerability in the sensor service. Successful exploitation of this vulnerability may affect availability. | CVSS3: 5.9 | 0% Низкий | 6 месяцев назад | |
GHSA-29g2-mrxj-jw38 In Safari before 11.1.2, iTunes before 12.8 for Windows, iOS before 11.4.1, tvOS before 11.4.1, iCloud for Windows before 7.6, multiple memory corruption issues were addressed with improved memory handling. | CVSS3: 8.8 | 1% Низкий | почти 4 года назад | |
GHSA-29g2-j2qf-h8qw Out of bounds memory access in the gamepad API in Google Chrome prior to 78.0.3904.70 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. | CVSS3: 8.8 | 1% Низкий | почти 4 года назад | |
GHSA-29g2-g2r5-p4x5 SchedMD Slurm before 17.11.13 and 18.x before 18.08.5 mishandles 32-bit systems. | CVSS3: 9.8 | 1% Низкий | почти 4 года назад |
Уязвимостей на страницу