Количество 376 080
Количество 376 080
GHSA-4wv5-vfv3-96c7
HPE Matrix Operating Environment before 7.5.1 allows remote attackers to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2016-4358.
GHSA-4wv5-g426-4246
A Stored Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 in many application forms. An attacker can inject an Angular expression and escape the Angular sandbox to achieve stored XSS. This can lead to privilege escalation.
GHSA-4wv4-xcmf-c3qh
HCL AppScan Source 9.0.3.13 and earlier is susceptible to cross-site scripting (XSS) attacks by allowing users to embed arbitrary JavaScript code in the Web UI.
GHSA-4wv4-mgfq-598v
Code injection in nobelprizeparser
GHSA-4wv4-6mjq-34pw
FlexPaperViewer.swf in Flexpaper before 2.3.1 allows remote attackers to conduct content-spoofing attacks via the Swfile parameter.
GHSA-4wv3-vrp8-r748
Integer overflow in the FlipFileTypeAtom_BtoN function in Apple Quicktime 7.1.5, and other versions before 7.2, allows remote attackers to execute arbitrary code via a crafted M4V (MP4) file.
GHSA-4wv3-q9v5-fp5m
Untrusted search path vulnerability in the perf_config function in tools/perf/util/config.c in perf, as distributed in the Linux kernel before 3.1, allows local users to overwrite arbitrary files via a crafted config file in the current working directory.
GHSA-4wv3-4xwf-g4g6
The sahab-alkher.com (aka com.tapatalk.sahabalkhercomvb) application 2.4.9.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
GHSA-4wv3-22h6-h824
Microsoft Exchange Server Remote Code Execution Vulnerability
GHSA-4wv2-5vm5-r9cc
SQL injection vulnerability in users.php in PHP Gift Registry 1.5.5 allows remote authenticated users to execute arbitrary SQL commands via the userid parameter in an edit action.
GHSA-4wv2-475w-c2fw
An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting parse_group_prop_ntr_selection_method in lib/ofp-util.c. When decoding a group mod, it validates the group type and command after the whole group mod has been decoded. The OF1.5 decoder, however, tries to use the type and command earlier, when it might still be invalid. This causes an assertion failure (via OVS_NOT_REACHED). ovs-vswitchd does not enable support for OpenFlow 1.5 by default.
GHSA-4wrx-2682-w227
resend command in Majordomo allows local users to gain privileges via shell metacharacters.
GHSA-4wrw-r87c-p2q9
Incorrect access control in the setWanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter upstream provisioning and connectivity via sending a crafted POST request to /cgi-bin/cstecgi.cgi.
GHSA-4wrw-jm7c-gf3x
sot/source/sdstor/stgstrms.cxx in LibreOffice before 5.4.5.1 and 6.x before 6.0.1.1 uses an incorrect integer data type in the StgSmallStrm class, which allows remote attackers to cause a denial of service (use-after-free with write access) or possibly have unspecified other impact via a crafted document that uses the structured storage ole2 wrapper file format.
GHSA-4wrw-g53q-g424
A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'. This CVE ID is unique from CVE-2019-0866, CVE-2019-0867, CVE-2019-0868, CVE-2019-0870.
GHSA-4wrv-p79w-3qmj
An issue was discovered in DouCo DouPHP 1.5 20181221. admin/product.php?rec=update has XSS via the name parameter.
GHSA-4wrv-c229-vc5p
SAP Financial Consolidation allows an unauthenticated attacker to gain unauthorized access to the Admin account. The vulnerability arises due to improper authentication mechanisms, due to which there is high impact on the Confidentiality, Integrity & Availability of the application.
GHSA-4wrr-xw2g-w6m2
Directory traversal vulnerability in gallerie.php in SL_site 1.0 allows remote attackers to list images in arbitrary directories via ".." sequences in the rep parameter, which is used to construct a directory name in admin/config.inc.php. NOTE: this issue could be used to produce resultant XSS from an error message.
GHSA-4wrr-wx49-f3mw
A relative path traversal vulnerability [CWE-23] in FortiWeb 7.0.0 through 7.0.1, 6.3.6 through 6.3.18, 6.4 all versions may allow an authenticated attacker to obtain unauthorized access to files and data via specifically crafted HTTP GET requests.
GHSA-4wrr-9h5r-m92w
Apache Struts Remote Java Code Execution
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4wv5-vfv3-96c7 HPE Matrix Operating Environment before 7.5.1 allows remote attackers to obtain sensitive information or modify data via unspecified vectors, a different vulnerability than CVE-2016-4358. | CVSS3: 9.1 | 4% Низкий | больше 4 лет назад | |
GHSA-4wv5-g426-4246 A Stored Client Side Template Injection (CSTI) with Angular was discovered in the SolarWinds Orion Platform 2019.2 HF1 in many application forms. An attacker can inject an Angular expression and escape the Angular sandbox to achieve stored XSS. This can lead to privilege escalation. | 2% Низкий | больше 4 лет назад | ||
GHSA-4wv4-xcmf-c3qh HCL AppScan Source 9.0.3.13 and earlier is susceptible to cross-site scripting (XSS) attacks by allowing users to embed arbitrary JavaScript code in the Web UI. | 1% Низкий | больше 4 лет назад | ||
GHSA-4wv4-mgfq-598v Code injection in nobelprizeparser | больше 5 лет назад | |||
GHSA-4wv4-6mjq-34pw FlexPaperViewer.swf in Flexpaper before 2.3.1 allows remote attackers to conduct content-spoofing attacks via the Swfile parameter. | CVSS3: 6.1 | 1% Низкий | больше 4 лет назад | |
GHSA-4wv3-vrp8-r748 Integer overflow in the FlipFileTypeAtom_BtoN function in Apple Quicktime 7.1.5, and other versions before 7.2, allows remote attackers to execute arbitrary code via a crafted M4V (MP4) file. | 6% Низкий | больше 4 лет назад | ||
GHSA-4wv3-q9v5-fp5m Untrusted search path vulnerability in the perf_config function in tools/perf/util/config.c in perf, as distributed in the Linux kernel before 3.1, allows local users to overwrite arbitrary files via a crafted config file in the current working directory. | 0% Низкий | больше 4 лет назад | ||
GHSA-4wv3-4xwf-g4g6 The sahab-alkher.com (aka com.tapatalk.sahabalkhercomvb) application 2.4.9.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 0% Низкий | больше 4 лет назад | ||
GHSA-4wv3-22h6-h824 Microsoft Exchange Server Remote Code Execution Vulnerability | CVSS3: 8 | 6% Низкий | около 3 лет назад | |
GHSA-4wv2-5vm5-r9cc SQL injection vulnerability in users.php in PHP Gift Registry 1.5.5 allows remote authenticated users to execute arbitrary SQL commands via the userid parameter in an edit action. | 1% Низкий | больше 4 лет назад | ||
GHSA-4wv2-475w-c2fw An issue was discovered in Open vSwitch (OvS) 2.7.x through 2.7.6, affecting parse_group_prop_ntr_selection_method in lib/ofp-util.c. When decoding a group mod, it validates the group type and command after the whole group mod has been decoded. The OF1.5 decoder, however, tries to use the type and command earlier, when it might still be invalid. This causes an assertion failure (via OVS_NOT_REACHED). ovs-vswitchd does not enable support for OpenFlow 1.5 by default. | CVSS3: 4.3 | 2% Низкий | больше 4 лет назад | |
GHSA-4wrx-2682-w227 resend command in Majordomo allows local users to gain privileges via shell metacharacters. | 1% Низкий | больше 4 лет назад | ||
GHSA-4wrw-r87c-p2q9 Incorrect access control in the setWanCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to alter upstream provisioning and connectivity via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | CVSS3: 9.1 | 0% Низкий | 23 дня назад | |
GHSA-4wrw-jm7c-gf3x sot/source/sdstor/stgstrms.cxx in LibreOffice before 5.4.5.1 and 6.x before 6.0.1.1 uses an incorrect integer data type in the StgSmallStrm class, which allows remote attackers to cause a denial of service (use-after-free with write access) or possibly have unspecified other impact via a crafted document that uses the structured storage ole2 wrapper file format. | CVSS3: 7.8 | 2% Низкий | больше 4 лет назад | |
GHSA-4wrw-g53q-g424 A Cross-site Scripting (XSS) vulnerability exists when Azure DevOps Server and Team Foundation Server do not properly sanitize user provided input, aka 'Azure DevOps Server and Team Foundation Server Cross-site Scripting Vulnerability'. This CVE ID is unique from CVE-2019-0866, CVE-2019-0867, CVE-2019-0868, CVE-2019-0870. | CVSS3: 6.1 | 2% Низкий | больше 4 лет назад | |
GHSA-4wrv-p79w-3qmj An issue was discovered in DouCo DouPHP 1.5 20181221. admin/product.php?rec=update has XSS via the name parameter. | CVSS3: 4.8 | 1% Низкий | больше 4 лет назад | |
GHSA-4wrv-c229-vc5p SAP Financial Consolidation allows an unauthenticated attacker to gain unauthorized access to the Admin account. The vulnerability arises due to improper authentication mechanisms, due to which there is high impact on the Confidentiality, Integrity & Availability of the application. | CVSS3: 9.8 | 1% Низкий | больше 1 года назад | |
GHSA-4wrr-xw2g-w6m2 Directory traversal vulnerability in gallerie.php in SL_site 1.0 allows remote attackers to list images in arbitrary directories via ".." sequences in the rep parameter, which is used to construct a directory name in admin/config.inc.php. NOTE: this issue could be used to produce resultant XSS from an error message. | 2% Низкий | больше 4 лет назад | ||
GHSA-4wrr-wx49-f3mw A relative path traversal vulnerability [CWE-23] in FortiWeb 7.0.0 through 7.0.1, 6.3.6 through 6.3.18, 6.4 all versions may allow an authenticated attacker to obtain unauthorized access to files and data via specifically crafted HTTP GET requests. | CVSS3: 6.5 | 1% Низкий | больше 3 лет назад | |
GHSA-4wrr-9h5r-m92w Apache Struts Remote Java Code Execution | CVSS3: 9.8 | 76% Высокий | больше 4 лет назад |
Уязвимостей на страницу