Количество 322 267
Количество 322 267
GHSA-22jv-36fh-m28x
A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application does not properly implement brute force protection against user credentials in its Client Communication component. This could allow an attacker to learn user credentials that are vulnerable to brute force attacks.
GHSA-22jr-vc7j-g762
Potential buffer overflow in psd-tools
GHSA-22jr-qpvv-v9f3
A vulnerability was determined in Campcodes Online Learning Management System 1.0. Affected is an unknown function of the file /admin/add_content.php. Executing manipulation of the argument Title can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
GHSA-22jr-jqv2-c6r8
Missing Authentication for Critical Function vulnerability in ABB ALS-mini-s4 IP, ABB ALS-mini-s8 IP.This issue affects . All firmware versions with the Serial Number from 2000 to 5166
GHSA-22jr-f6pc-522x
Tanium addressed an insertion of sensitive information into log file vulnerability in Trends.
GHSA-22jq-crhx-w9j5
The COPPA error page in the Accounts setup dialog in Mozilla Firefox OS before 2.2 embeds content from an external web server URL into the System process, which allows man-in-the-middle attackers to bypass intended access restrictions by spoofing that server.
GHSA-22jq-62mj-8hw3
Directory traversal vulnerability in download.php in Sisfo Kampus 0.8 allows remote attackers to list arbitrary directories via an absolute pathname in the dir parameter.
GHSA-22jq-22rq-52q5
Multiple unspecified vulnerabilities in the (1) Mobile IP NAT Traversal feature and (2) Mobile IPv6 subsystem in Cisco IOS 12.3 through 12.4 allow remote attackers to cause a denial of service (input queue wedge and interface outage) via MIPv6 packets, aka Bug ID CSCsm97220.
GHSA-22jp-w3cg-gvmm
Liferay Portal has Stored Cross-Site Scripting Vulnerability via Message Boards Feature
GHSA-22jp-m5f3-q68p
Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier version, 2017.011.30138 and earlier version, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.
GHSA-22jm-p2vv-j2hc
Plone XSS
GHSA-22jm-gmg3-6r8v
Cross-site scripting (XSS) vulnerability in board.php in mowdBB RC-6 allows remote attackers to inject arbitrary web script or HTML via the forum_name[] parameter.
GHSA-22jm-4hxw-35jf
OpenStack Nova can leak consoleauth token into log files
GHSA-22jj-r264-9ffc
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PressTigers ZIP Code Based Content Protection allows SQL Injection. This issue affects ZIP Code Based Content Protection: from n/a through 1.0.0.
GHSA-22jj-744v-92v5
livehelperchat is vulnerable to Generation of Error Message Containing Sensitive Information
GHSA-22jh-hqf7-v4mw
Windows Network Address Translation (NAT) Denial of Service Vulnerability.
GHSA-22jh-6gx8-f944
Elastic APM agent for Python client CGI proxy redirection flaw
GHSA-22jh-5463-4m46
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/blog/blogpublish.php.
GHSA-22jg-rc3r-96wc
Real Media RealServer (rmserver) 6.0.3.353 stores a password in plaintext in the world-readable rmserver.cfg file, which allows local users to gain privileges.
GHSA-22jf-gccc-jpfh
VCFTools vcfools prior to version 0.1.15 is affected by: Heap Use-After-Free. The impact is: Denial of Service or possibly unspecified impact (eg. code execution or information disclosure). The component is: The header::add_FILTER_descriptor method in header.cpp. The attack vector is: The victim must open a specially crafted VCF file.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-22jv-36fh-m28x A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP1). The affected application does not properly implement brute force protection against user credentials in its Client Communication component. This could allow an attacker to learn user credentials that are vulnerable to brute force attacks. | CVSS3: 7.5 | 0% Низкий | больше 1 года назад | |
GHSA-22jr-vc7j-g762 Potential buffer overflow in psd-tools | CVSS3: 9.8 | 0% Низкий | около 6 лет назад | |
GHSA-22jr-qpvv-v9f3 A vulnerability was determined in Campcodes Online Learning Management System 1.0. Affected is an unknown function of the file /admin/add_content.php. Executing manipulation of the argument Title can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. | CVSS3: 7.3 | 0% Низкий | 6 месяцев назад | |
GHSA-22jr-jqv2-c6r8 Missing Authentication for Critical Function vulnerability in ABB ALS-mini-s4 IP, ABB ALS-mini-s8 IP.This issue affects . All firmware versions with the Serial Number from 2000 to 5166 | CVSS3: 9.1 | 0% Низкий | 5 месяцев назад | |
GHSA-22jr-f6pc-522x Tanium addressed an insertion of sensitive information into log file vulnerability in Trends. | CVSS3: 6.5 | 0% Низкий | около 1 месяца назад | |
GHSA-22jq-crhx-w9j5 The COPPA error page in the Accounts setup dialog in Mozilla Firefox OS before 2.2 embeds content from an external web server URL into the System process, which allows man-in-the-middle attackers to bypass intended access restrictions by spoofing that server. | 0% Низкий | почти 4 года назад | ||
GHSA-22jq-62mj-8hw3 Directory traversal vulnerability in download.php in Sisfo Kampus 0.8 allows remote attackers to list arbitrary directories via an absolute pathname in the dir parameter. | 6% Низкий | почти 4 года назад | ||
GHSA-22jq-22rq-52q5 Multiple unspecified vulnerabilities in the (1) Mobile IP NAT Traversal feature and (2) Mobile IPv6 subsystem in Cisco IOS 12.3 through 12.4 allow remote attackers to cause a denial of service (input queue wedge and interface outage) via MIPv6 packets, aka Bug ID CSCsm97220. | 1% Низкий | почти 4 года назад | ||
GHSA-22jp-w3cg-gvmm Liferay Portal has Stored Cross-Site Scripting Vulnerability via Message Boards Feature | 0% Низкий | 7 месяцев назад | ||
GHSA-22jp-m5f3-q68p Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier version, 2017.011.30138 and earlier version, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution. | CVSS3: 6.5 | 7% Низкий | почти 4 года назад | |
GHSA-22jm-p2vv-j2hc Plone XSS | CVSS3: 6.1 | 0% Низкий | почти 4 года назад | |
GHSA-22jm-gmg3-6r8v Cross-site scripting (XSS) vulnerability in board.php in mowdBB RC-6 allows remote attackers to inject arbitrary web script or HTML via the forum_name[] parameter. | 1% Низкий | почти 4 года назад | ||
GHSA-22jm-4hxw-35jf OpenStack Nova can leak consoleauth token into log files | CVSS3: 3.3 | 0% Низкий | почти 4 года назад | |
GHSA-22jj-r264-9ffc Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PressTigers ZIP Code Based Content Protection allows SQL Injection. This issue affects ZIP Code Based Content Protection: from n/a through 1.0.0. | CVSS3: 7.6 | 0% Низкий | 7 месяцев назад | |
GHSA-22jj-744v-92v5 livehelperchat is vulnerable to Generation of Error Message Containing Sensitive Information | 0% Низкий | около 4 лет назад | ||
GHSA-22jh-hqf7-v4mw Windows Network Address Translation (NAT) Denial of Service Vulnerability. | CVSS3: 7.5 | 24% Средний | почти 4 года назад | |
GHSA-22jh-6gx8-f944 Elastic APM agent for Python client CGI proxy redirection flaw | CVSS3: 7.2 | 0% Низкий | почти 4 года назад | |
GHSA-22jh-5463-4m46 Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/blog/blogpublish.php. | 0% Низкий | почти 4 года назад | ||
GHSA-22jg-rc3r-96wc Real Media RealServer (rmserver) 6.0.3.353 stores a password in plaintext in the world-readable rmserver.cfg file, which allows local users to gain privileges. | 0% Низкий | почти 4 года назад | ||
GHSA-22jf-gccc-jpfh VCFTools vcfools prior to version 0.1.15 is affected by: Heap Use-After-Free. The impact is: Denial of Service or possibly unspecified impact (eg. code execution or information disclosure). The component is: The header::add_FILTER_descriptor method in header.cpp. The attack vector is: The victim must open a specially crafted VCF file. | почти 4 года назад |
Уязвимостей на страницу