Количество 323 083
Количество 323 083
GHSA-22qf-62f9-pj62
As a part of Tenable’s vulnerability disclosure program, a vulnerability in a Nessus plugin was identified and reported. This vulnerability could allow a malicious actor with sufficient permissions on a scan target to place a binary in a specific filesystem location, and abuse the impacted plugin in order to escalate privileges.
GHSA-22q9-m8j5-x7xg
cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_make32() function at cute_png.h.
GHSA-22q9-hqm5-mhmc
Cross-Site Scripting in swagger-ui
GHSA-22q9-7cmf-jjxp
The LDAP component in Fedora Directory Server 1.0 allow remote attackers to cause a denial of service (crash) via a certain "bad BER sequence" that results in a free of uninitialized memory, as demonstrated using the ProtoVer LDAP test suite.
GHSA-22q8-rwx9-62gg
A vulnerability was found in Campcodes Legal Case Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /admin/court-type. The manipulation of the argument court_name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263805 was assigned to this vulnerability.
GHSA-22q8-ghmq-63vf
libgit2-sys affected by memory corruption, denial of service, and arbitrary code execution in libgit2
GHSA-22q7-qw7f-w974
Norton Password Manager, prior to 6.6.2.5, may be susceptible to an information disclosure issue, which is a type of vulnerability whereby there is an unintentional disclosure of information to an actor that is not explicitly authorized to have access to that information.
GHSA-22q7-cg4r-p9mx
TYPO3 Cross-Site Scripting in Fluid ViewHelpers
GHSA-22q6-wwq7-2jj9
OpenStack Keystone Improper Authentication vulnerability
GHSA-22q6-rw64-5gjj
Zoho ManageEngine ADManager Plus before 7183 allows admin users to exploit an XXE issue to view files.
GHSA-22q6-hvj2-jgmw
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 150905.
GHSA-22q6-9rvj-cmpf
Buffer Overflow in Emerson GE Automation Proficy Machine Edition v8.0 allows an attacker to cause a denial of service and application crash via crafted traffic from a Man-in-the-Middle (MITM) attack to the component "FrameworX.exe" in the module "MSVCR100.dll".
GHSA-22q6-7m3g-6r77
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
GHSA-22q5-qg84-2p5f
Unspecified vulnerability in the OCI component in Oracle Database Server 10.2.0.3, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect confidentiality and integrity via unknown vectors.
GHSA-22q5-9phm-744v
XWiki allows unregistered users to access private pages information through REST endpoint
GHSA-22q5-57p4-rxcv
Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The web application improperly protects credentials which could allow an attacker to obtain credentials for remote access to controllers.
GHSA-22q4-f5r6-3xqw
The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable.
GHSA-22q4-5758-44qv
Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to SERVER:DML.
GHSA-22q3-mmfp-g262
Multiple unspecified vulnerabilities in DFLabs PTK 1.0.0 through 1.0.4 allow remote attackers to execute arbitrary commands in processes launched by PTK's Apache HTTP Server via (1) "external tools" or (2) a crafted forensic image.
GHSA-22q3-4v32-4m7c
Tmall_demo v2024.07.03 was discovered to contain an arbitrary file upload via the component uploadUserHeadImage.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-22qf-62f9-pj62 As a part of Tenable’s vulnerability disclosure program, a vulnerability in a Nessus plugin was identified and reported. This vulnerability could allow a malicious actor with sufficient permissions on a scan target to place a binary in a specific filesystem location, and abuse the impacted plugin in order to escalate privileges. | CVSS3: 7.8 | 0% Низкий | около 2 лет назад | |
GHSA-22q9-m8j5-x7xg cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_make32() function at cute_png.h. | CVSS3: 7.8 | 0% Низкий | больше 1 года назад | |
GHSA-22q9-hqm5-mhmc Cross-Site Scripting in swagger-ui | больше 5 лет назад | |||
GHSA-22q9-7cmf-jjxp The LDAP component in Fedora Directory Server 1.0 allow remote attackers to cause a denial of service (crash) via a certain "bad BER sequence" that results in a free of uninitialized memory, as demonstrated using the ProtoVer LDAP test suite. | 1% Низкий | почти 4 года назад | ||
GHSA-22q8-rwx9-62gg A vulnerability was found in Campcodes Legal Case Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /admin/court-type. The manipulation of the argument court_name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263805 was assigned to this vulnerability. | CVSS3: 3.5 | 0% Низкий | почти 2 года назад | |
GHSA-22q8-ghmq-63vf libgit2-sys affected by memory corruption, denial of service, and arbitrary code execution in libgit2 | CVSS3: 8.6 | около 2 лет назад | ||
GHSA-22q7-qw7f-w974 Norton Password Manager, prior to 6.6.2.5, may be susceptible to an information disclosure issue, which is a type of vulnerability whereby there is an unintentional disclosure of information to an actor that is not explicitly authorized to have access to that information. | 0% Низкий | почти 4 года назад | ||
GHSA-22q7-cg4r-p9mx TYPO3 Cross-Site Scripting in Fluid ViewHelpers | CVSS3: 6.1 | почти 2 года назад | ||
GHSA-22q6-wwq7-2jj9 OpenStack Keystone Improper Authentication vulnerability | CVSS3: 5.3 | 1% Низкий | почти 4 года назад | |
GHSA-22q6-rw64-5gjj Zoho ManageEngine ADManager Plus before 7183 allows admin users to exploit an XXE issue to view files. | CVSS3: 4.9 | 1% Низкий | больше 2 лет назад | |
GHSA-22q6-hvj2-jgmw IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 150905. | CVSS3: 7.1 | 1% Низкий | почти 4 года назад | |
GHSA-22q6-9rvj-cmpf Buffer Overflow in Emerson GE Automation Proficy Machine Edition v8.0 allows an attacker to cause a denial of service and application crash via crafted traffic from a Man-in-the-Middle (MITM) attack to the component "FrameworX.exe" in the module "MSVCR100.dll". | 0% Низкий | почти 4 года назад | ||
GHSA-22q6-7m3g-6r77 An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | CVSS3: 9.1 | 11% Средний | больше 1 года назад | |
GHSA-22q5-qg84-2p5f Unspecified vulnerability in the OCI component in Oracle Database Server 10.2.0.3, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect confidentiality and integrity via unknown vectors. | 0% Низкий | почти 4 года назад | ||
GHSA-22q5-9phm-744v XWiki allows unregistered users to access private pages information through REST endpoint | 0% Низкий | около 1 года назад | ||
GHSA-22q5-57p4-rxcv Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The web application improperly protects credentials which could allow an attacker to obtain credentials for remote access to controllers. | CVSS3: 9.8 | 0% Низкий | почти 4 года назад | |
GHSA-22q4-f5r6-3xqw The iconv() function in the GNU C Library versions 2.39 and older may overflow the output buffer passed to it by up to 4 bytes when converting strings to the ISO-2022-CN-EXT character set, which may be used to crash an application or overwrite a neighbouring variable. | CVSS3: 7.3 | 93% Критический | почти 2 года назад | |
GHSA-22q4-5758-44qv Unspecified vulnerability in Oracle MySQL Server 5.5.39 and earlier, and 5.6.20 and earlier, allows remote authenticated users to affect confidentiality, integrity, and availability via vectors related to SERVER:DML. | 1% Низкий | почти 4 года назад | ||
GHSA-22q3-mmfp-g262 Multiple unspecified vulnerabilities in DFLabs PTK 1.0.0 through 1.0.4 allow remote attackers to execute arbitrary commands in processes launched by PTK's Apache HTTP Server via (1) "external tools" or (2) a crafted forensic image. | 2% Низкий | почти 4 года назад | ||
GHSA-22q3-4v32-4m7c Tmall_demo v2024.07.03 was discovered to contain an arbitrary file upload via the component uploadUserHeadImage. | CVSS3: 4.9 | 0% Низкий | больше 1 года назад |
Уязвимостей на страницу