Количество 375 356
Количество 375 356
GHSA-4r6q-r4w3-542r
Unspecified vulnerability in Oracle Sun Java System Access Manager and Oracle OpenSSO 7, 7.1, and 8 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
GHSA-4r6q-cp7v-3g84
Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub component of Oracle PeopleSoft Products (subcomponent: HTML Area). The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PRTL Interaction Hub. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PRTL Interaction Hub, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PRTL Interaction Hub accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PRTL Interaction Hub accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N).
GHSA-4r6p-r9pm-m3ff
The sockets subsystem in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allows attackers to gain privileges via a crafted application that uses (1) the AF_MSM_IPC socket class or (2) another socket class that is unrecognized by SELinux, aka internal bug 28612709.
GHSA-4r6p-ff6w-vwv3
NETGEAR ReadyNAS OS 6 devices, running ReadyNAS OS versions prior to 6.8.0 are affected by stored XSS.
GHSA-4r6p-5938-6337
In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WritePNGImage of coders/png.c, related to Magick_png_write_raw_profile and LocaleNCompare.
GHSA-4r6m-j55r-vxwv
The quicktime_user_atoms_read_atom function in useratoms.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) via a crafted mp4 file.
GHSA-4r6j-v785-r8vc
74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /job.
GHSA-4r6j-p6gq-79w6
Verydows 2.0 has XSS via the index.php?c=main a parameter, as demonstrated by an a=index[XSS] value.
GHSA-4r6j-fwcx-94cf
snowflake-connector-python is vulnerable to Regular Expression Denial of Service (ReDoS)
GHSA-4r6h-8v6p-xvw6
Prototype Pollution in sheetJS
GHSA-4r6h-5v86-94p3
LiquidJS: Uncontrolled Resource Consumption in `join` filter allows template authors to bypass `memoryLimit` and crash the process
GHSA-4r6h-327w-8qwr
libvterm through 0+bzr726, as used in Vim and other products, mishandles certain out-of-memory conditions, leading to a denial of service (application crash), related to screen.c, state.c, and vterm.c.
GHSA-4r6g-xhx7-fm36
Contao Core directory traversal vulnerability
GHSA-4r6g-prvv-3gp3
An issue was discovered in Percona XtraDB Cluster before 5.7.28-31.42. A bundled script inadvertently sets a static transition_key for SST processes in place of the random key expected.
GHSA-4r6g-pqff-6vpv
Adobe DNG Converter versions 9.7 and earlier have an exploitable memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.
GHSA-4r6g-jg94-h27c
An issue was discovered in Finder on Samsung mobile devices with Q(10.0) software. A call to a non-existent provider allows attackers to cause a denial of service. The Samsung ID is SVE-2020-18629 (December 2020).
GHSA-4r6f-r3vj-r486
An issue was discovered in the Linux kernel before 5.2.1. There is a use-after-free caused by a malicious USB device in the drivers/net/wireless/intersil/p54/p54usb.c driver.
GHSA-4r6f-9cpw-f6g6
(Web) MQTT with PROXY Protocol enabled: a loopback-only user permission bypass
GHSA-4r6c-hgqq-rr35
A buffer overflow can be triggered in LeviStudio HMI Editor, Version 1.10 part of Wecon LeviStudioU 1.8.29, and PI Studio HMI Project Programmer, Build: November 11, 2017 and prior by opening a specially crafted file.
GHSA-4r6c-7c28-gmfr
Pega Platform from 8.5.4 to 8.7.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4r6q-r4w3-542r Unspecified vulnerability in Oracle Sun Java System Access Manager and Oracle OpenSSO 7, 7.1, and 8 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. | 2% Низкий | больше 4 лет назад | ||
GHSA-4r6q-cp7v-3g84 Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub component of Oracle PeopleSoft Products (subcomponent: HTML Area). The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise PRTL Interaction Hub. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PeopleSoft Enterprise PRTL Interaction Hub, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PeopleSoft Enterprise PRTL Interaction Hub accessible data as well as unauthorized read access to a subset of PeopleSoft Enterprise PRTL Interaction Hub accessible data. CVSS 3.0 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). | CVSS3: 6.1 | 1% Низкий | больше 4 лет назад | |
GHSA-4r6p-r9pm-m3ff The sockets subsystem in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-07-01 allows attackers to gain privileges via a crafted application that uses (1) the AF_MSM_IPC socket class or (2) another socket class that is unrecognized by SELinux, aka internal bug 28612709. | CVSS3: 7.8 | 0% Низкий | больше 4 лет назад | |
GHSA-4r6p-ff6w-vwv3 NETGEAR ReadyNAS OS 6 devices, running ReadyNAS OS versions prior to 6.8.0 are affected by stored XSS. | 0% Низкий | больше 4 лет назад | ||
GHSA-4r6p-5938-6337 In ImageMagick 7.0.8-43 Q16, there is a heap-based buffer over-read in the function WritePNGImage of coders/png.c, related to Magick_png_write_raw_profile and LocaleNCompare. | CVSS3: 9.1 | 3% Низкий | больше 4 лет назад | |
GHSA-4r6m-j55r-vxwv The quicktime_user_atoms_read_atom function in useratoms.c in libquicktime 1.2.4 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) via a crafted mp4 file. | CVSS3: 6.5 | 5% Низкий | больше 4 лет назад | |
GHSA-4r6j-v785-r8vc 74cmsSE v3.5.1 was discovered to contain a reflective cross-site scripting (XSS) vulnerability via the path /job. | CVSS3: 6.1 | 1% Низкий | около 4 лет назад | |
GHSA-4r6j-p6gq-79w6 Verydows 2.0 has XSS via the index.php?c=main a parameter, as demonstrated by an a=index[XSS] value. | CVSS3: 6.1 | 1% Низкий | больше 4 лет назад | |
GHSA-4r6j-fwcx-94cf snowflake-connector-python is vulnerable to Regular Expression Denial of Service (ReDoS) | CVSS3: 5.9 | 1% Низкий | почти 4 года назад | |
GHSA-4r6h-8v6p-xvw6 Prototype Pollution in sheetJS | CVSS3: 7.8 | 1% Низкий | больше 3 лет назад | |
GHSA-4r6h-5v86-94p3 LiquidJS: Uncontrolled Resource Consumption in `join` filter allows template authors to bypass `memoryLimit` and crash the process | CVSS3: 7.5 | 0% Низкий | 12 дней назад | |
GHSA-4r6h-327w-8qwr libvterm through 0+bzr726, as used in Vim and other products, mishandles certain out-of-memory conditions, leading to a denial of service (application crash), related to screen.c, state.c, and vterm.c. | CVSS3: 7.5 | 3% Низкий | больше 4 лет назад | |
GHSA-4r6g-xhx7-fm36 Contao Core directory traversal vulnerability | CVSS3: 4.3 | 1% Низкий | больше 4 лет назад | |
GHSA-4r6g-prvv-3gp3 An issue was discovered in Percona XtraDB Cluster before 5.7.28-31.42. A bundled script inadvertently sets a static transition_key for SST processes in place of the random key expected. | CVSS3: 8.1 | 2% Низкий | больше 4 лет назад | |
GHSA-4r6g-pqff-6vpv Adobe DNG Converter versions 9.7 and earlier have an exploitable memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution. | CVSS3: 9.8 | 4% Низкий | больше 4 лет назад | |
GHSA-4r6g-jg94-h27c An issue was discovered in Finder on Samsung mobile devices with Q(10.0) software. A call to a non-existent provider allows attackers to cause a denial of service. The Samsung ID is SVE-2020-18629 (December 2020). | 0% Низкий | больше 4 лет назад | ||
GHSA-4r6f-r3vj-r486 An issue was discovered in the Linux kernel before 5.2.1. There is a use-after-free caused by a malicious USB device in the drivers/net/wireless/intersil/p54/p54usb.c driver. | CVSS3: 4.6 | 1% Низкий | больше 4 лет назад | |
GHSA-4r6f-9cpw-f6g6 (Web) MQTT with PROXY Protocol enabled: a loopback-only user permission bypass | около 2 месяцев назад | |||
GHSA-4r6c-hgqq-rr35 A buffer overflow can be triggered in LeviStudio HMI Editor, Version 1.10 part of Wecon LeviStudioU 1.8.29, and PI Studio HMI Project Programmer, Build: November 11, 2017 and prior by opening a specially crafted file. | CVSS3: 5.3 | 1% Низкий | больше 4 лет назад | |
GHSA-4r6c-7c28-gmfr Pega Platform from 8.5.4 to 8.7.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter. | CVSS3: 6.1 | 1% Низкий | около 4 лет назад |
Уязвимостей на страницу