Количество 375 356
Количество 375 356
GHSA-4r53-8549-7m3r
Envoy before 1.12.1 allows a remote denial of service because of resource loops, as demonstrated by a single idle TCP connection being able to keep a worker thread in an infinite busy loop when continue_on_listener_filters_timeout is used.
GHSA-4r52-wvcw-74vw
Clustered Data ONTAP versions prior to 9.7P13 and 9.8P3 are susceptible to a vulnerability which could allow single workloads to cause a Denial of Service (DoS) on a cluster node.
GHSA-4r52-jjv6-vvm7
Information loss or omission in Safebrowsing in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)
GHSA-4r52-fgmg-vqxc
Some HTTP security headers are not properly set by the web server when sending responses to the client application.
GHSA-4r52-ff3g-g952
The ath_rate_sample function in the ath_rate/sample/sample.c sample code in MadWifi before 0.9.3 allows remote attackers to cause a denial of service (failed KASSERT and system crash) by moving a connected system to a location with low signal strength, and possibly other vectors related to a race condition between interface enabling and packet transmission.
GHSA-4r4x-7f2r-2f4c
Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.1.2, 9.0.6, and 8.2.9 suffer from SMB User Authentication Bypass. Nextcloud/ownCloud include an optional and not by default enabled SMB authentication component that allows authenticating users against an SMB server. This backend is implemented in a way that tries to connect to a SMB server and if that succeeded consider the user logged-in. The backend did not properly take into account SMB servers that have any kind of anonymous auth configured. This is the default on SMB servers nowadays and allows an unauthenticated attacker to gain access to an account without valid credentials. Note: The SMB backend is disabled by default and requires manual configuration in the Nextcloud/ownCloud config file. If you have not configured the SMB backend then you're not affected by this vulnerability.
GHSA-4r4x-49qh-hfgv
Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 displays web service tokens associated with (1) disabled services and (2) users who no longer have authorization, which allows remote authenticated users to have an unspecified impact by reading these tokens.
GHSA-4r4w-h2xw-494x
Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information.
GHSA-4r4w-cm3v-q4m9
A vulnerability was found in itsourcecode Restaurant Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/member_save.php. The manipulation of the argument last leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.
GHSA-4r4w-2wgp-w7cj
Open WebUI Prompt history IDOR: unbound history_id allows cross-prompt read and deletion
GHSA-4r4v-x4wj-59wx
A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in Security Update 2022-003 Catalina, macOS Big Sur 11.6.5, macOS Monterey 12.3. A local user may be able to write arbitrary files.
GHSA-4r4v-f3wv-mqw2
A OS Command Injection vulnerability was discovered in Artica Proxy 4.30.000000. Attackers can execute OS commands in cyrus.events.php with GET param logs and POST param rp.
GHSA-4r4v-5gvp-ww57
SQL injection vulnerability in welcome.php in AJ Square AJ HYIP PRIME allows remote attackers to execute arbitrary SQL commands via the id parameter.
GHSA-4r4v-5cjx-r22j
SAP HANA extended application services, version 1, advanced does not sufficiently validate an XML document accepted from an authenticated developer with privileges to the SAP space (XML External Entity vulnerability).
GHSA-4r4v-4fqg-3m5p
In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf100283c.
GHSA-4r4v-3jc5-hrg9
TCC-TRANSACTION has an Improper Input Validation vulnerability
GHSA-4r4v-2j2q-ch33
A vulnerability, which was classified as problematic, has been found in yzane vscode-markdown-pdf 1.5.0. Affected by this issue is some unknown functionality of the component Markdown File Handler. The manipulation leads to pathname traversal. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.
GHSA-4r4r-hj2w-xx29
A low privileged admin account with a weak default password of admin exists on the Foxconn FEMTO AP-FC4064-T AP_GT_B38_5.8.3lb15-W47 LTE Build 15. In addition, its web management page relies on the existence or values of cookies when performing security-critical operations. One can gain privileges by modifying cookies.
GHSA-4r4r-4jp4-wwf9
FUXA has JWT Authentication Bypass via HTTP Referer header spoofing
GHSA-4r4r-44h4-6pmr
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Muji muji allows PHP Local File Inclusion.This issue affects Muji: from n/a through <= 1.2.0.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4r53-8549-7m3r Envoy before 1.12.1 allows a remote denial of service because of resource loops, as demonstrated by a single idle TCP connection being able to keep a worker thread in an infinite busy loop when continue_on_listener_filters_timeout is used. | 2% Низкий | больше 4 лет назад | ||
GHSA-4r52-wvcw-74vw Clustered Data ONTAP versions prior to 9.7P13 and 9.8P3 are susceptible to a vulnerability which could allow single workloads to cause a Denial of Service (DoS) on a cluster node. | 1% Низкий | больше 4 лет назад | ||
GHSA-4r52-jjv6-vvm7 Information loss or omission in Safebrowsing in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium) | CVSS3: 6.5 | 0% Низкий | 12 дней назад | |
GHSA-4r52-fgmg-vqxc Some HTTP security headers are not properly set by the web server when sending responses to the client application. | CVSS3: 6.1 | 0% Низкий | 7 месяцев назад | |
GHSA-4r52-ff3g-g952 The ath_rate_sample function in the ath_rate/sample/sample.c sample code in MadWifi before 0.9.3 allows remote attackers to cause a denial of service (failed KASSERT and system crash) by moving a connected system to a location with low signal strength, and possibly other vectors related to a race condition between interface enabling and packet transmission. | 2% Низкий | больше 4 лет назад | ||
GHSA-4r4x-7f2r-2f4c Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.1.2, 9.0.6, and 8.2.9 suffer from SMB User Authentication Bypass. Nextcloud/ownCloud include an optional and not by default enabled SMB authentication component that allows authenticating users against an SMB server. This backend is implemented in a way that tries to connect to a SMB server and if that succeeded consider the user logged-in. The backend did not properly take into account SMB servers that have any kind of anonymous auth configured. This is the default on SMB servers nowadays and allows an unauthenticated attacker to gain access to an account without valid credentials. Note: The SMB backend is disabled by default and requires manual configuration in the Nextcloud/ownCloud config file. If you have not configured the SMB backend then you're not affected by this vulnerability. | CVSS3: 8.1 | 4% Низкий | больше 4 лет назад | |
GHSA-4r4x-49qh-hfgv Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 displays web service tokens associated with (1) disabled services and (2) users who no longer have authorization, which allows remote authenticated users to have an unspecified impact by reading these tokens. | 1% Низкий | больше 4 лет назад | ||
GHSA-4r4w-h2xw-494x Incorrect authorization in Samsung Health prior to version 7.0.0 allows local attackers to access sensitive information. | CVSS3: 5.5 | 0% Низкий | около 1 месяца назад | |
GHSA-4r4w-cm3v-q4m9 A vulnerability was found in itsourcecode Restaurant Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/member_save.php. The manipulation of the argument last leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well. | CVSS3: 7.3 | 1% Низкий | больше 1 года назад | |
GHSA-4r4w-2wgp-w7cj Open WebUI Prompt history IDOR: unbound history_id allows cross-prompt read and deletion | CVSS3: 6.4 | 0% Низкий | 3 месяца назад | |
GHSA-4r4v-x4wj-59wx A validation issue existed in the handling of symlinks. This issue was addressed with improved validation of symlinks. This issue is fixed in Security Update 2022-003 Catalina, macOS Big Sur 11.6.5, macOS Monterey 12.3. A local user may be able to write arbitrary files. | CVSS3: 5.5 | 18% Средний | больше 3 лет назад | |
GHSA-4r4v-f3wv-mqw2 A OS Command Injection vulnerability was discovered in Artica Proxy 4.30.000000. Attackers can execute OS commands in cyrus.events.php with GET param logs and POST param rp. | CVSS3: 9.8 | 3% Низкий | больше 4 лет назад | |
GHSA-4r4v-5gvp-ww57 SQL injection vulnerability in welcome.php in AJ Square AJ HYIP PRIME allows remote attackers to execute arbitrary SQL commands via the id parameter. | 1% Низкий | больше 4 лет назад | ||
GHSA-4r4v-5cjx-r22j SAP HANA extended application services, version 1, advanced does not sufficiently validate an XML document accepted from an authenticated developer with privileges to the SAP space (XML External Entity vulnerability). | CVSS3: 6.5 | 2% Низкий | больше 4 лет назад | |
GHSA-4r4v-4fqg-3m5p In Windows Master (aka Windows Optimization Master) 7.99.13.604, the driver file (WoptiHWDetect.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0xf100283c. | CVSS3: 7.8 | 0% Низкий | больше 4 лет назад | |
GHSA-4r4v-3jc5-hrg9 TCC-TRANSACTION has an Improper Input Validation vulnerability | CVSS3: 6.3 | 0% Низкий | 4 месяца назад | |
GHSA-4r4v-2j2q-ch33 A vulnerability, which was classified as problematic, has been found in yzane vscode-markdown-pdf 1.5.0. Affected by this issue is some unknown functionality of the component Markdown File Handler. The manipulation leads to pathname traversal. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. | CVSS3: 3.3 | 0% Низкий | около 2 лет назад | |
GHSA-4r4r-hj2w-xx29 A low privileged admin account with a weak default password of admin exists on the Foxconn FEMTO AP-FC4064-T AP_GT_B38_5.8.3lb15-W47 LTE Build 15. In addition, its web management page relies on the existence or values of cookies when performing security-critical operations. One can gain privileges by modifying cookies. | CVSS3: 9.8 | 1% Низкий | больше 4 лет назад | |
GHSA-4r4r-4jp4-wwf9 FUXA has JWT Authentication Bypass via HTTP Referer header spoofing | CVSS3: 9.8 | 6% Низкий | 7 месяцев назад | |
GHSA-4r4r-44h4-6pmr Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Muji muji allows PHP Local File Inclusion.This issue affects Muji: from n/a through <= 1.2.0. | CVSS3: 8.1 | 1% Низкий | 8 месяцев назад |
Уязвимостей на страницу