Количество 375 268
Количество 375 268
GHSA-4q9c-68c7-fxff
TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the pppoePass parameter in the setIpv6Cfg function.
GHSA-4q9c-6763-78hw
Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Install). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. While the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Manager Base Platform accessible data as well as unauthorized read access to a subset of Oracle Enterprise Manager Base Platform accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVS...
GHSA-4q98-wr72-h35w
Improper input validation in Apache Santuario XML Security for Java
GHSA-4q98-p85m-4p54
Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the mac parameter at /goform/GetParentControlInfo.
GHSA-4q98-jf5r-gpmg
In findAvailSpellCheckerLocked of TextServicesManagerService.java, there is a possible way to bypass the warning dialog when selecting an untrusted spell checker due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0Android ID: A-118694079
GHSA-4q98-f277-w2f4
The default_encrypt function in encrypt.c in IRC Services before 5.0.63, and 5.1.x before 5.1.7, allows remote attackers to cause a denial of service (daemon crash) via a long password. NOTE: some of these details are obtained from third party information.
GHSA-4q97-mrgv-92q2
jhead v3.08 was discovered to contain a heap-use-after-free via the ProcessFile function at jhead.c.
GHSA-4q97-g4xv-35c8
IBM Security Guardium 8.2, 9.0, and 10.0 contains a vulnerability that could allow a local attacker with CLI access to inject arbitrary commands which would be executed as root. IBM X-Force ID: 121174.
GHSA-4q97-fh3f-j294
Prototype Pollution in tiny-conf
GHSA-4q96-h8mr-4mvm
Missing Authorization vulnerability in Avirtum iPanorama 360 WordPress Virtual Tour Builder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects iPanorama 360 WordPress Virtual Tour Builder: from n/a through 1.8.3.
GHSA-4q96-9f63-p7jj
Path Traversal in ImpressCMS
GHSA-4q96-97v6-xq9v
The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges.
GHSA-4q96-6xhq-ff43
malicious SVG attachment causing stored XSS vulnerability
GHSA-4q95-v5vg-fjc2
SOPlanning 1.45 is vulnerable to a CSRF attack that allows for arbitrary user creation via process/xajax_server.php.
GHSA-4q95-6mw3-3rm5
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
GHSA-4q95-263m-g434
Unspecified vulnerability in the Pegasus CIM Server in IBM Hardware Management Console (HMC) 7 R3.2.0 allows remote attackers to cause a denial of service via unspecified vectors.
GHSA-4q94-m8w5-hxm3
Rejected reason: Not used
GHSA-4q93-v92x-p89f
Keycloak Vulnerable to Incorrect Authorization
GHSA-4q93-fvm9-qjff
A reflected XSS vulnerability exists in Quest KACE Systems Management Appliance Server Center 9.1.317 affecting the userui/software_library.php component via the PATH_INFO.
GHSA-4q93-6p46-6x3h
An issue was discovered in Quest KACE Agent for Windows 12.0.38 and 13.1.23.0. An Arbitrary file create vulnerability exists in the KSchedulerSvc.exe, KUserAlert.exe, and Runkbot.exe components. This allows local attackers to create any file of their choice with NT Authority\SYSTEM privileges.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4q9c-68c7-fxff TOTOLINK A3300R V17.0.0cu.557_B20221024 was discovered to contain a command injection vulnerability via the pppoePass parameter in the setIpv6Cfg function. | CVSS3: 9.8 | 2% Низкий | больше 2 лет назад | |
GHSA-4q9c-6763-78hw Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Install). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows high privileged attacker with network access via HTTPS to compromise Oracle Enterprise Manager Base Platform. While the vulnerability is in Oracle Enterprise Manager Base Platform, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Enterprise Manager Base Platform accessible data as well as unauthorized read access to a subset of Oracle Enterprise Manager Base Platform accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Enterprise Manager Base Platform. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVS... | CVSS3: 9 | 0% Низкий | 3 месяца назад | |
GHSA-4q98-wr72-h35w Improper input validation in Apache Santuario XML Security for Java | CVSS3: 5.5 | 1% Низкий | около 7 лет назад | |
GHSA-4q98-p85m-4p54 Tenda F1203 V2.0.1.6 was discovered to contain a buffer overflow via the mac parameter at /goform/GetParentControlInfo. | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | |
GHSA-4q98-jf5r-gpmg In findAvailSpellCheckerLocked of TextServicesManagerService.java, there is a possible way to bypass the warning dialog when selecting an untrusted spell checker due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0Android ID: A-118694079 | CVSS3: 7.8 | 0% Низкий | больше 4 лет назад | |
GHSA-4q98-f277-w2f4 The default_encrypt function in encrypt.c in IRC Services before 5.0.63, and 5.1.x before 5.1.7, allows remote attackers to cause a denial of service (daemon crash) via a long password. NOTE: some of these details are obtained from third party information. | 2% Низкий | больше 4 лет назад | ||
GHSA-4q97-mrgv-92q2 jhead v3.08 was discovered to contain a heap-use-after-free via the ProcessFile function at jhead.c. | CVSS3: 7.8 | 0% Низкий | больше 1 года назад | |
GHSA-4q97-g4xv-35c8 IBM Security Guardium 8.2, 9.0, and 10.0 contains a vulnerability that could allow a local attacker with CLI access to inject arbitrary commands which would be executed as root. IBM X-Force ID: 121174. | CVSS3: 7.4 | 0% Низкий | больше 4 лет назад | |
GHSA-4q97-fh3f-j294 Prototype Pollution in tiny-conf | CVSS3: 9.8 | 2% Низкий | больше 5 лет назад | |
GHSA-4q96-h8mr-4mvm Missing Authorization vulnerability in Avirtum iPanorama 360 WordPress Virtual Tour Builder allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects iPanorama 360 WordPress Virtual Tour Builder: from n/a through 1.8.3. | CVSS3: 5.3 | 0% Низкий | почти 2 года назад | |
GHSA-4q96-9f63-p7jj Path Traversal in ImpressCMS | CVSS3: 8.1 | 3% Низкий | больше 4 лет назад | |
GHSA-4q96-97v6-xq9v The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges. | CVSS3: 9.8 | 1% Низкий | больше 4 лет назад | |
GHSA-4q96-6xhq-ff43 malicious SVG attachment causing stored XSS vulnerability | CVSS3: 8.7 | 2% Низкий | почти 6 лет назад | |
GHSA-4q95-v5vg-fjc2 SOPlanning 1.45 is vulnerable to a CSRF attack that allows for arbitrary user creation via process/xajax_server.php. | 1% Низкий | больше 4 лет назад | ||
GHSA-4q95-6mw3-3rm5 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | 9 месяцев назад | |||
GHSA-4q95-263m-g434 Unspecified vulnerability in the Pegasus CIM Server in IBM Hardware Management Console (HMC) 7 R3.2.0 allows remote attackers to cause a denial of service via unspecified vectors. | 2% Низкий | больше 4 лет назад | ||
GHSA-4q94-m8w5-hxm3 Rejected reason: Not used | больше 1 года назад | |||
GHSA-4q93-v92x-p89f Keycloak Vulnerable to Incorrect Authorization | CVSS3: 4.3 | 0% Низкий | 4 месяца назад | |
GHSA-4q93-fvm9-qjff A reflected XSS vulnerability exists in Quest KACE Systems Management Appliance Server Center 9.1.317 affecting the userui/software_library.php component via the PATH_INFO. | 1% Низкий | больше 4 лет назад | ||
GHSA-4q93-6p46-6x3h An issue was discovered in Quest KACE Agent for Windows 12.0.38 and 13.1.23.0. An Arbitrary file create vulnerability exists in the KSchedulerSvc.exe, KUserAlert.exe, and Runkbot.exe components. This allows local attackers to create any file of their choice with NT Authority\SYSTEM privileges. | CVSS3: 6.6 | 0% Низкий | больше 2 лет назад |
Уязвимостей на страницу