Количество 371 326
Количество 371 326
GHSA-4g82-3jcr-q52w
Malware in ctx
GHSA-4g7x-pvhw-3mph
In isp, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09071481; Issue ID: MSV-1730.
GHSA-4g7x-7vgq-3j28
Vulnerability in list function leads to arbitrary code execution via filePath parameters
GHSA-4g7v-x2gv-v9qf
Heap-based buffer overflow in the opj_j2k_read_SPCod_SPCoc function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome before 51.0.2704.63, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PDF document.
GHSA-4g7v-38jx-hv6c
In wifi service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed
GHSA-4g7r-3q85-mg82
SGI syserr program allows local users to corrupt files.
GHSA-4g7q-xrgc-v37w
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Ashan Perera EventON allows PHP Local File Inclusion. This issue affects EventON: from n/a through 2.3.2.
GHSA-4g7q-85r5-pm7w
Improper usage of implicit intent in Bluetooth prior to SMR Mar-2023 Release 1 allows attacker to get MAC address of connected device.
GHSA-4g7q-85g4-qw3w
A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the web-based management interface on an affected system. An attacker could exploit this vulnerability by persuading a user of the interface to click a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user. These actions could include modifying the system configuration and deleting accounts.
GHSA-4g7q-7v9w-3x8m
DoS in KAS in GitLab CE/EE affecting all versions from 16.10.0 prior to 16.10.6 and 16.11.0 prior to 16.11.3 allows an attacker to crash KAS via crafted gRPC requests.
GHSA-4g7q-7553-2768
Improper permissions for Intel(R) USB 3.0 Creator Utility all versions may allow an authenticated user to potentially enable escalation of privilege via local access.
GHSA-4g7q-44qp-cc5c
Concrete CMS is vulnerable to unauthenticated file usage disclosure
GHSA-4g7p-889h-qvww
Authenticated privilege escalation in NetScaler Console and NetScaler Agent allows.
GHSA-4g7p-5pq3-g6vh
An exploitable vulnerability exists in the remote control functionality of Circle with Disney running firmware 2.0.1. SSL certificates for specific domain names can cause the goclient daemon to accept a different certificate than intended. An attacker can host an HTTPS server with this certificate to trigger this vulnerability.
GHSA-4g7p-53pf-4mw9
Improper input validation in the Central Filestore in Ivanti Avalanche 6.3.1 allows a remote authenticated attacker with admin rights to achieve RCE.
GHSA-4g7m-g45x-47rp
In the Linux kernel, the following vulnerability has been resolved: ovl: fix warning in ovl_create_real() Syzbot triggered the following warning in ovl_workdir_create() -> ovl_create_real(): if (!err && WARN_ON(!newdentry->d_inode)) { The reason is that the cgroup2 filesystem returns from mkdir without instantiating the new dentry. Weird filesystems such as this will be rejected by overlayfs at a later stage during setup, but to prevent such a warning, call ovl_mkdir_real() directly from ovl_workdir_create() and reject this case early.
GHSA-4g7m-fgrx-qqc3
Cisco IOS 12.3 and 12.4 on Aironet access points allows remote attackers to cause a denial of service (radio-interface input-queue hang) via IAPP 0x3281 packets, aka Bug ID CSCtc12426.
GHSA-4g7j-qx49-cxcp
Improper authentication vulnerability in Proself Enterprise/Standard Edition Ver5.61 and earlier, Proself Gateway Edition Ver1.62 and earlier, and Proself Mail Sanitize Edition Ver1.07 and earlier allow a remote unauthenticated attacker to log in to the product's Control Panel and perform an unintended operation.
GHSA-4g7j-fjgw-f3qw
IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) Rev J-M and (X3/MX100 for Rev M only), and Avalon Fetal/Maternal Monitors FM20/FM30/FM40/FM50 with software Revisions F.0, G.0 and J.3 have a vulnerability that allows an unauthenticated attacker to access memory ("write-what-where") from an attacker-chosen device address within the same subnet.
GHSA-4g7j-ccqc-2759
The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), as well as the management of access rights for such IP, including modification of a license-deny response to a license grant. The methods are flawed and, in the most egregious cases, enable attack vectors that allow recovery of the entire underlying plaintext IP. Implementations of IEEE P1735 may be weak to cryptographic attacks that allow an attacker to obtain plaintext intellectual property without the key, among other impacts.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4g82-3jcr-q52w Malware in ctx | больше 4 лет назад | |||
GHSA-4g7x-pvhw-3mph In isp, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09071481; Issue ID: MSV-1730. | CVSS3: 4.4 | 0% Низкий | почти 2 года назад | |
GHSA-4g7x-7vgq-3j28 Vulnerability in list function leads to arbitrary code execution via filePath parameters | CVSS3: 9.8 | 2% Низкий | почти 5 лет назад | |
GHSA-4g7v-x2gv-v9qf Heap-based buffer overflow in the opj_j2k_read_SPCod_SPCoc function in j2k.c in OpenJPEG, as used in PDFium in Google Chrome before 51.0.2704.63, allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PDF document. | CVSS3: 8.8 | 2% Низкий | больше 4 лет назад | |
GHSA-4g7v-38jx-hv6c In wifi service, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service with no additional execution privileges needed | CVSS3: 5.5 | 0% Низкий | почти 3 года назад | |
GHSA-4g7r-3q85-mg82 SGI syserr program allows local users to corrupt files. | 0% Низкий | больше 4 лет назад | ||
GHSA-4g7q-xrgc-v37w Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Ashan Perera EventON allows PHP Local File Inclusion. This issue affects EventON: from n/a through 2.3.2. | CVSS3: 8.8 | 2% Низкий | больше 1 года назад | |
GHSA-4g7q-85r5-pm7w Improper usage of implicit intent in Bluetooth prior to SMR Mar-2023 Release 1 allows attacker to get MAC address of connected device. | CVSS3: 3.3 | 0% Низкий | больше 3 лет назад | |
GHSA-4g7q-85g4-qw3w A vulnerability in the web-based management interface of Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the web-based management interface on an affected system. An attacker could exploit this vulnerability by persuading a user of the interface to click a malicious link. A successful exploit could allow the attacker to perform arbitrary actions with the privilege level of the affected user. These actions could include modifying the system configuration and deleting accounts. | CVSS3: 8.1 | 0% Низкий | больше 3 лет назад | |
GHSA-4g7q-7v9w-3x8m DoS in KAS in GitLab CE/EE affecting all versions from 16.10.0 prior to 16.10.6 and 16.11.0 prior to 16.11.3 allows an attacker to crash KAS via crafted gRPC requests. | CVSS3: 3.1 | 0% Низкий | больше 2 лет назад | |
GHSA-4g7q-7553-2768 Improper permissions for Intel(R) USB 3.0 Creator Utility all versions may allow an authenticated user to potentially enable escalation of privilege via local access. | CVSS3: 7.8 | 0% Низкий | больше 4 лет назад | |
GHSA-4g7q-44qp-cc5c Concrete CMS is vulnerable to unauthenticated file usage disclosure | 1% Низкий | 4 месяца назад | ||
GHSA-4g7p-889h-qvww Authenticated privilege escalation in NetScaler Console and NetScaler Agent allows. | CVSS3: 8.8 | 13% Средний | больше 1 года назад | |
GHSA-4g7p-5pq3-g6vh An exploitable vulnerability exists in the remote control functionality of Circle with Disney running firmware 2.0.1. SSL certificates for specific domain names can cause the goclient daemon to accept a different certificate than intended. An attacker can host an HTTPS server with this certificate to trigger this vulnerability. | CVSS3: 5.9 | 1% Низкий | больше 4 лет назад | |
GHSA-4g7p-53pf-4mw9 Improper input validation in the Central Filestore in Ivanti Avalanche 6.3.1 allows a remote authenticated attacker with admin rights to achieve RCE. | CVSS3: 7.2 | 2% Низкий | около 2 лет назад | |
GHSA-4g7m-g45x-47rp In the Linux kernel, the following vulnerability has been resolved: ovl: fix warning in ovl_create_real() Syzbot triggered the following warning in ovl_workdir_create() -> ovl_create_real(): if (!err && WARN_ON(!newdentry->d_inode)) { The reason is that the cgroup2 filesystem returns from mkdir without instantiating the new dentry. Weird filesystems such as this will be rejected by overlayfs at a later stage during setup, but to prevent such a warning, call ovl_mkdir_real() directly from ovl_workdir_create() and reject this case early. | CVSS3: 5.5 | 0% Низкий | около 2 лет назад | |
GHSA-4g7m-fgrx-qqc3 Cisco IOS 12.3 and 12.4 on Aironet access points allows remote attackers to cause a denial of service (radio-interface input-queue hang) via IAPP 0x3281 packets, aka Bug ID CSCtc12426. | 2% Низкий | больше 4 лет назад | ||
GHSA-4g7j-qx49-cxcp Improper authentication vulnerability in Proself Enterprise/Standard Edition Ver5.61 and earlier, Proself Gateway Edition Ver1.62 and earlier, and Proself Mail Sanitize Edition Ver1.07 and earlier allow a remote unauthenticated attacker to log in to the product's Control Panel and perform an unintended operation. | CVSS3: 7.5 | 1% Низкий | около 3 лет назад | |
GHSA-4g7j-fjgw-f3qw IntelliVue Patient Monitors MP Series (including MP2/X2/MP30/MP50/MP70/NP90/MX700/800) Rev B-M, IntelliVue Patient Monitors MX (MX400-550) Rev J-M and (X3/MX100 for Rev M only), and Avalon Fetal/Maternal Monitors FM20/FM30/FM40/FM50 with software Revisions F.0, G.0 and J.3 have a vulnerability that allows an unauthenticated attacker to access memory ("write-what-where") from an attacker-chosen device address within the same subnet. | CVSS3: 8.3 | 0% Низкий | больше 4 лет назад | |
GHSA-4g7j-ccqc-2759 The P1735 IEEE standard describes flawed methods for encrypting electronic-design intellectual property (IP), as well as the management of access rights for such IP, including modification of a license-deny response to a license grant. The methods are flawed and, in the most egregious cases, enable attack vectors that allow recovery of the entire underlying plaintext IP. Implementations of IEEE P1735 may be weak to cryptographic attacks that allow an attacker to obtain plaintext intellectual property without the key, among other impacts. | CVSS3: 7.8 | 0% Низкий | больше 4 лет назад |
Уязвимостей на страницу