Количество 370 914
Количество 370 914
GHSA-4f7q-xq4j-fmj8
Server Side Request Forgery (SSRF) vulnerability exists in owncloud/user_ldap < 0.15.4 in the settings of the user_ldap app. Administration role is necessary for exploitation.
GHSA-4f7q-fvgr-jx57
The TV Bengali Open Directory (aka com.TVBengali) application 1.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
GHSA-4f7p-mhh6-p6r7
The XML parser in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 allows remote authenticated administrators to read arbitrary files or cause a denial of service via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
GHSA-4f7p-jr5x-cg78
Improper authentication in the firmware for the Intel(R) Slim Bootloader may allow a privileged user to potentially enable escalation of privilege via local access.
GHSA-4f7p-398v-2rw7
A vulnerability in the management API of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an unauthenticated, remote attacker to read and modify the outgoing proxy configuration settings. This vulnerability is due to the lack of authentication in an API endpoint. An attacker could exploit this vulnerability by sending a request to the affected API of a Catalyst Center device. A successful exploit could allow the attacker to view or modify the outgoing proxy configuration, which could disrupt internet traffic from Cisco Catalyst Center or may allow the attacker to intercept outbound internet traffic.
GHSA-4f7p-27jc-3c36
HTTP Request Smuggling in waitress
GHSA-4f7m-v6hv-9hcr
An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.50, kernel 5.5 before version 05.54.50, kernel 5.6 before version 05.61.50, and kernel 5.7 before version 05.70.50. In VariableRuntimeDxe driver, SmmUpdateVariablePropertySmi () is a SMM callback function and it uses StrCmp () to compare variable names. This action may cause a buffer over-read.
GHSA-4f7m-gcp2-rqr8
EMC Isilon OneFS 7.1 before 7.1.1.8, 7.2.0 before 7.2.0.4, and 7.2.1 before 7.2.1.1 allows remote authenticated administrators to bypass a SmartLock root-login restriction by creating a root account and establishing a login session.
GHSA-4f7j-xf8r-8572
Missing authentication in the SearchStudentsRFID method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction sensitive student data by unauthenticated attackers.
GHSA-4f7j-px6v-m38x
Wazuh SIEM version 4.8.2 is affected by a broken access control vulnerability. This issue allows the unauthorized creation of internal users without assigning any existing user role, potentially leading to privilege escalation or unauthorized access to sensitive resources.
GHSA-4f7j-5j3r-xxc5
Certain NETGEAR devices are affected by stored XSS. This affects D6100 before 1.0.0.63, DM200 before 1.0.0.61, R7800 before 1.0.2.52, R8900 before 1.0.4.12, R9000 before 1.0.4.12, WN3000RPv2 before 1.0.0.68, and WNR2000v5 before 1.0.0.66.
GHSA-4f7h-9j2x-cmr4
Improper Authentication in Apache Tomcat
GHSA-4f7g-mqhx-8h4r
In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Fix a possible memory leak In bnxt_re_setup_chip_ctx() when bnxt_qplib_map_db_bar() fails driver is not freeing the memory allocated for "rdev->chip_ctx".
GHSA-4f7g-j96w-63jv
Remote Procedure Call Runtime Denial of Service Vulnerability
GHSA-4f7g-c479-3cx4
SeaCMS 6.61 has two XSS issues in the admin_config.php file via certain form fields.
GHSA-4f7c-pmjv-c25w
Apache Log4net: Silent log event loss in XmlLayout and XmlLayoutSchemaLog4J due to unescaped XML 1.0 forbidden characters
GHSA-4f7c-mrrq-rv96
Cross-site scripting (XSS) vulnerability in avatar.php for CoolForum 0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the img parameter.
GHSA-4f7c-f5r2-23hx
Xen 4.4.x and earlier, when using a large number of VCPUs, does not properly handle read and write locks, which allows local x86 guest users to cause a denial of service (write denial or NMI watchdog timeout and host crash) via a large number of read requests, a different vulnerability than CVE-2014-9065.
GHSA-4f7c-7x79-wr4p
Successful exploitation of the vulnerability could allow an unauthenticated attacker to conduct brute force guessing and account takeover as the session cookies are predictable, potentially allowing the attackers to gain root, admin or user access and reset passwords.
GHSA-4f7c-6xx9-hvm8
Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2024.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4f7q-xq4j-fmj8 Server Side Request Forgery (SSRF) vulnerability exists in owncloud/user_ldap < 0.15.4 in the settings of the user_ldap app. Administration role is necessary for exploitation. | 1% Низкий | больше 4 лет назад | ||
GHSA-4f7q-fvgr-jx57 The TV Bengali Open Directory (aka com.TVBengali) application 1.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 0% Низкий | больше 4 лет назад | ||
GHSA-4f7p-mhh6-p6r7 The XML parser in Lifecycle Query Engine (LQE) in IBM Jazz Reporting Service 6.0 and 6.0.1 before 6.0.1 iFix006 allows remote authenticated administrators to read arbitrary files or cause a denial of service via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | CVSS3: 7.5 | 2% Низкий | больше 4 лет назад | |
GHSA-4f7p-jr5x-cg78 Improper authentication in the firmware for the Intel(R) Slim Bootloader may allow a privileged user to potentially enable escalation of privilege via local access. | CVSS3: 7.5 | 0% Низкий | больше 1 года назад | |
GHSA-4f7p-398v-2rw7 A vulnerability in the management API of Cisco Catalyst Center, formerly Cisco DNA Center, could allow an unauthenticated, remote attacker to read and modify the outgoing proxy configuration settings. This vulnerability is due to the lack of authentication in an API endpoint. An attacker could exploit this vulnerability by sending a request to the affected API of a Catalyst Center device. A successful exploit could allow the attacker to view or modify the outgoing proxy configuration, which could disrupt internet traffic from Cisco Catalyst Center or may allow the attacker to intercept outbound internet traffic. | CVSS3: 7.3 | 0% Низкий | больше 1 года назад | |
GHSA-4f7p-27jc-3c36 HTTP Request Smuggling in waitress | CVSS3: 7.5 | 2% Низкий | больше 4 лет назад | |
GHSA-4f7m-v6hv-9hcr An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.50, kernel 5.5 before version 05.54.50, kernel 5.6 before version 05.61.50, and kernel 5.7 before version 05.70.50. In VariableRuntimeDxe driver, SmmUpdateVariablePropertySmi () is a SMM callback function and it uses StrCmp () to compare variable names. This action may cause a buffer over-read. | CVSS3: 7.5 | 0% Низкий | больше 1 года назад | |
GHSA-4f7m-gcp2-rqr8 EMC Isilon OneFS 7.1 before 7.1.1.8, 7.2.0 before 7.2.0.4, and 7.2.1 before 7.2.1.1 allows remote authenticated administrators to bypass a SmartLock root-login restriction by creating a root account and establishing a login session. | CVSS3: 8 | 2% Низкий | больше 4 лет назад | |
GHSA-4f7j-xf8r-8572 Missing authentication in the SearchStudentsRFID method in IDAttend’s IDWeb application 3.1.052 and earlier allows extraction sensitive student data by unauthenticated attackers. | CVSS3: 7.5 | 1% Низкий | почти 3 года назад | |
GHSA-4f7j-px6v-m38x Wazuh SIEM version 4.8.2 is affected by a broken access control vulnerability. This issue allows the unauthorized creation of internal users without assigning any existing user role, potentially leading to privilege escalation or unauthorized access to sensitive resources. | CVSS3: 7.3 | 0% Низкий | больше 1 года назад | |
GHSA-4f7j-5j3r-xxc5 Certain NETGEAR devices are affected by stored XSS. This affects D6100 before 1.0.0.63, DM200 before 1.0.0.61, R7800 before 1.0.2.52, R8900 before 1.0.4.12, R9000 before 1.0.4.12, WN3000RPv2 before 1.0.0.68, and WNR2000v5 before 1.0.0.66. | 1% Низкий | больше 4 лет назад | ||
GHSA-4f7h-9j2x-cmr4 Improper Authentication in Apache Tomcat | 7% Низкий | больше 4 лет назад | ||
GHSA-4f7g-mqhx-8h4r In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: Fix a possible memory leak In bnxt_re_setup_chip_ctx() when bnxt_qplib_map_db_bar() fails driver is not freeing the memory allocated for "rdev->chip_ctx". | CVSS3: 5.5 | 0% Низкий | почти 2 года назад | |
GHSA-4f7g-j96w-63jv Remote Procedure Call Runtime Denial of Service Vulnerability | CVSS3: 6.5 | 2% Низкий | около 3 лет назад | |
GHSA-4f7g-c479-3cx4 SeaCMS 6.61 has two XSS issues in the admin_config.php file via certain form fields. | CVSS3: 6.1 | 1% Низкий | больше 4 лет назад | |
GHSA-4f7c-pmjv-c25w Apache Log4net: Silent log event loss in XmlLayout and XmlLayoutSchemaLog4J due to unescaped XML 1.0 forbidden characters | CVSS3: 5.3 | 1% Низкий | 5 месяцев назад | |
GHSA-4f7c-mrrq-rv96 Cross-site scripting (XSS) vulnerability in avatar.php for CoolForum 0.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the img parameter. | 2% Низкий | больше 4 лет назад | ||
GHSA-4f7c-f5r2-23hx Xen 4.4.x and earlier, when using a large number of VCPUs, does not properly handle read and write locks, which allows local x86 guest users to cause a denial of service (write denial or NMI watchdog timeout and host crash) via a large number of read requests, a different vulnerability than CVE-2014-9065. | 0% Низкий | больше 4 лет назад | ||
GHSA-4f7c-7x79-wr4p Successful exploitation of the vulnerability could allow an unauthenticated attacker to conduct brute force guessing and account takeover as the session cookies are predictable, potentially allowing the attackers to gain root, admin or user access and reset passwords. | CVSS3: 5 | 0% Низкий | около 1 года назад | |
GHSA-4f7c-6xx9-hvm8 Rejected reason: This candidate was in a CNA pool that was not assigned to any issues during 2024. | около 1 года назад |
Уязвимостей на страницу