Количество 370 914
Количество 370 914
GHSA-4f63-f425-rwcr
Windows XP allows local users to execute arbitrary programs by creating a task at an elevated privilege level through the eventtriggers.exe command-line tool or the Task Scheduler service, aka "Windows Management Vulnerability."
GHSA-4f63-89w9-3jjv
Using a Custom Cipher with `NID_undef` may lead to NULL encryption
GHSA-4f62-x2cj-9j6j
A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.
GHSA-4f62-jjjx-4hrr
Deserialization of Untrusted Data vulnerability in leafcolor Applay - Shortcodes applay-shortcodes allows Object Injection.This issue affects Applay - Shortcodes: from n/a through <= 3.7.
GHSA-4f62-c8fw-44pp
Heap-based buffer overflow in the loadbuf function in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted e-mail message because of a hardcoded realloc size, a different vulnerability than CVE-2014-3618.
GHSA-4f62-78r3-84fq
Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby remote code execution.
GHSA-4f5x-v9cj-7ffr
IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to a server-side request forgery (SSRF) vulnerability.
GHSA-4f5x-q4jc-xfcf
Cross-site Scripting in pimcore
GHSA-4f5x-m8xg-x3fm
Arbitrary File Read in Saperion Web Client version 7.5.2 83166.
GHSA-4f5x-fxpp-vm4x
myPhile 1.2.1 allows remote attackers to bypass authentication via an empty password. NOTE: some of these details are obtained from third party information.
GHSA-4f5x-cggh-2x55
dedecmdv6 v6.1.9 is vulnerable to Arbitrary file deletion via file_manage_control.php.
GHSA-4f5x-9vpp-x3hw
Cross-site request forgery (CSRF) vulnerability in users_maint.html in KrisonAV CMS before 3.0.2 allows remote attackers to hijack the authentication of administrators for requests that create user accounts via a crafted request.
GHSA-4f5w-x884-92x8
Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMServerAdmin.asmx function.
GHSA-4f5w-5x35-7vgh
An issue was discovered in PHP 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1. Inappropriately parsing an HTTP response leads to a segmentation fault because http_header_value in ext/standard/http_fopen_wrapper.c can be a NULL value that is mishandled in an atoi call.
GHSA-4f5w-5ccj-9j8h
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MorganF Weather Layer allows Stored XSS. This issue affects Weather Layer: from n/a through 4.2.1.
GHSA-4f5w-42g5-f95q
Illustrator versions 29.8.3, 30.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption to services. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
GHSA-4f5w-327f-jw8g
An Improper Authorization vulnerability was identified in the EOL OVA based connect component which is deployed for installation purposes in the customer internal network. Under certain conditions, this could allow a bad actor to gain unauthorized access to the local db containing weakly hashed credentials of the installer. This EOL component was deprecated in September 2023 with end of support extended till January 2024.
GHSA-4f5v-gcjx-w64x
A vulnerability has been identified in SINUMERIK 808D V4.7 (All versions), SINUMERIK 808D V4.8 (All versions), SINUMERIK 828D V4.7 (All versions < V4.7 SP6 HF1), SINUMERIK 840D sl V4.7 (All versions < V4.7 SP6 HF5), SINUMERIK 840D sl V4.8 (All versions < V4.8 SP3). A local attacker with elevated user privileges (manufact) could modify a CRAMFS archive so that after reboot the system loads the modified CRAMFS file and attacker-controlled code is executed with root privileges. The security vulnerability could be exploited by an attacker with local access to the affected systems. Successful exploitation requires elevated user privileges (manufact) but no user interaction. The vulnerability could allow an attacker to compromise confidentiality, integrity and availability of the system. At the time of advisory publication no public exploitation of this security vulnerability was known.
GHSA-4f5v-4r5w-g4x3
Lua through 5.4.0 mishandles the interaction between stack resizes and garbage collection, leading to a heap-based buffer overflow, heap-based buffer over-read, or use-after-free.
GHSA-4f5r-h5fc-r77g
Multiple SQL injection vulnerabilities in Graphiks MyForum 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4f63-f425-rwcr Windows XP allows local users to execute arbitrary programs by creating a task at an elevated privilege level through the eventtriggers.exe command-line tool or the Task Scheduler service, aka "Windows Management Vulnerability." | 21% Средний | больше 4 лет назад | ||
GHSA-4f63-89w9-3jjv Using a Custom Cipher with `NID_undef` may lead to NULL encryption | CVSS3: 7.5 | 3% Низкий | почти 4 года назад | |
GHSA-4f62-x2cj-9j6j A authenticated remote command injection vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability. | CVSS3: 7.2 | 1% Низкий | больше 4 лет назад | |
GHSA-4f62-jjjx-4hrr Deserialization of Untrusted Data vulnerability in leafcolor Applay - Shortcodes applay-shortcodes allows Object Injection.This issue affects Applay - Shortcodes: from n/a through <= 3.7. | CVSS3: 8.8 | 0% Низкий | 7 месяцев назад | |
GHSA-4f62-c8fw-44pp Heap-based buffer overflow in the loadbuf function in formisc.c in formail in procmail 3.22 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted e-mail message because of a hardcoded realloc size, a different vulnerability than CVE-2014-3618. | CVSS3: 9.8 | 13% Средний | больше 4 лет назад | |
GHSA-4f62-78r3-84fq Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby remote code execution. | CVSS3: 9.8 | 1% Низкий | около 2 месяцев назад | |
GHSA-4f5x-v9cj-7ffr IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to a server-side request forgery (SSRF) vulnerability. | CVSS3: 5 | 0% Низкий | 10 дней назад | |
GHSA-4f5x-q4jc-xfcf Cross-site Scripting in pimcore | CVSS3: 6.6 | 2% Низкий | больше 4 лет назад | |
GHSA-4f5x-m8xg-x3fm Arbitrary File Read in Saperion Web Client version 7.5.2 83166. | CVSS3: 7.5 | 1% Низкий | больше 4 лет назад | |
GHSA-4f5x-fxpp-vm4x myPhile 1.2.1 allows remote attackers to bypass authentication via an empty password. NOTE: some of these details are obtained from third party information. | 1% Низкий | больше 4 лет назад | ||
GHSA-4f5x-cggh-2x55 dedecmdv6 v6.1.9 is vulnerable to Arbitrary file deletion via file_manage_control.php. | CVSS3: 9.1 | 1% Низкий | почти 4 года назад | |
GHSA-4f5x-9vpp-x3hw Cross-site request forgery (CSRF) vulnerability in users_maint.html in KrisonAV CMS before 3.0.2 allows remote attackers to hijack the authentication of administrators for requests that create user accounts via a crafted request. | 1% Низкий | больше 4 лет назад | ||
GHSA-4f5w-x884-92x8 Cross Site Scripting vulnerability in openPetra v.2023.02 allows a remote attacker to obtain sensitive information via the serverMServerAdmin.asmx function. | CVSS3: 7.3 | 1% Низкий | почти 2 года назад | |
GHSA-4f5w-5x35-7vgh An issue was discovered in PHP 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1. Inappropriately parsing an HTTP response leads to a segmentation fault because http_header_value in ext/standard/http_fopen_wrapper.c can be a NULL value that is mishandled in an atoi call. | CVSS3: 7.5 | 3% Низкий | больше 4 лет назад | |
GHSA-4f5w-5ccj-9j8h Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in MorganF Weather Layer allows Stored XSS. This issue affects Weather Layer: from n/a through 4.2.1. | CVSS3: 5.9 | 0% Низкий | больше 1 года назад | |
GHSA-4f5w-42g5-f95q Illustrator versions 29.8.3, 30.0 and earlier are affected by a NULL Pointer Dereference vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application, causing disruption to services. Exploitation of this issue requires user interaction in that a victim must open a malicious file. | CVSS3: 5.5 | 0% Низкий | 8 месяцев назад | |
GHSA-4f5w-327f-jw8g An Improper Authorization vulnerability was identified in the EOL OVA based connect component which is deployed for installation purposes in the customer internal network. Under certain conditions, this could allow a bad actor to gain unauthorized access to the local db containing weakly hashed credentials of the installer. This EOL component was deprecated in September 2023 with end of support extended till January 2024. | 0% Низкий | больше 1 года назад | ||
GHSA-4f5v-gcjx-w64x A vulnerability has been identified in SINUMERIK 808D V4.7 (All versions), SINUMERIK 808D V4.8 (All versions), SINUMERIK 828D V4.7 (All versions < V4.7 SP6 HF1), SINUMERIK 840D sl V4.7 (All versions < V4.7 SP6 HF5), SINUMERIK 840D sl V4.8 (All versions < V4.8 SP3). A local attacker with elevated user privileges (manufact) could modify a CRAMFS archive so that after reboot the system loads the modified CRAMFS file and attacker-controlled code is executed with root privileges. The security vulnerability could be exploited by an attacker with local access to the affected systems. Successful exploitation requires elevated user privileges (manufact) but no user interaction. The vulnerability could allow an attacker to compromise confidentiality, integrity and availability of the system. At the time of advisory publication no public exploitation of this security vulnerability was known. | CVSS3: 7.8 | 0% Низкий | больше 4 лет назад | |
GHSA-4f5v-4r5w-g4x3 Lua through 5.4.0 mishandles the interaction between stack resizes and garbage collection, leading to a heap-based buffer overflow, heap-based buffer over-read, or use-after-free. | CVSS3: 8.8 | 2% Низкий | больше 4 лет назад | |
GHSA-4f5r-h5fc-r77g Multiple SQL injection vulnerabilities in Graphiks MyForum 1.3 allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields. | 1% Низкий | больше 4 лет назад |
Уязвимостей на страницу