Количество 370 914
Количество 370 914
GHSA-4cx5-3q2w-5wr7
An improper certificate validation vulnerability exists in AVTECH IP cameras, DVRs, and NVRs due to the use of wget with --no-check-certificate in scripts like SyncCloudAccount.sh and SyncPermit.sh. This exposes HTTPS communications to man-in-the-middle (MITM) attacks.
GHSA-4cx5-2fr7-x88f
Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'View' parameter in '/course/index.php'.
GHSA-4cx4-xm36-7hp9
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stefano Marra Smart Mockups allows Stored XSS.This issue affects Smart Mockups: from n/a through 1.2.0.
GHSA-4cx4-gv7f-pqv2
Contributor Local File Inclusion in Goya Core < 1.0.9.4 versions.
GHSA-4cx3-gvx4-j3wg
A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to duplicate files which can lead to UI inconvenience, and exhaustion of disk space.Credit for discovery: "Solar Security CMS Research Team"
GHSA-4cx3-3c38-j9vv
katalyst-koi: Session cookies can be replayed after user logout
GHSA-4cx2-fc23-5wg6
Bouncy Castle for Java bcpkix, bcprov, bcpkix-fips on All (API modules) allows Excessive Allocation
GHSA-4cx2-827f-fp6c
Immuta v2.8.2 is affected by improper session management: user sessions are not revoked upon logout.
GHSA-4cx2-4xxw-gpfv
JetBrains TeamCity 2019.1 and 2019.1.1 allows cross-site scripting (XSS), potentially making it possible to send an arbitrary HTTP request to a TeamCity server under the name of the currently logged-in user.
GHSA-4cwx-xrxh-9ff7
An issue was discovered in the ROS communications-related packages (aka ros_comm or ros-melodic-ros-comm) through 1.14.3. ROS_ASSERT_MSG only works when ROS_ASSERT_ENABLED is defined. This leads to a problem in the remove() function in clients/roscpp/src/libros/spinner.cpp. When ROS_ASSERT_ENABLED is not defined, the iterator loop will run out of the scope of the array, and cause denial of service for other components (that depend on the communication-related functions of this package).
GHSA-4cwx-r6vp-5886
A vulnerability in the implementation of the Datagram TLS (DTLS) protocol in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause high CPU utilization, resulting in a denial of service (DoS) condition. This vulnerability is due to suboptimal processing that occurs when establishing a DTLS tunnel as part of an AnyConnect SSL VPN connection. An attacker could exploit this vulnerability by sending a steady stream of crafted DTLS traffic to an affected device. A successful exploit could allow the attacker to exhaust resources on the affected VPN headend device. This could cause existing DTLS tunnels to stop passing traffic and prevent new DTLS tunnels from establishing, resulting in a DoS condition. Note: When the attack traffic stops, the device recovers gracefully.
GHSA-4cwx-j38m-p4pm
Insecure method vulnerability in TuxScripting.dll in the TuxSystem ActiveX control in 2X ApplicationServer 10.1 Build 1224 allows remote attackers to create or overwrite arbitrary files via the ExportSettings method.
GHSA-4cwx-87j2-xc8v
** UNSUPPPORTED WHEN ASSIGNED **Broken Access Control in User Authentication in Avaya Scopia Pathfinder 10 and 20 PTS version 8.3.7.0.4 allows remote unauthenticated attackers to bypass the login page, access sensitive information, and reset user passwords via URL modification.
GHSA-4cwx-7wf7-3272
undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives
GHSA-4cww-rww7-fw7q
A security issue was discovered in the Kubernetes Image Builder where default credentials are enabled during the image build process. Additionally, virtual machine images built using the Nutanix or the OVA provider do not disable these default credentials, and nodes using the resulting images may be accessible via these default credentials. The credentials can be used to gain root access. Kubernetes clusters are only affected if their Windows nodes use VM images created via the Image Builder project with its Nutanix or OVA provider.
GHSA-4cww-f7w5-x525
Stack consumption in trust-dns-server
GHSA-4cww-8m8h-fvjq
Directory traversal vulnerability in FlexWATCH Network Camera 3.0 and earlier allows remote attackers to bypass access restrictions for (1) admin/aindex.asp or (2) admin/aindex.html via a .. (dot dot) and encoded / (%2f) sequence in the URL.
GHSA-4cwv-p4c3-xrh9
Memory corruption in video due to configuration weakness. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables
GHSA-4cwr-vwjh-j2gw
Active Directory Domain Services Elevation of Privilege Vulnerability.
GHSA-4cwr-jp57-8cx6
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Session Fixation OVE-20230524-0004.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-4cx5-3q2w-5wr7 An improper certificate validation vulnerability exists in AVTECH IP cameras, DVRs, and NVRs due to the use of wget with --no-check-certificate in scripts like SyncCloudAccount.sh and SyncPermit.sh. This exposes HTTPS communications to man-in-the-middle (MITM) attacks. | 0% Низкий | около 1 года назад | ||
GHSA-4cx5-2fr7-x88f Cross-Site Scripting (XSS) vulnerability in School Attendance Monitoring System and School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain details of their session cookie via the 'View' parameter in '/course/index.php'. | CVSS3: 7.1 | 0% Низкий | около 2 лет назад | |
GHSA-4cx4-xm36-7hp9 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Stefano Marra Smart Mockups allows Stored XSS.This issue affects Smart Mockups: from n/a through 1.2.0. | CVSS3: 6.5 | 0% Низкий | почти 2 года назад | |
GHSA-4cx4-gv7f-pqv2 Contributor Local File Inclusion in Goya Core < 1.0.9.4 versions. | CVSS3: 7.5 | 0% Низкий | 3 месяца назад | |
GHSA-4cx3-gvx4-j3wg A CSRF in Concrete CMS version 8.5.5 and below allows an attacker to duplicate files which can lead to UI inconvenience, and exhaustion of disk space.Credit for discovery: "Solar Security CMS Research Team" | 0% Низкий | больше 4 лет назад | ||
GHSA-4cx3-3c38-j9vv katalyst-koi: Session cookies can be replayed after user logout | CVSS3: 7.4 | 0% Низкий | 4 месяца назад | |
GHSA-4cx2-fc23-5wg6 Bouncy Castle for Java bcpkix, bcprov, bcpkix-fips on All (API modules) allows Excessive Allocation | 0% Низкий | около 1 года назад | ||
GHSA-4cx2-827f-fp6c Immuta v2.8.2 is affected by improper session management: user sessions are not revoked upon logout. | 1% Низкий | больше 4 лет назад | ||
GHSA-4cx2-4xxw-gpfv JetBrains TeamCity 2019.1 and 2019.1.1 allows cross-site scripting (XSS), potentially making it possible to send an arbitrary HTTP request to a TeamCity server under the name of the currently logged-in user. | 1% Низкий | больше 4 лет назад | ||
GHSA-4cwx-xrxh-9ff7 An issue was discovered in the ROS communications-related packages (aka ros_comm or ros-melodic-ros-comm) through 1.14.3. ROS_ASSERT_MSG only works when ROS_ASSERT_ENABLED is defined. This leads to a problem in the remove() function in clients/roscpp/src/libros/spinner.cpp. When ROS_ASSERT_ENABLED is not defined, the iterator loop will run out of the scope of the array, and cause denial of service for other components (that depend on the communication-related functions of this package). | 1% Низкий | больше 4 лет назад | ||
GHSA-4cwx-r6vp-5886 A vulnerability in the implementation of the Datagram TLS (DTLS) protocol in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause high CPU utilization, resulting in a denial of service (DoS) condition. This vulnerability is due to suboptimal processing that occurs when establishing a DTLS tunnel as part of an AnyConnect SSL VPN connection. An attacker could exploit this vulnerability by sending a steady stream of crafted DTLS traffic to an affected device. A successful exploit could allow the attacker to exhaust resources on the affected VPN headend device. This could cause existing DTLS tunnels to stop passing traffic and prevent new DTLS tunnels from establishing, resulting in a DoS condition. Note: When the attack traffic stops, the device recovers gracefully. | CVSS3: 7.5 | 1% Низкий | больше 4 лет назад | |
GHSA-4cwx-j38m-p4pm Insecure method vulnerability in TuxScripting.dll in the TuxSystem ActiveX control in 2X ApplicationServer 10.1 Build 1224 allows remote attackers to create or overwrite arbitrary files via the ExportSettings method. | 4% Низкий | больше 4 лет назад | ||
GHSA-4cwx-87j2-xc8v ** UNSUPPPORTED WHEN ASSIGNED **Broken Access Control in User Authentication in Avaya Scopia Pathfinder 10 and 20 PTS version 8.3.7.0.4 allows remote unauthenticated attackers to bypass the login page, access sensitive information, and reset user passwords via URL modification. | CVSS3: 9.1 | 1% Низкий | почти 4 года назад | |
GHSA-4cwx-7wf7-3272 undici vulnerable to cross-user information disclosure and parse-time crash via degenerate private cache directives | CVSS3: 7.4 | 0% Низкий | около 1 месяца назад | |
GHSA-4cww-rww7-fw7q A security issue was discovered in the Kubernetes Image Builder where default credentials are enabled during the image build process. Additionally, virtual machine images built using the Nutanix or the OVA provider do not disable these default credentials, and nodes using the resulting images may be accessible via these default credentials. The credentials can be used to gain root access. Kubernetes clusters are only affected if their Windows nodes use VM images created via the Image Builder project with its Nutanix or OVA provider. | CVSS3: 7.5 | 0% Низкий | около 1 года назад | |
GHSA-4cww-f7w5-x525 Stack consumption in trust-dns-server | CVSS3: 7.5 | 1% Низкий | около 5 лет назад | |
GHSA-4cww-8m8h-fvjq Directory traversal vulnerability in FlexWATCH Network Camera 3.0 and earlier allows remote attackers to bypass access restrictions for (1) admin/aindex.asp or (2) admin/aindex.html via a .. (dot dot) and encoded / (%2f) sequence in the URL. | 3% Низкий | больше 4 лет назад | ||
GHSA-4cwv-p4c3-xrh9 Memory corruption in video due to configuration weakness. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables | CVSS3: 9.8 | 0% Низкий | почти 4 года назад | |
GHSA-4cwr-vwjh-j2gw Active Directory Domain Services Elevation of Privilege Vulnerability. | CVSS3: 7.1 | 1% Низкий | почти 4 года назад | |
GHSA-4cwr-jp57-8cx6 Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Session Fixation OVE-20230524-0004. | CVSS3: 9.1 | 1% Низкий | больше 1 года назад |
Уязвимостей на страницу