Количество 370 841
Количество 370 841
GHSA-49wh-vw4x-p83m
The Customer's Tomedo Server in Version 1.7.3 communicates to the Vendor Tomedo Server via HTTP (in cleartext) that can be sniffed by unauthorized actors. Basic authentication is used for the authentication, making it possible to base64 decode the sniffed credentials and discover the username and password.
GHSA-49wh-pf3r-rqvx
Cross-site request forgery in Teltonika firmware TRB2_R_00.02.04.3 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.
GHSA-49wh-cm7q-9w2h
Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by a Null pointer dereference vulnerability. An authenticated attacker could leverage this vulnerability achieve an application denial-of-service in the context of the current user. Exploitation of this issue does not requires user interaction.
GHSA-49wh-6wrq-xcjr
PHP remote file inclusion vulnerability in inc/gabarits.php in R. Corson PHP Forge 3 beta 2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cfg_racine parameter.
GHSA-49wh-353r-wj79
This candidate was in a CNA pool that was not assigned to any issues during 2021.
GHSA-49wf-927p-jpvj
OpenFlow plugin for OpenDaylight allows spoofing the SDN topology
GHSA-49wc-x7ph-q668
On F5 BIG-IP 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, when multiple route domains are configured, undisclosed requests to big3d can cause an increase in CPU resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
GHSA-49wc-943v-whmw
Windows Secure Channel Denial of Service Vulnerability
GHSA-49w9-82cj-xr48
MantisBT SQL Injection via mc_project_get_users function
GHSA-49w9-5v8p-jcmw
In the Linux kernel, the following vulnerability has been resolved: spi: sn-f-ospi: Fix division by zero When there is no dummy cycle in the spi-nor commands, both dummy bus cycle bytes and width are zero. Because of the cpu's warning when divided by zero, the warning should be avoided. Return just zero to avoid such calculations.
GHSA-49w8-qx9g-ww3r
Dell SonicWall TotalSecure TZ 100 devices with firmware before 5.9.1.0-22o allow remote attackers to cause a denial of service via a crafted packet.
GHSA-49w7-7c42-5jfv
The sell function of a smart contract implementation for Substratum (SUB), a tradable Ethereum ERC20 token, allows a potential trap that could be used to cause financial damage to the seller, because of overflow of the multiplication of its argument amount and a manipulable variable sellPrice, aka the "tradeTrap" issue.
GHSA-49w7-5r33-jm9m
http-swagger XSS via PUT requests
GHSA-49w6-73cw-chjr
Astro's server source code is exposed to the public if sourcemaps are enabled
GHSA-49w6-3ccf-2xg2
Rejected reason: Not used
GHSA-49w5-c2q7-xqvq
An issue in JerryscriptProject jerryscript v.3.0.0 allows an attacker to obtain sensitive information via a crafted script to the arrays.
GHSA-49w4-8c2m-qh25
Adobe Illustrator version 24.1.2 (and earlier) is affected by a memory corruption vulnerability that occurs when parsing a specially crafted .svg file. This could result in arbitrary code execution in the context of the current user. This vulnerability requires user interaction to exploit.
GHSA-49w4-256x-6pj9
An XSS issue was discovered in upcoming_events.php in the Upcoming Events plugin before 1.33 for MyBB via a crafted name for an event.
GHSA-49w3-g48r-qp76
Multiple cross-site scripting (XSS) vulnerabilities in register.php in Tritanium Bulletin Board (TBB) 1.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) newuser_name, (2) newuser_email, and (3) newuser_hp parameters in the faction=register mode in index.php.
GHSA-49w3-3w9f-g824
Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N).
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-49wh-vw4x-p83m The Customer's Tomedo Server in Version 1.7.3 communicates to the Vendor Tomedo Server via HTTP (in cleartext) that can be sniffed by unauthorized actors. Basic authentication is used for the authentication, making it possible to base64 decode the sniffed credentials and discover the username and password. | CVSS3: 9.8 | 2% Низкий | больше 4 лет назад | |
GHSA-49wh-pf3r-rqvx Cross-site request forgery in Teltonika firmware TRB2_R_00.02.04.3 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link. | 9% Низкий | больше 4 лет назад | ||
GHSA-49wh-cm7q-9w2h Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by a Null pointer dereference vulnerability. An authenticated attacker could leverage this vulnerability achieve an application denial-of-service in the context of the current user. Exploitation of this issue does not requires user interaction. | 2% Низкий | больше 4 лет назад | ||
GHSA-49wh-6wrq-xcjr PHP remote file inclusion vulnerability in inc/gabarits.php in R. Corson PHP Forge 3 beta 2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cfg_racine parameter. | 3% Низкий | больше 4 лет назад | ||
GHSA-49wh-353r-wj79 This candidate was in a CNA pool that was not assigned to any issues during 2021. | больше 3 лет назад | |||
GHSA-49wf-927p-jpvj OpenFlow plugin for OpenDaylight allows spoofing the SDN topology | CVSS3: 7.5 | 2% Низкий | больше 4 лет назад | |
GHSA-49wc-x7ph-q668 On F5 BIG-IP 13.1.x versions prior to 13.1.5, and all versions of 12.1.x and 11.6.x, when multiple route domains are configured, undisclosed requests to big3d can cause an increase in CPU resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | CVSS3: 5.3 | 1% Низкий | больше 4 лет назад | |
GHSA-49wc-943v-whmw Windows Secure Channel Denial of Service Vulnerability | CVSS3: 7.5 | 2% Низкий | больше 3 лет назад | |
GHSA-49w9-82cj-xr48 MantisBT SQL Injection via mc_project_get_users function | CVSS3: 5.3 | 5% Низкий | больше 4 лет назад | |
GHSA-49w9-5v8p-jcmw In the Linux kernel, the following vulnerability has been resolved: spi: sn-f-ospi: Fix division by zero When there is no dummy cycle in the spi-nor commands, both dummy bus cycle bytes and width are zero. Because of the cpu's warning when divided by zero, the warning should be avoided. Return just zero to avoid such calculations. | CVSS3: 5.5 | 0% Низкий | больше 1 года назад | |
GHSA-49w8-qx9g-ww3r Dell SonicWall TotalSecure TZ 100 devices with firmware before 5.9.1.0-22o allow remote attackers to cause a denial of service via a crafted packet. | 3% Низкий | больше 4 лет назад | ||
GHSA-49w7-7c42-5jfv The sell function of a smart contract implementation for Substratum (SUB), a tradable Ethereum ERC20 token, allows a potential trap that could be used to cause financial damage to the seller, because of overflow of the multiplication of its argument amount and a manipulable variable sellPrice, aka the "tradeTrap" issue. | CVSS3: 7.5 | 1% Низкий | больше 4 лет назад | |
GHSA-49w7-5r33-jm9m http-swagger XSS via PUT requests | CVSS3: 6.1 | 1% Низкий | больше 2 лет назад | |
GHSA-49w6-73cw-chjr Astro's server source code is exposed to the public if sourcemaps are enabled | 1% Низкий | больше 1 года назад | ||
GHSA-49w6-3ccf-2xg2 Rejected reason: Not used | около 1 года назад | |||
GHSA-49w5-c2q7-xqvq An issue in JerryscriptProject jerryscript v.3.0.0 allows an attacker to obtain sensitive information via a crafted script to the arrays. | CVSS3: 7.5 | 1% Низкий | около 3 лет назад | |
GHSA-49w4-8c2m-qh25 Adobe Illustrator version 24.1.2 (and earlier) is affected by a memory corruption vulnerability that occurs when parsing a specially crafted .svg file. This could result in arbitrary code execution in the context of the current user. This vulnerability requires user interaction to exploit. | 3% Низкий | больше 4 лет назад | ||
GHSA-49w4-256x-6pj9 An XSS issue was discovered in upcoming_events.php in the Upcoming Events plugin before 1.33 for MyBB via a crafted name for an event. | CVSS3: 6.1 | 3% Низкий | больше 4 лет назад | |
GHSA-49w3-g48r-qp76 Multiple cross-site scripting (XSS) vulnerabilities in register.php in Tritanium Bulletin Board (TBB) 1.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) newuser_name, (2) newuser_email, and (3) newuser_hp parameters in the faction=register mode in index.php. | 2% Низкий | больше 4 лет назад | ||
GHSA-49w3-3w9f-g824 Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version that is affected is 11.2.25.0.000. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Hyperion Data Relationship Management. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Hyperion Data Relationship Management accessible data as well as unauthorized access to critical data or complete access to all Oracle Hyperion Data Relationship Management accessible data. CVSS 3.1 Base Score 9.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). | CVSS3: 9.1 | 0% Низкий | 25 дней назад |
Уязвимостей на страницу