Количество 367 277
Количество 367 277
GHSA-45gc-6g92-9g2j
Out-of-bounds Read in mrb_obj_is_kind_of in in GitHub repository mruby/mruby prior to 3.2. # Impact: Possible arbitrary code execution if being exploited.
GHSA-45g9-v625-vr5r
TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the country parameter at setting/delStaticDhcpRules.
GHSA-45g9-98w8-8m3w
Nvu 0.99+1.0pre uses an old copy of Mozilla XPCOM which can result in multiple security issues.
GHSA-45g8-5xrw-r5wm
A vulnerability in the file and malware inspection feature of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass the file and malware inspection policies on an affected system. The vulnerability exists because the affected software insufficiently validates incoming traffic. An attacker could exploit this vulnerability by sending a crafted HTTP request through an affected device. A successful exploit could allow the attacker to bypass the file and malware inspection policies and send malicious traffic through the affected device.
GHSA-45g7-4cgq-4vp4
Jsish 2.4.84 2.0484 is affected by: Reachable Assertion. The impact is: denial of service. The component is: function Jsi_ValueArrayIndex (jsiValue.c:366). The attack vector is: executing crafted javascript code. The fixed version is: after commit 738ead193aff380a7e3d7ffb8e11e446f76867f3.
GHSA-45g7-3c3h-rm3p
A buffer overflow exists in HelpSystems tcpcrypt on Linux, used for BoKS encrypted telnet through BoKS version 6.7.1. Since tcpcrypt is setuid, exploitation leads to privilege escalation.
GHSA-45g5-qmv3-9f22
The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely and directly enter an interactive shell interface.
GHSA-45g4-mj6j-wggg
A vulnerability was found in SourceCodester Service Provider Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /classes/Master.php?f=save_inquiry. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. VDB-233890 is the identifier assigned to this vulnerability.
GHSA-45g4-83v3-gcqp
A cross-site scripting (XSS) vulnerability exists in the search-autootaxi.php endpoint of the ATSMS web application. The application fails to properly sanitize user input submitted through a form field, allowing an attacker to inject arbitrary JavaScript code. The malicious payload is stored in the backend and executed when a user or administrator accesses the affected report page. This allows attackers to exfiltrate session cookies, hijack user sessions, and perform unauthorized actions in the context of the victims browser.
GHSA-45g4-3pq8-625w
dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/doAdminAction.php?act=editAdmin&id=17
GHSA-45g3-mf2x-6mxc
Pantomime in Ecartis 1.0.0 snapshot 20050909 stores e-mail attachments in a publicly accessible directory, which may allow remote attackers to upload arbitrary files.
GHSA-45g3-hwwx-j5r9
In Schneider Electric U.motion Builder software versions prior to v1.3.4, a remote command injection allows authentication bypass.
GHSA-45g3-59h2-54v9
Dovecot 1.1 before 2.2.13 and dovecot-ee before 2.1.7.7 and 2.2.x before 2.2.12.12 does not properly close old connections, which allows remote attackers to cause a denial of service (resource consumption) via an incomplete SSL/TLS handshake for an IMAP/POP3 connection.
GHSA-45g3-4pmp-w6x8
Improper input validation vulnerability in Workflow of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to alter the data of Workflow without the appropriate privilege.
GHSA-45g2-wqp2-rh43
SQL injection vulnerability in ads.php in Softbiz Ad Management plus Script 1 allows remote authenticated users to execute arbitrary SQL commands via the package parameter.
GHSA-45g2-r339-pjwf
Cockpit CMS Cross-Site Request Forgery vulnerability
GHSA-45g2-pwgf-cj2v
An issue in Aranda PassRecovery v1.0 allows attackers to enumerate valid user accounts in Active Directory via sending a crafted POST request to /user/existdirectory/1.
GHSA-45g2-3cmv-w565
In Developer Tools, there is a possible missing verification incorrect input. This could lead to local escalation of privilege with no additional execution privileges needed.
GHSA-45fx-qq48-m87m
FMP/NOTIFY protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service
GHSA-45fx-8598-pqhv
Delta Electronics DIAEnergie has insufficient input validation which makes it possible to perform a path traversal attack and write outside of the intended directory. If a file name is specified that already exists on the file system, then the original file will be overwritten.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-45gc-6g92-9g2j Out-of-bounds Read in mrb_obj_is_kind_of in in GitHub repository mruby/mruby prior to 3.2. # Impact: Possible arbitrary code execution if being exploited. | CVSS3: 7.8 | 0% Низкий | больше 4 лет назад | |
GHSA-45g9-v625-vr5r TOTOlink A7100RU(V7.4cu.2313_B20191024) was discovered to contain a command injection vulnerability via the country parameter at setting/delStaticDhcpRules. | CVSS3: 9.8 | 2% Низкий | больше 3 лет назад | |
GHSA-45g9-98w8-8m3w Nvu 0.99+1.0pre uses an old copy of Mozilla XPCOM which can result in multiple security issues. | CVSS3: 9.8 | 2% Низкий | больше 4 лет назад | |
GHSA-45g8-5xrw-r5wm A vulnerability in the file and malware inspection feature of Cisco Firepower Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass the file and malware inspection policies on an affected system. The vulnerability exists because the affected software insufficiently validates incoming traffic. An attacker could exploit this vulnerability by sending a crafted HTTP request through an affected device. A successful exploit could allow the attacker to bypass the file and malware inspection policies and send malicious traffic through the affected device. | CVSS3: 5.8 | 1% Низкий | больше 4 лет назад | |
GHSA-45g7-4cgq-4vp4 Jsish 2.4.84 2.0484 is affected by: Reachable Assertion. The impact is: denial of service. The component is: function Jsi_ValueArrayIndex (jsiValue.c:366). The attack vector is: executing crafted javascript code. The fixed version is: after commit 738ead193aff380a7e3d7ffb8e11e446f76867f3. | 1% Низкий | больше 4 лет назад | ||
GHSA-45g7-3c3h-rm3p A buffer overflow exists in HelpSystems tcpcrypt on Linux, used for BoKS encrypted telnet through BoKS version 6.7.1. Since tcpcrypt is setuid, exploitation leads to privilege escalation. | CVSS3: 9.8 | 1% Низкий | больше 4 лет назад | |
GHSA-45g5-qmv3-9f22 The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely and directly enter an interactive shell interface. | CVSS3: 8.8 | 0% Низкий | 3 месяца назад | |
GHSA-45g4-mj6j-wggg A vulnerability was found in SourceCodester Service Provider Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /classes/Master.php?f=save_inquiry. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. VDB-233890 is the identifier assigned to this vulnerability. | CVSS3: 6.3 | 0% Низкий | около 3 лет назад | |
GHSA-45g4-83v3-gcqp A cross-site scripting (XSS) vulnerability exists in the search-autootaxi.php endpoint of the ATSMS web application. The application fails to properly sanitize user input submitted through a form field, allowing an attacker to inject arbitrary JavaScript code. The malicious payload is stored in the backend and executed when a user or administrator accesses the affected report page. This allows attackers to exfiltrate session cookies, hijack user sessions, and perform unauthorized actions in the context of the victims browser. | CVSS3: 5.4 | 0% Низкий | 12 месяцев назад | |
GHSA-45g4-3pq8-625w dingfanzu CMS 1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via /admin/doAdminAction.php?act=editAdmin&id=17 | CVSS3: 6.3 | 0% Низкий | почти 2 года назад | |
GHSA-45g3-mf2x-6mxc Pantomime in Ecartis 1.0.0 snapshot 20050909 stores e-mail attachments in a publicly accessible directory, which may allow remote attackers to upload arbitrary files. | 2% Низкий | больше 4 лет назад | ||
GHSA-45g3-hwwx-j5r9 In Schneider Electric U.motion Builder software versions prior to v1.3.4, a remote command injection allows authentication bypass. | CVSS3: 9.8 | 3% Низкий | больше 4 лет назад | |
GHSA-45g3-59h2-54v9 Dovecot 1.1 before 2.2.13 and dovecot-ee before 2.1.7.7 and 2.2.x before 2.2.12.12 does not properly close old connections, which allows remote attackers to cause a denial of service (resource consumption) via an incomplete SSL/TLS handshake for an IMAP/POP3 connection. | 3% Низкий | больше 4 лет назад | ||
GHSA-45g3-4pmp-w6x8 Improper input validation vulnerability in Workflow of Cybozu Garoon 4.0.0 to 5.0.2 allows a remote authenticated attacker to alter the data of Workflow without the appropriate privilege. | 1% Низкий | больше 4 лет назад | ||
GHSA-45g2-wqp2-rh43 SQL injection vulnerability in ads.php in Softbiz Ad Management plus Script 1 allows remote authenticated users to execute arbitrary SQL commands via the package parameter. | 1% Низкий | больше 4 лет назад | ||
GHSA-45g2-r339-pjwf Cockpit CMS Cross-Site Request Forgery vulnerability | CVSS3: 8.8 | 1% Низкий | около 3 лет назад | |
GHSA-45g2-pwgf-cj2v An issue in Aranda PassRecovery v1.0 allows attackers to enumerate valid user accounts in Active Directory via sending a crafted POST request to /user/existdirectory/1. | CVSS3: 6.5 | 0% Низкий | 12 месяцев назад | |
GHSA-45g2-3cmv-w565 In Developer Tools, there is a possible missing verification incorrect input. This could lead to local escalation of privilege with no additional execution privileges needed. | CVSS3: 6.8 | 0% Низкий | около 1 года назад | |
GHSA-45fx-qq48-m87m FMP/NOTIFY protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows denial of service | CVSS3: 5.5 | 0% Низкий | 2 месяца назад | |
GHSA-45fx-8598-pqhv Delta Electronics DIAEnergie has insufficient input validation which makes it possible to perform a path traversal attack and write outside of the intended directory. If a file name is specified that already exists on the file system, then the original file will be overwritten. | CVSS3: 8.8 | 1% Низкий | больше 2 лет назад |
Уязвимостей на страницу