Количество 366 653
Количество 366 653
GHSA-43x3-5v8m-8xf2
sendfax.php in iFAX AvantFAX before 3.3.6 and HylaFAX Enterprise Web Interface before 0.2.5 allows authenticated Command Injection.
GHSA-43x2-g84q-fmqx
OpenDJ Pre-Auth RCE via Java Deserialization in JMX RMI
GHSA-43x2-3vw5-55c5
tsMuxer git-c6a0277 was discovered to contain a segmentation fault via DTSStreamReader::findFrame in dtsStreamReader.cpp.
GHSA-43x2-2pcr-g799
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka "MS XML Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.
GHSA-43ww-xqjh-ppmf
Multiple integer overflows in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to obtain sensitive information (memory contents) or cause a denial of service (thread crash) via a large len value to the (1) strspn or (2) strcspn function, which triggers an out-of-bounds read. NOTE: this affects different product versions than CVE-2007-3996.
GHSA-43ww-vg8r-97hv
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Zio Alberto zioalberto allows PHP Local File Inclusion.This issue affects Zio Alberto: from n/a through <= 1.2.2.
GHSA-43ww-hgjh-c9cg
Unspecified vulnerability in Small Footprint CIM Broker (SFCB) before 1.2.5 has unknown impact and attack vectors.
GHSA-43ww-gwmw-f89v
Server-Side Request Forgery (CWE-918) in Kibana allows authenticated users with connector management privileges to bypass the operator-configured connection allowlist. By configuring a Webhook connector with a crafted target, an attacker can cause Kibana to issue outbound requests to destinations that the egress restriction controls were intended to block.
GHSA-43ww-866w-7xv9
IBM Security QRadar 3.12 EDR uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive credential information.
GHSA-43ww-5h9q-8jh6
Unspecified vulnerability in the Solaris component in Oracle Sun Products Suite 8, 9, 10, and 11 Express allows remote attackers to affect availability via unknown vectors related to Remote Quota Server (rquotad).
GHSA-43wv-w8q4-mcvr
Windows MSHTML Platform Spoofing Vulnerability
GHSA-43wv-g93j-pw44
Unspecified vulnerability in Serv-U File Server 7.0.0.1, and other versions before 7.2.0.1, allows remote authenticated users to cause a denial of service (daemon crash) via an SSH session with SFTP commands for directory creation and logging.
GHSA-43wv-9mh2-86p7
Multiple cross-site request forgery (CSRF) vulnerabilities in PHPJabbers Appointment Scheduler 2.0 allow remote attackers to hijack the authentication of administrators for requests that (1) conduct cross-site scripting (XSS) attacks via the i18n[1][name] parameter in a pjActionCreate action to the pjAdminServices controller or (2) add an administrator via a pjActionCreate action to the pjAdminUsers controller.
GHSA-43wv-9cr7-p3pg
DLL Injection Vulnerability in McAfee Agent (MA) for Windows prior to 5.6.6 allows local users to execute arbitrary code via careful placement of a malicious DLL.
GHSA-43wv-69rq-rx33
The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and including, 7.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability was partially patched in version 7.6.9.
GHSA-43wr-9394-fxp2
OX App Suite before frontend 7.10.6-rev24 allows the loading (without user consent) of an e-mail message's remote resources during printing.
GHSA-43wr-5mwj-x7p2
IBM Security Directory Server 6.4.0 is deployed with active debugging code that can create unintended entry points. IBM X-Force ID: 165952.
GHSA-43wq-xrcm-3vgr
@discordjs/opus vulnerable to Denial of Service
GHSA-43wq-xr5f-53ww
Out-of-bounds read in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 14.0.33 may allow an unauthenticated user to potentially enable denial of service via network access.
GHSA-43wq-r34m-56ch
In BigBlueButton before 2.2.28 (or earlier), uploaded presentations are sent to clients without a Content-Type header, which allows XSS, as demonstrated by a .png file extension for an HTML document.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-43x3-5v8m-8xf2 sendfax.php in iFAX AvantFAX before 3.3.6 and HylaFAX Enterprise Web Interface before 0.2.5 allows authenticated Command Injection. | 2% Низкий | больше 4 лет назад | ||
GHSA-43x2-g84q-fmqx OpenDJ Pre-Auth RCE via Java Deserialization in JMX RMI | 3 месяца назад | |||
GHSA-43x2-3vw5-55c5 tsMuxer git-c6a0277 was discovered to contain a segmentation fault via DTSStreamReader::findFrame in dtsStreamReader.cpp. | CVSS3: 5.5 | 1% Низкий | больше 4 лет назад | |
GHSA-43x2-2pcr-g799 A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input, aka "MS XML Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. | CVSS3: 8.8 | 49% Средний | больше 4 лет назад | |
GHSA-43ww-xqjh-ppmf Multiple integer overflows in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to obtain sensitive information (memory contents) or cause a denial of service (thread crash) via a large len value to the (1) strspn or (2) strcspn function, which triggers an out-of-bounds read. NOTE: this affects different product versions than CVE-2007-3996. | 3% Низкий | больше 4 лет назад | ||
GHSA-43ww-vg8r-97hv Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Zio Alberto zioalberto allows PHP Local File Inclusion.This issue affects Zio Alberto: from n/a through <= 1.2.2. | CVSS3: 8.1 | 0% Низкий | 7 месяцев назад | |
GHSA-43ww-hgjh-c9cg Unspecified vulnerability in Small Footprint CIM Broker (SFCB) before 1.2.5 has unknown impact and attack vectors. | 1% Низкий | больше 4 лет назад | ||
GHSA-43ww-gwmw-f89v Server-Side Request Forgery (CWE-918) in Kibana allows authenticated users with connector management privileges to bypass the operator-configured connection allowlist. By configuring a Webhook connector with a crafted target, an attacker can cause Kibana to issue outbound requests to destinations that the egress restriction controls were intended to block. | CVSS3: 7.7 | 0% Низкий | 3 месяца назад | |
GHSA-43ww-866w-7xv9 IBM Security QRadar 3.12 EDR uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive credential information. | CVSS3: 5.9 | 0% Низкий | больше 1 года назад | |
GHSA-43ww-5h9q-8jh6 Unspecified vulnerability in the Solaris component in Oracle Sun Products Suite 8, 9, 10, and 11 Express allows remote attackers to affect availability via unknown vectors related to Remote Quota Server (rquotad). | 2% Низкий | больше 4 лет назад | ||
GHSA-43wv-w8q4-mcvr Windows MSHTML Platform Spoofing Vulnerability | CVSS3: 7.5 | 84% Высокий | около 2 лет назад | |
GHSA-43wv-g93j-pw44 Unspecified vulnerability in Serv-U File Server 7.0.0.1, and other versions before 7.2.0.1, allows remote authenticated users to cause a denial of service (daemon crash) via an SSH session with SFTP commands for directory creation and logging. | 2% Низкий | больше 4 лет назад | ||
GHSA-43wv-9mh2-86p7 Multiple cross-site request forgery (CSRF) vulnerabilities in PHPJabbers Appointment Scheduler 2.0 allow remote attackers to hijack the authentication of administrators for requests that (1) conduct cross-site scripting (XSS) attacks via the i18n[1][name] parameter in a pjActionCreate action to the pjAdminServices controller or (2) add an administrator via a pjActionCreate action to the pjAdminUsers controller. | 2% Низкий | больше 4 лет назад | ||
GHSA-43wv-9cr7-p3pg DLL Injection Vulnerability in McAfee Agent (MA) for Windows prior to 5.6.6 allows local users to execute arbitrary code via careful placement of a malicious DLL. | CVSS3: 6.7 | 0% Низкий | больше 4 лет назад | |
GHSA-43wv-69rq-rx33 The Themify Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and including, 7.6.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. The vulnerability was partially patched in version 7.6.9. | CVSS3: 6.4 | 0% Низкий | 12 месяцев назад | |
GHSA-43wr-9394-fxp2 OX App Suite before frontend 7.10.6-rev24 allows the loading (without user consent) of an e-mail message's remote resources during printing. | CVSS3: 5.3 | 1% Низкий | больше 3 лет назад | |
GHSA-43wr-5mwj-x7p2 IBM Security Directory Server 6.4.0 is deployed with active debugging code that can create unintended entry points. IBM X-Force ID: 165952. | 1% Низкий | больше 4 лет назад | ||
GHSA-43wq-xrcm-3vgr @discordjs/opus vulnerable to Denial of Service | CVSS3: 7.5 | 1% Низкий | около 2 лет назад | |
GHSA-43wq-xr5f-53ww Out-of-bounds read in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 14.0.33 may allow an unauthenticated user to potentially enable denial of service via network access. | CVSS3: 7.5 | 3% Низкий | больше 4 лет назад | |
GHSA-43wq-r34m-56ch In BigBlueButton before 2.2.28 (or earlier), uploaded presentations are sent to clients without a Content-Type header, which allows XSS, as demonstrated by a .png file extension for an HTML document. | 1% Низкий | больше 4 лет назад |
Уязвимостей на страницу