Количество 366 653
Количество 366 653
GHSA-436g-fhfc-9g5w
D-Tale: Remote Code Execution through redis/shelf storage
GHSA-436g-2f92-cvhh
Jenkins Role-based Authorization Strategy Plugin grants permissions even after they’ve been disabled
GHSA-436f-fmh9-32gq
IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty could provide weaker than expected security when administering security settings.
GHSA-436f-chr9-2p6r
The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root with insufficient access control, which allows remote attackers to obtain sensitive setup and configuration information via a direct request.
GHSA-436c-96vr-9jcq
Integer overflow in the plist_from_bin function in bplist.c in libimobiledevice/libplist before 2017-04-19 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted plist file.
GHSA-4369-x39w-2545
VMware ESX Server 1.5.2 before Patch 4 allows local users to execute arbitrary programs as root via certain modified VMware ESX Server environment variables.
GHSA-4369-mg8x-jq9f
An authorization bypass vulnerability exists in the Mavenir SCE Application Provisioning Portal, version PORTAL-LBS-R_1_0_24_0, which allows an authenticated 'guest' user to perform unauthorized administrative actions, such as accessing the 'add user' feature, by bypassing client-side access controls.
GHSA-4368-7mjc-5763
A resample query can be used to trigger out-of-memory crashes in Grafana.
GHSA-4368-3x2v-g4cm
Google V8, as used in Google Chrome before 28.0.1500.95, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that leverage "type confusion."
GHSA-4368-2cqv-7wjv
Cross-site scripting (XSS) vulnerability in Daverave Simplog 1.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via a blog post.
GHSA-4367-vj5g-xqcr
Double free vulnerability in Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allows attackers to execute arbitrary code via unspecified vectors.
GHSA-4367-rch8-6vrp
PHP remote file inclusion vulnerability in SmartSiteCMS 1.0 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the root parameter in (1) comment.php, (2) admin/comedit.php, (3) admin/test.php, (4) admin/index.php, and (5) admin/include/inc_adminfoot.php, a different set of vectors than CVE-2006-3162.
GHSA-4367-pw62-mx9j
The IBM Integration Bus for z/OS 10.1 through 10.1.0.2 AdminAPI is vulnerable to a denial of service due to file system exhaustion. IBM X-Force ID: 279972.
GHSA-4367-8h95-cxcx
An issue in ClipBucket v5 v.5.5.2 allows an attacker to execute arbitrary code via the Authentication interface, login page endpoint and HTTP response security headers components
GHSA-4367-36c5-2mx8
DedeCMS V5.7.99 was discovered to contain an arbitrary file upload vulnerability via the component /dede/file_manage_control.php.
GHSA-4366-c9hw-r9qg
In the Linux kernel, the following vulnerability has been resolved: xen: privcmd: Fix possible access to a freed kirqfd instance Nothing prevents simultaneous ioctl calls to privcmd_irqfd_assign() and privcmd_irqfd_deassign(). If that happens, it is possible that a kirqfd created and added to the irqfds_list by privcmd_irqfd_assign() may get removed by another thread executing privcmd_irqfd_deassign(), while the former is still using it after dropping the locks. This can lead to a situation where an already freed kirqfd instance may be accessed and cause kernel oops. Use SRCU locking to prevent the same, as is done for the KVM implementation for irqfds.
GHSA-4365-vm8j-8w63
Cross-site scripting (XSS) vulnerability in the Notifications form in Red Hat Subscription Asset Manager before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the username field.
GHSA-4365-fhm5-qcrx
Maliciously Crafted Model Archive Can Lead To Arbitrary File Write
GHSA-4364-jq2q-6hrc
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow an authenticated user to cause a denial of service due to improper allocation of resources.
GHSA-4363-x42f-xph6
Malicious Package in hw-trnasport-u2f
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-436g-fhfc-9g5w D-Tale: Remote Code Execution through redis/shelf storage | 1% Низкий | 5 месяцев назад | ||
GHSA-436g-2f92-cvhh Jenkins Role-based Authorization Strategy Plugin grants permissions even after they’ve been disabled | CVSS3: 5.9 | 1% Низкий | больше 3 лет назад | |
GHSA-436f-fmh9-32gq IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.3 IBM WebSphere Application Server Liberty could provide weaker than expected security when administering security settings. | CVSS3: 6.7 | 0% Низкий | 5 месяцев назад | |
GHSA-436f-chr9-2p6r The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root with insufficient access control, which allows remote attackers to obtain sensitive setup and configuration information via a direct request. | 2% Низкий | больше 4 лет назад | ||
GHSA-436c-96vr-9jcq Integer overflow in the plist_from_bin function in bplist.c in libimobiledevice/libplist before 2017-04-19 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted plist file. | CVSS3: 5.5 | 1% Низкий | больше 4 лет назад | |
GHSA-4369-x39w-2545 VMware ESX Server 1.5.2 before Patch 4 allows local users to execute arbitrary programs as root via certain modified VMware ESX Server environment variables. | 0% Низкий | больше 4 лет назад | ||
GHSA-4369-mg8x-jq9f An authorization bypass vulnerability exists in the Mavenir SCE Application Provisioning Portal, version PORTAL-LBS-R_1_0_24_0, which allows an authenticated 'guest' user to perform unauthorized administrative actions, such as accessing the 'add user' feature, by bypassing client-side access controls. | CVSS3: 8.8 | 0% Низкий | больше 1 года назад | |
GHSA-4368-7mjc-5763 A resample query can be used to trigger out-of-memory crashes in Grafana. | CVSS3: 6.5 | 0% Низкий | 5 месяцев назад | |
GHSA-4368-3x2v-g4cm Google V8, as used in Google Chrome before 28.0.1500.95, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that leverage "type confusion." | 3% Низкий | больше 4 лет назад | ||
GHSA-4368-2cqv-7wjv Cross-site scripting (XSS) vulnerability in Daverave Simplog 1.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via a blog post. | 1% Низкий | больше 4 лет назад | ||
GHSA-4367-vj5g-xqcr Double free vulnerability in Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on Linux, Adobe AIR before 15.0.0.356, Adobe AIR SDK before 15.0.0.356, and Adobe AIR SDK & Compiler before 15.0.0.356 allows attackers to execute arbitrary code via unspecified vectors. | 8% Низкий | больше 4 лет назад | ||
GHSA-4367-rch8-6vrp PHP remote file inclusion vulnerability in SmartSiteCMS 1.0 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the root parameter in (1) comment.php, (2) admin/comedit.php, (3) admin/test.php, (4) admin/index.php, and (5) admin/include/inc_adminfoot.php, a different set of vectors than CVE-2006-3162. | 4% Низкий | больше 4 лет назад | ||
GHSA-4367-pw62-mx9j The IBM Integration Bus for z/OS 10.1 through 10.1.0.2 AdminAPI is vulnerable to a denial of service due to file system exhaustion. IBM X-Force ID: 279972. | CVSS3: 6.5 | 1% Низкий | больше 2 лет назад | |
GHSA-4367-8h95-cxcx An issue in ClipBucket v5 v.5.5.2 allows an attacker to execute arbitrary code via the Authentication interface, login page endpoint and HTTP response security headers components | CVSS3: 7.3 | 0% Низкий | 3 месяца назад | |
GHSA-4367-36c5-2mx8 DedeCMS V5.7.99 was discovered to contain an arbitrary file upload vulnerability via the component /dede/file_manage_control.php. | CVSS3: 7.2 | 1% Низкий | почти 4 года назад | |
GHSA-4366-c9hw-r9qg In the Linux kernel, the following vulnerability has been resolved: xen: privcmd: Fix possible access to a freed kirqfd instance Nothing prevents simultaneous ioctl calls to privcmd_irqfd_assign() and privcmd_irqfd_deassign(). If that happens, it is possible that a kirqfd created and added to the irqfds_list by privcmd_irqfd_assign() may get removed by another thread executing privcmd_irqfd_deassign(), while the former is still using it after dropping the locks. This can lead to a situation where an already freed kirqfd instance may be accessed and cause kernel oops. Use SRCU locking to prevent the same, as is done for the KVM implementation for irqfds. | CVSS3: 5.5 | 0% Низкий | почти 2 года назад | |
GHSA-4365-vm8j-8w63 Cross-site scripting (XSS) vulnerability in the Notifications form in Red Hat Subscription Asset Manager before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the username field. | 2% Низкий | больше 4 лет назад | ||
GHSA-4365-fhm5-qcrx Maliciously Crafted Model Archive Can Lead To Arbitrary File Write | CVSS3: 7.3 | 1% Низкий | почти 5 лет назад | |
GHSA-4364-jq2q-6hrc IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5.0 - 11.5.9 and 12.1.0 - 12.1.3 could allow an authenticated user to cause a denial of service due to improper allocation of resources. | CVSS3: 6.5 | 0% Низкий | 7 месяцев назад | |
GHSA-4363-x42f-xph6 Malicious Package in hw-trnasport-u2f | CVSS3: 9.1 | около 6 лет назад |
Уязвимостей на страницу