Количество 365 324
Количество 365 324
GHSA-3wgw-h3pq-p82c
Generation of Error Message Containing Sensitive Information vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Agent modules).This issue affects Hitachi Device Manager: before 8.8.5-04.
GHSA-3wgw-9fm4-w9hv
The Chartboost library before 2.0.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
GHSA-3wgv-24f6-hqhj
CVE was unused by HPE.
GHSA-3wgr-c9q2-xcp3
Insecure Permissions issue in Raiden Professional Server RaidenFTPD v.2.4 build 4005 allows a local attacker to gain privileges and execute arbitrary code via crafted executable running from the installation directory.
GHSA-3wgq-wrwc-vqmv
astral-tokio-tar has a path traversal in tar extraction
GHSA-3wgq-h4fr-cwg5
laravel-crud-wizard-free has File Validation Bypass
GHSA-3wgq-7p7q-x7pg
A iccselectdevtype expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
GHSA-3wgq-2r52-v65w
The start_authentication function in lightdm-gtk-greeter.c in LightDM GTK+ Greeter before 1.7.1 does not properly handle the return value from the lightdm_greeter_get_authentication_user function, which allows local users to cause a denial of service (NULL pointer dereference) via an empty username.
GHSA-3wgp-p23j-5xjj
SAP Commerce Cloud (previously known as SAP Hybris Commerce), (HY_COM, versions 6.3, 6.4, 6.5, 6.6, 6.7, 1808, 1811), allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service.
GHSA-3wgp-8w96-g9f5
Rejected reason: Not used
GHSA-3wgm-hxjc-v3w2
Inappropriate implementation in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
GHSA-3wgm-5fw2-jv64
Cross-site scripting (XSS) vulnerability in HP Service Manager 9.30 through 9.32 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
GHSA-3wgm-584m-j4r6
Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.
GHSA-3wgm-2gw2-vh5m
Kubernetes GitRepo Volume Inadvertent Local Repository Access
GHSA-3wgj-c2hg-vm6q
Open WebUI vulnerable to stored XSS via OAuth picture claim stored as SVG data URI in profile_image_url
GHSA-3wgh-5r9h-pf5v
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.36 and Prior to 5.2.10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data and unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.0 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H).
GHSA-3wgg-cmh5-mrf4
NEC Univerge Sv9100 WebPro 6.00.00 devices have Cleartext Password Storage in the Web UI.
GHSA-3wgg-3j4j-3f69
Jenkins Aqua Security Scanner Plugin vulnerability exposes scanner tokens
GHSA-3wgf-ccpx-rv72
Improper handling of insufficient permissions or privileges in Windows Installer allows an authorized attacker to elevate privileges locally.
GHSA-3wgc-2cj2-h23p
A vulnerability was found in Tenda A15 15.13.07.13. It has been classified as critical. This affects an unknown part of the file /goform/setBlackRule of the component Web-based Management Interface. The manipulation of the argument deviceList leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-250701 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3wgw-h3pq-p82c Generation of Error Message Containing Sensitive Information vulnerability in Hitachi Device Manager on Windows, Linux (Device Manager Agent modules).This issue affects Hitachi Device Manager: before 8.8.5-04. | CVSS3: 5.3 | 0% Низкий | больше 2 лет назад | |
GHSA-3wgw-9fm4-w9hv The Chartboost library before 2.0.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 0% Низкий | больше 4 лет назад | ||
GHSA-3wgv-24f6-hqhj CVE was unused by HPE. | больше 3 лет назад | |||
GHSA-3wgr-c9q2-xcp3 Insecure Permissions issue in Raiden Professional Server RaidenFTPD v.2.4 build 4005 allows a local attacker to gain privileges and execute arbitrary code via crafted executable running from the installation directory. | CVSS3: 7.3 | 0% Низкий | больше 2 лет назад | |
GHSA-3wgq-wrwc-vqmv astral-tokio-tar has a path traversal in tar extraction | 0% Низкий | 11 месяцев назад | ||
GHSA-3wgq-h4fr-cwg5 laravel-crud-wizard-free has File Validation Bypass | больше 1 года назад | |||
GHSA-3wgq-7p7q-x7pg A iccselectdevtype expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07). | 7% Низкий | больше 4 лет назад | ||
GHSA-3wgq-2r52-v65w The start_authentication function in lightdm-gtk-greeter.c in LightDM GTK+ Greeter before 1.7.1 does not properly handle the return value from the lightdm_greeter_get_authentication_user function, which allows local users to cause a denial of service (NULL pointer dereference) via an empty username. | 0% Низкий | больше 4 лет назад | ||
GHSA-3wgp-p23j-5xjj SAP Commerce Cloud (previously known as SAP Hybris Commerce), (HY_COM, versions 6.3, 6.4, 6.5, 6.6, 6.7, 1808, 1811), allows an attacker to prevent legitimate users from accessing a service, either by crashing or flooding the service. | CVSS3: 7.5 | 3% Низкий | больше 4 лет назад | |
GHSA-3wgp-8w96-g9f5 Rejected reason: Not used | 11 месяцев назад | |||
GHSA-3wgm-hxjc-v3w2 Inappropriate implementation in ANGLE in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High) | CVSS3: 6.5 | 0% Низкий | около 1 месяца назад | |
GHSA-3wgm-5fw2-jv64 Cross-site scripting (XSS) vulnerability in HP Service Manager 9.30 through 9.32 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 2% Низкий | больше 4 лет назад | ||
GHSA-3wgm-584m-j4r6 Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier, 2017.011.30138 and earlier, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution. | 7% Низкий | больше 4 лет назад | ||
GHSA-3wgm-2gw2-vh5m Kubernetes GitRepo Volume Inadvertent Local Repository Access | CVSS3: 6.5 | 1% Низкий | больше 1 года назад | |
GHSA-3wgj-c2hg-vm6q Open WebUI vulnerable to stored XSS via OAuth picture claim stored as SVG data URI in profile_image_url | CVSS3: 7.3 | 4 месяца назад | ||
GHSA-3wgh-5r9h-pf5v Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.36 and Prior to 5.2.10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data and unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.0 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H). | CVSS3: 6.6 | 0% Низкий | больше 4 лет назад | |
GHSA-3wgg-cmh5-mrf4 NEC Univerge Sv9100 WebPro 6.00.00 devices have Cleartext Password Storage in the Web UI. | CVSS3: 9.8 | 14% Средний | больше 4 лет назад | |
GHSA-3wgg-3j4j-3f69 Jenkins Aqua Security Scanner Plugin vulnerability exposes scanner tokens | CVSS3: 4.3 | 0% Низкий | около 1 года назад | |
GHSA-3wgf-ccpx-rv72 Improper handling of insufficient permissions or privileges in Windows Installer allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 5 месяцев назад | |
GHSA-3wgc-2cj2-h23p A vulnerability was found in Tenda A15 15.13.07.13. It has been classified as critical. This affects an unknown part of the file /goform/setBlackRule of the component Web-based Management Interface. The manipulation of the argument deviceList leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-250701 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 7.2 | 2% Низкий | больше 2 лет назад |
Уязвимостей на страницу