Количество 365 060
Количество 365 060
GHSA-3vhm-q4w3-rw8q
OroPlatform Forced Redirect to External Website
GHSA-3vhm-28vh-hww9
Stack-based buffer overflow in the TEA decoding algorithm in RhinoSoft Serv-U FTP server 7.0.0.1, 9.0.0.5, and other versions before 9.1.0.0 allows remote attackers to execute arbitrary code via a long hexadecimal string.
GHSA-3vhj-m86h-3wmf
IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 198834.
GHSA-3vhj-7fhw-rq33
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
GHSA-3vhh-8wwm-whvg
In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Add NULL ptr dereference checking at the end of attr_allocate_frame() It is preferable to exit through the out: label because internal debugging functions are located there.
GHSA-3vhh-58w3-43m4
Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Java DB). Supported versions that are affected are Java SE: 6u191, 7u181 and 8u172. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. While the vulnerability is in Java SE, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVE-2018-2938 addresses CVE-2018-1313. CVSS 3.0 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H).
GHSA-3vhg-jg9c-c6r7
ManageEngine ADSelfService Plus before 6112 is vulnerable to mail spoofing.
GHSA-3vhg-2gj6-mm5q
A vulnerability, which was classified as problematic, has been found in Shoplazza 1.1. This issue affects some unknown processing of the file /admin/api/admin/articles/ of the component Add Blog Post Handler. The manipulation of the argument Title leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-216191.
GHSA-3vhf-gvj3-rcch
Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an internal maintenance REST API (if enabled by Admin user from UI). A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain APIs applicable only for Admin Users on the application's backend database that could potentially allow an unauthorized user access to restricted resources and change of state.
GHSA-3vhc-wxjg-c7wf
An issue was discovered on Samsung mobile devices with Q(10.0) software. Attackers can trigger an out-of-bounds access and device reset via a 4K wallpaper image because ImageProcessHelper mishandles boundary checks. The Samsung ID is SVE-2020-18056 (July 2020).
GHSA-3vhc-576x-3qv4
Hono JWK Auth Middleware has JWT algorithm confusion when JWK lacks "alg" (untrusted header.alg fallback)
GHSA-3vhc-4mgh-2vvp
In the Linux kernel, the following vulnerability has been resolved: arp: use RCU protection in arp_xmit() arp_xmit() can be called without RTNL or RCU protection. Use RCU protection to avoid potential UAF.
GHSA-3vh9-fqgx-vjph
Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
GHSA-3vh9-9frp-jhqv
OpenTofu versions before 1.11.4 contain a denial of service vulnerability in the tofu init command when processing maliciously-crafted .zip archives for provider or module packages. Attackers can cause excessive CPU usage by controlling .zip archive content served during dependency installation, degrading system performance and preventing timely completion of the init process.
GHSA-3vh9-8p9q-8wmw
Open Web Analytics (OWA) before 1.5.6 improperly generates random nonce values, which makes it easier for remote attackers to bypass a CSRF protection mechanism by leveraging knowledge of an OWA user name.
GHSA-3vh8-f4xf-hgr4
The (1) dupatch and (2) setld utilities in HP Tru64 UNIX 5.1B PK1 and earlier allows local users to overwrite files and possibly gain root privileges via a symlink attack.
GHSA-3vh8-3f6g-98cq
The examapp plugin 1.0 for WordPress has XSS via exam input text fields.
GHSA-3vh7-ff9w-cqhq
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Monterey 12.7.4, watchOS 10.3, tvOS 17.3, macOS Ventura 13.6.5, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3. An app may be able to cause a denial-of-service.
GHSA-3vh6-pp7q-5xhf
A cross-site scripting (XSS) vulnerability in the Admin Login page of Allworx System Software v9.1.9.12 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the SessionID parameter at query.asp.
GHSA-3vh6-2h2q-2g33
BTS is affected by information disclosure vulnerability where mobile network operator personnel connected over BTS Web Element Manager, regardless of the access privileges, having a possibility to read BTS service operation details performed by Nokia Care service personnel via SSH.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3vhm-q4w3-rw8q OroPlatform Forced Redirect to External Website | CVSS3: 6.1 | больше 2 лет назад | ||
GHSA-3vhm-28vh-hww9 Stack-based buffer overflow in the TEA decoding algorithm in RhinoSoft Serv-U FTP server 7.0.0.1, 9.0.0.5, and other versions before 9.1.0.0 allows remote attackers to execute arbitrary code via a long hexadecimal string. | 83% Высокий | больше 4 лет назад | ||
GHSA-3vhj-m86h-3wmf IBM Jazz Reporting Service 6.0.6.1, 7.0, 7.0.1, and 7.0.2 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 198834. | 1% Низкий | больше 4 лет назад | ||
GHSA-3vhj-7fhw-rq33 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | больше 1 года назад | |||
GHSA-3vhh-8wwm-whvg In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Add NULL ptr dereference checking at the end of attr_allocate_frame() It is preferable to exit through the out: label because internal debugging functions are located there. | CVSS3: 5.5 | 0% Низкий | больше 2 лет назад | |
GHSA-3vhh-58w3-43m4 Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Java DB). Supported versions that are affected are Java SE: 6u191, 7u181 and 8u172. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE. While the vulnerability is in Java SE, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java SE. Note: This vulnerability can only be exploited by supplying data to APIs in the specified Component without using Untrusted Java Web Start applications or Untrusted Java applets, such as through a web service. CVE-2018-2938 addresses CVE-2018-1313. CVSS 3.0 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H). | CVSS3: 9 | 2% Низкий | больше 4 лет назад | |
GHSA-3vhg-jg9c-c6r7 ManageEngine ADSelfService Plus before 6112 is vulnerable to mail spoofing. | CVSS3: 6.5 | 2% Низкий | больше 4 лет назад | |
GHSA-3vhg-2gj6-mm5q A vulnerability, which was classified as problematic, has been found in Shoplazza 1.1. This issue affects some unknown processing of the file /admin/api/admin/articles/ of the component Add Blog Post Handler. The manipulation of the argument Title leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-216191. | CVSS3: 5.4 | 1% Низкий | больше 3 лет назад | |
GHSA-3vhf-gvj3-rcch Dell SCG, versions prior to 5.24.00.00, contain an Improper Access Control vulnerability in the SCG exposed for an internal maintenance REST API (if enabled by Admin user from UI). A remote low privileged attacker could potentially exploit this vulnerability, leading to the execution of certain APIs applicable only for Admin Users on the application's backend database that could potentially allow an unauthorized user access to restricted resources and change of state. | CVSS3: 5.4 | 0% Низкий | около 2 лет назад | |
GHSA-3vhc-wxjg-c7wf An issue was discovered on Samsung mobile devices with Q(10.0) software. Attackers can trigger an out-of-bounds access and device reset via a 4K wallpaper image because ImageProcessHelper mishandles boundary checks. The Samsung ID is SVE-2020-18056 (July 2020). | 0% Низкий | больше 4 лет назад | ||
GHSA-3vhc-576x-3qv4 Hono JWK Auth Middleware has JWT algorithm confusion when JWK lacks "alg" (untrusted header.alg fallback) | CVSS3: 8.2 | 0% Низкий | 8 месяцев назад | |
GHSA-3vhc-4mgh-2vvp In the Linux kernel, the following vulnerability has been resolved: arp: use RCU protection in arp_xmit() arp_xmit() can be called without RTNL or RCU protection. Use RCU protection to avoid potential UAF. | CVSS3: 7.8 | 1% Низкий | больше 1 года назад | |
GHSA-3vh9-fqgx-vjph Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 1% Низкий | около 1 года назад | |
GHSA-3vh9-9frp-jhqv OpenTofu versions before 1.11.4 contain a denial of service vulnerability in the tofu init command when processing maliciously-crafted .zip archives for provider or module packages. Attackers can cause excessive CPU usage by controlling .zip archive content served during dependency installation, degrading system performance and preventing timely completion of the init process. | CVSS3: 3.1 | 0% Низкий | 16 дней назад | |
GHSA-3vh9-8p9q-8wmw Open Web Analytics (OWA) before 1.5.6 improperly generates random nonce values, which makes it easier for remote attackers to bypass a CSRF protection mechanism by leveraging knowledge of an OWA user name. | CVSS3: 8.8 | 1% Низкий | больше 4 лет назад | |
GHSA-3vh8-f4xf-hgr4 The (1) dupatch and (2) setld utilities in HP Tru64 UNIX 5.1B PK1 and earlier allows local users to overwrite files and possibly gain root privileges via a symlink attack. | 0% Низкий | больше 4 лет назад | ||
GHSA-3vh8-3f6g-98cq The examapp plugin 1.0 for WordPress has XSS via exam input text fields. | 1% Низкий | больше 4 лет назад | ||
GHSA-3vh7-ff9w-cqhq A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Monterey 12.7.4, watchOS 10.3, tvOS 17.3, macOS Ventura 13.6.5, iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3. An app may be able to cause a denial-of-service. | CVSS3: 6.2 | 0% Низкий | больше 2 лет назад | |
GHSA-3vh6-pp7q-5xhf A cross-site scripting (XSS) vulnerability in the Admin Login page of Allworx System Software v9.1.9.12 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the SessionID parameter at query.asp. | CVSS3: 6.1 | 0% Низкий | около 1 года назад | |
GHSA-3vh6-2h2q-2g33 BTS is affected by information disclosure vulnerability where mobile network operator personnel connected over BTS Web Element Manager, regardless of the access privileges, having a possibility to read BTS service operation details performed by Nokia Care service personnel via SSH. | CVSS3: 3.3 | 0% Низкий | почти 2 года назад |
Уязвимостей на страницу