Количество 365 060
Количество 365 060
GHSA-3v6v-w2x6-55vq
Privilege escalation vulnerability in McAfee Agent (MA) before 5.6.1 HF3, allows local administrator users to potentially disable some McAfee processes by manipulating the MA directory control and placing a carefully constructed file in the MA directory.
GHSA-3v6v-6vwq-2h95
Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network.
GHSA-3v6v-2x6p-32mc
pgadmin4 vulnerable to Code Injection
GHSA-3v6r-vhg4-9m9j
IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.
GHSA-3v6r-pw5p-6hc2
An elevation of privilege exists in Windows Audio Service, aka 'Windows Audio Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1021, CVE-2019-1022, CVE-2019-1026, CVE-2019-1027, CVE-2019-1028.
GHSA-3v6q-chwv-xhhp
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Smplug-in Social Like Box and Page by WpDevArt plugin <= 0.8.39 versions.
GHSA-3v6p-5m88-xqx6
Integer overflow in the wrestool program in icoutils before 0.31.1 allows remote attackers to cause a denial of service (memory corruption) via a crafted executable, which triggers a denial of service (application crash) or the possibility of execution of arbitrary code.
GHSA-3v6p-5g46-w432
Improper input validation in some Intel(R) Neural Compressor software before version v3.0 may allow an authenticated user to potentially enable escalation of privilege via adjacent access.
GHSA-3v6m-8v49-4vvq
Race condition in the administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows remote attackers to obtain privileged-account access, and consequently provide ZipDownload.jsp input containing directory traversal sequences to read arbitrary files, via a request to port 40080 or 40443.
GHSA-3v6j-v3qc-cxff
Denial of service from unlimited password lengths
GHSA-3v6j-pmgg-8c38
Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) private JPEG data. Successful exploitation could lead to arbitrary code execution.
GHSA-3v6j-9mf5-wv3f
The default password for the web application’s root user (the vendor’s private account) was weak and the MD5 hash was used to crack the password using a widely available open-source tool.
GHSA-3v6h-ww3h-9h87
SQL injection vulnerability in poll_frame.php in Vote! Pro 4.0 and earlier allows remote attackers to execute arbitrary SQL commands via the poll_id parameter.
GHSA-3v6h-m7q4-2c4g
A directory traversal vulnerability exists in the BIG-IP Configuration Utility that may allow an authenticated attacker to execute commands on the BIG-IP system. For BIG-IP system running in Appliance mode, a successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
GHSA-3v6h-hqm4-2rg6
Arbitrary File Write in adm-zip
GHSA-3v6h-4jjq-8c6c
A weakness has been identified in elunez eladmin up to 2.7. This affects the function exportUser. This manipulation causes csv injection. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited.
GHSA-3v6g-g235-cmv9
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 BEAR woo-bulk-editor allows Blind SQL Injection.This issue affects BEAR: from n/a through <= 1.1.7.1.
GHSA-3v6f-w66g-3mv6
A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before processing. A local attacker can exploit this via a crafted protocol v1 request to the PAM responder socket, causing an out-of-bounds read and process crash, resulting in a denial of service.
GHSA-3v6f-r45v-h8fj
When reading a file, an uninitialized value could have been used as read limit. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11.
GHSA-3v6f-p2hc-xq2j
A weakness has been identified in LinkStackOrg LinkStack up to 4.8.6. Impacted is the function editPage of the file app/Http/Controllers/UserController.php. Executing a manipulation of the argument pageDescription can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a pull request but has not reacted yet.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3v6v-w2x6-55vq Privilege escalation vulnerability in McAfee Agent (MA) before 5.6.1 HF3, allows local administrator users to potentially disable some McAfee processes by manipulating the MA directory control and placing a carefully constructed file in the MA directory. | 0% Низкий | больше 4 лет назад | ||
GHSA-3v6v-6vwq-2h95 Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a security feature over a network. | CVSS3: 5.3 | 0% Низкий | 20 дней назад | |
GHSA-3v6v-2x6p-32mc pgadmin4 vulnerable to Code Injection | CVSS3: 8.8 | 80% Высокий | больше 3 лет назад | |
GHSA-3v6r-vhg4-9m9j IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server. | CVSS3: 8.8 | 2% Низкий | больше 4 лет назад | |
GHSA-3v6r-pw5p-6hc2 An elevation of privilege exists in Windows Audio Service, aka 'Windows Audio Service Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2019-1021, CVE-2019-1022, CVE-2019-1026, CVE-2019-1027, CVE-2019-1028. | CVSS3: 7.8 | 1% Низкий | больше 4 лет назад | |
GHSA-3v6q-chwv-xhhp Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Smplug-in Social Like Box and Page by WpDevArt plugin <= 0.8.39 versions. | CVSS3: 4.8 | 0% Низкий | больше 3 лет назад | |
GHSA-3v6p-5m88-xqx6 Integer overflow in the wrestool program in icoutils before 0.31.1 allows remote attackers to cause a denial of service (memory corruption) via a crafted executable, which triggers a denial of service (application crash) or the possibility of execution of arbitrary code. | CVSS3: 8.8 | 4% Низкий | больше 4 лет назад | |
GHSA-3v6p-5g46-w432 Improper input validation in some Intel(R) Neural Compressor software before version v3.0 may allow an authenticated user to potentially enable escalation of privilege via adjacent access. | CVSS3: 5.5 | 0% Низкий | почти 2 года назад | |
GHSA-3v6m-8v49-4vvq Race condition in the administration-panel web service in IBM System Networking Switch Center (SNSC) before 7.3.1.5 and Lenovo Switch Center before 8.1.2.0 allows remote attackers to obtain privileged-account access, and consequently provide ZipDownload.jsp input containing directory traversal sequences to read arbitrary files, via a request to port 40080 or 40443. | 1% Низкий | больше 4 лет назад | ||
GHSA-3v6j-v3qc-cxff Denial of service from unlimited password lengths | CVSS3: 5.3 | 1% Низкий | около 3 лет назад | |
GHSA-3v6j-pmgg-8c38 Adobe Acrobat Reader 2017.009.20058 and earlier, 2017.008.30051 and earlier, 2015.006.30306 and earlier, and 11.0.20 and earlier has an exploitable memory corruption vulnerability in the image conversion engine when processing Enhanced Metafile Format (EMF) private JPEG data. Successful exploitation could lead to arbitrary code execution. | CVSS3: 8.8 | 7% Низкий | больше 4 лет назад | |
GHSA-3v6j-9mf5-wv3f The default password for the web application’s root user (the vendor’s private account) was weak and the MD5 hash was used to crack the password using a widely available open-source tool. | CVSS3: 6.5 | 1% Низкий | около 4 лет назад | |
GHSA-3v6h-ww3h-9h87 SQL injection vulnerability in poll_frame.php in Vote! Pro 4.0 and earlier allows remote attackers to execute arbitrary SQL commands via the poll_id parameter. | 1% Низкий | больше 4 лет назад | ||
GHSA-3v6h-m7q4-2c4g A directory traversal vulnerability exists in the BIG-IP Configuration Utility that may allow an authenticated attacker to execute commands on the BIG-IP system. For BIG-IP system running in Appliance mode, a successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | CVSS3: 9.9 | 2% Низкий | почти 3 года назад | |
GHSA-3v6h-hqm4-2rg6 Arbitrary File Write in adm-zip | CVSS3: 5.5 | 15% Средний | около 8 лет назад | |
GHSA-3v6h-4jjq-8c6c A weakness has been identified in elunez eladmin up to 2.7. This affects the function exportUser. This manipulation causes csv injection. The attack may be initiated remotely. The exploit has been made available to the public and could be exploited. | CVSS3: 6.3 | 0% Низкий | около 1 года назад | |
GHSA-3v6g-g235-cmv9 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in RealMag777 BEAR woo-bulk-editor allows Blind SQL Injection.This issue affects BEAR: from n/a through <= 1.1.7.1. | CVSS3: 7.6 | 0% Низкий | 4 месяца назад | |
GHSA-3v6f-w66g-3mv6 A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before processing. A local attacker can exploit this via a crafted protocol v1 request to the PAM responder socket, causing an out-of-bounds read and process crash, resulting in a denial of service. | CVSS3: 5.5 | 0% Низкий | 27 дней назад | |
GHSA-3v6f-r45v-h8fj When reading a file, an uninitialized value could have been used as read limit. This vulnerability affects Firefox < 113, Firefox ESR < 102.11, and Thunderbird < 102.11. | CVSS3: 8.8 | 1% Низкий | около 3 лет назад | |
GHSA-3v6f-p2hc-xq2j A weakness has been identified in LinkStackOrg LinkStack up to 4.8.6. Impacted is the function editPage of the file app/Http/Controllers/UserController.php. Executing a manipulation of the argument pageDescription can lead to cross site scripting. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through a pull request but has not reacted yet. | CVSS3: 3.5 | 0% Низкий | 4 месяца назад |
Уязвимостей на страницу