Количество 342 247
Количество 342 247
GHSA-2jx9-cx6r-jg2x
Microsoft Word Remote Code Execution Vulnerability.
GHSA-2jx8-v4hv-gx3h
XXE vulnerability in Launch import
GHSA-2jx8-662q-2wpq
The web portal in TC software on Cisco TelePresence endpoints does not require an exact password match during a login attempt by a user who has not configured a password, which allows remote attackers to bypass authentication by sending an arbitrary password, aka Bug ID CSCud96071.
GHSA-2jx7-xg83-j2m7
Zendframework Denial of Service vector via XEE injection
GHSA-2jx7-jqgc-hgxg
Cloudera Manager 5.8.x before 5.8.5, 5.9.x before 5.9.2, and 5.10.x before 5.10.1 allows a read-only Cloudera Manager user to discover the usernames of other users and elevate the privileges of those users.
GHSA-2jx6-v8vf-jjp6
Input validation vulnerability in Qualifio's Wheel of Fortune. This vulnerability could allow an attacker to modify a single email to contain upper and lower case characters in order to access the application and win prizes as many times as wanted.
GHSA-2jx5-wrfm-w8mv
Improper access control for some SigTest before version 6.1.10 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires active user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.
GHSA-2jx5-39j8-fv56
Unspecified vulnerability in HP IceWall SSO 10.0 Dfw and IceWall MCRP 2.1 and 3.0 allows remote attackers to cause a denial of service via unknown vectors.
GHSA-2jx4-xmvj-hmcw
An issue was discovered in the Shannon RCS component in Samsung Exynos Modem 5123 and 5300. An incorrect default permission can cause unintended querying of RCS capability via a crafted application.
GHSA-2jx4-mmr5-ww75
BatchSignCS, a background Windows application developed by WellChoose, has an Arbitrary File Write vulnerability. If a user visits a malicious website while the application is running, remote attackers can write arbitrary files to any path and potentially lead to arbitrary code execution.
GHSA-2jx4-7qpj-c9gc
Buffer overflow in Citadel SMTP server 7.10 and earlier allows remote attackers to execute arbitrary code via a long RCPT TO command, which is not properly handled by the makeuserkey function. NOTE: some of these details were obtained from third party information.
GHSA-2jx3-rgf3-fqhj
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.38. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N).
GHSA-2jx3-p89p-3f69
An authenticated user can perform XML eXternal Entity injection in Management Console in Symantec Identity Manager 14.4
GHSA-2jx3-m5vv-rvc6
Stack-based buffer overflow in Far Manager 1.70beta1 and earlier allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long pathname.
GHSA-2jx3-fx5f-r2c6
FFmpeg discovered to contain a code injection vulnerability in the component net.bramp.ffmpeg.FFmpeg.<constructor>
GHSA-2jx3-65f3-xr8r
spomky-labs/otphp: Mass-assignment in Factory::loadFromProvisioningUri lets a hostile provisioning URI corrupt OTP state or leak an uncaught TypeError
GHSA-2jx3-5j9v-prpp
BlockWishList SQL Injection vulnerability
GHSA-2jx2-x46f-wj52
**UNSUPPORTED WHEN ASSIGNED** A path traversal vulnerability in the web management interface of the Zyxel AMG1302-T10B firmware version 2.00(AAJC.16)C0 could allow an authenticated attacker with administrator privileges to access restricted directories by sending a crafted HTTP request to an affected device.
GHSA-2jx2-r7f9-93pw
Cross-site scripting vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, Ver.2.10.x series versions prior to Ver.2.10.50, and Ver.2.9.0 and earlier versions. If this vulnerability is exploited, a user with a contributor or higher privilege may execute an arbitrary script on the web browser of the user who accessed the website using the product.
GHSA-2jx2-qcm4-rf9h
Incomplete Internal State Distinction in GRPCWebToHTTP2ServerCodec
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2jx9-cx6r-jg2x Microsoft Word Remote Code Execution Vulnerability. | CVSS3: 7.8 | 1% Низкий | почти 4 года назад | |
GHSA-2jx8-v4hv-gx3h XXE vulnerability in Launch import | CVSS3: 7.5 | 1% Низкий | около 5 лет назад | |
GHSA-2jx8-662q-2wpq The web portal in TC software on Cisco TelePresence endpoints does not require an exact password match during a login attempt by a user who has not configured a password, which allows remote attackers to bypass authentication by sending an arbitrary password, aka Bug ID CSCud96071. | 1% Низкий | больше 4 лет назад | ||
GHSA-2jx7-xg83-j2m7 Zendframework Denial of Service vector via XEE injection | CVSS3: 7.5 | около 2 лет назад | ||
GHSA-2jx7-jqgc-hgxg Cloudera Manager 5.8.x before 5.8.5, 5.9.x before 5.9.2, and 5.10.x before 5.10.1 allows a read-only Cloudera Manager user to discover the usernames of other users and elevate the privileges of those users. | 1% Низкий | больше 4 лет назад | ||
GHSA-2jx6-v8vf-jjp6 Input validation vulnerability in Qualifio's Wheel of Fortune. This vulnerability could allow an attacker to modify a single email to contain upper and lower case characters in order to access the application and win prizes as many times as wanted. | CVSS3: 5.3 | 0% Низкий | больше 1 года назад | |
GHSA-2jx5-wrfm-w8mv Improper access control for some SigTest before version 6.1.10 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires active user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts. | CVSS3: 6.7 | 0% Низкий | 10 месяцев назад | |
GHSA-2jx5-39j8-fv56 Unspecified vulnerability in HP IceWall SSO 10.0 Dfw and IceWall MCRP 2.1 and 3.0 allows remote attackers to cause a denial of service via unknown vectors. | 4% Низкий | больше 4 лет назад | ||
GHSA-2jx4-xmvj-hmcw An issue was discovered in the Shannon RCS component in Samsung Exynos Modem 5123 and 5300. An incorrect default permission can cause unintended querying of RCS capability via a crafted application. | CVSS3: 9.8 | 1% Низкий | около 3 лет назад | |
GHSA-2jx4-mmr5-ww75 BatchSignCS, a background Windows application developed by WellChoose, has an Arbitrary File Write vulnerability. If a user visits a malicious website while the application is running, remote attackers can write arbitrary files to any path and potentially lead to arbitrary code execution. | CVSS3: 8.8 | 1% Низкий | около 1 года назад | |
GHSA-2jx4-7qpj-c9gc Buffer overflow in Citadel SMTP server 7.10 and earlier allows remote attackers to execute arbitrary code via a long RCPT TO command, which is not properly handled by the makeuserkey function. NOTE: some of these details were obtained from third party information. | 12% Средний | больше 4 лет назад | ||
GHSA-2jx3-rgf3-fqhj Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.38. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N). | CVSS3: 6 | 1% Низкий | почти 4 года назад | |
GHSA-2jx3-p89p-3f69 An authenticated user can perform XML eXternal Entity injection in Management Console in Symantec Identity Manager 14.4 | CVSS3: 8.8 | 1% Низкий | больше 3 лет назад | |
GHSA-2jx3-m5vv-rvc6 Stack-based buffer overflow in Far Manager 1.70beta1 and earlier allows local users to cause a denial of service (crash) and possibly execute arbitrary code via a long pathname. | 1% Низкий | больше 4 лет назад | ||
GHSA-2jx3-fx5f-r2c6 FFmpeg discovered to contain a code injection vulnerability in the component net.bramp.ffmpeg.FFmpeg.<constructor> | CVSS3: 9.8 | 1% Низкий | около 3 лет назад | |
GHSA-2jx3-65f3-xr8r spomky-labs/otphp: Mass-assignment in Factory::loadFromProvisioningUri lets a hostile provisioning URI corrupt OTP state or leak an uncaught TypeError | 2 месяца назад | |||
GHSA-2jx3-5j9v-prpp BlockWishList SQL Injection vulnerability | CVSS3: 8.1 | 24% Средний | около 4 лет назад | |
GHSA-2jx2-x46f-wj52 **UNSUPPORTED WHEN ASSIGNED** A path traversal vulnerability in the web management interface of the Zyxel AMG1302-T10B firmware version 2.00(AAJC.16)C0 could allow an authenticated attacker with administrator privileges to access restricted directories by sending a crafted HTTP request to an affected device. | CVSS3: 4.9 | 9% Низкий | больше 1 года назад | |
GHSA-2jx2-r7f9-93pw Cross-site scripting vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.7, Ver.3.0.x series versions prior to Ver.3.0.29, Ver.2.11.x series versions prior to Ver.2.11.58, Ver.2.10.x series versions prior to Ver.2.10.50, and Ver.2.9.0 and earlier versions. If this vulnerability is exploited, a user with a contributor or higher privilege may execute an arbitrary script on the web browser of the user who accessed the website using the product. | CVSS3: 5.4 | 0% Низкий | больше 2 лет назад | |
GHSA-2jx2-qcm4-rf9h Incomplete Internal State Distinction in GRPCWebToHTTP2ServerCodec | 2% Низкий | около 3 лет назад |
Уязвимостей на страницу