Количество 364 920
Количество 364 920
GHSA-3rjm-q6hg-6jw8
RealOne Player 2.0 Build 6.0.11.872 allows remote attackers to cause a denial of service (array out-of-bounds access and application crash) via a crafted .aiff file.
GHSA-3rjm-jwr3-fh58
Buffer overflow in the Napster client beta 5 allows remote attackers to cause a denial of service via a long message.
GHSA-3rjj-rpg2-4f2q
Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Branch Intelligent Management System Software Module (aka BIMS) allows remote attackers to obtain sensitive information via unknown vectors, aka ZDI-CAN-1607.
GHSA-3rjh-r4h7-c3mq
Broadcast control frames can disconnect multiple aircraft simultaneously leading to delayed clearances and air traffic controller overload. This type of attack can be carried out remotely over radio frequency.
GHSA-3rjh-fcp5-cg7v
In BIG-IQ 5.2.0-7.0.0, high availability (HA) synchronization is not secure by TLS and may allow on-path attackers to read / modify confidential data in transit.
GHSA-3rjh-cgv2-5vr4
Directory traversal vulnerability in filemanager.asp for Hosting Controller 1.4.1 and earlier allows remote attackers to read and modify arbitrary files, and execute commands, via a .. (dot dot) in the OpenPath parameter.
GHSA-3rjg-j65w-6v3j
Rejected reason: Not used
GHSA-3rjg-j575-7f6p
Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.
GHSA-3rjg-j22m-wrv3
A mediaforaction expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
GHSA-3rjg-g3j8-q837
D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formLanguageChange. This vulnerability allows attackers to cause a Denial of Service (DoS) via the nextPage parameter.
GHSA-3rjg-ff6r-x2c7
A vulnerability was found in Rebuild up to 3.5.5. It has been classified as problematic. Affected is the function getFileOfData of the file /filex/read-raw. The manipulation of the argument url leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252456.
GHSA-3rjg-586v-gcmf
Beauty Parlour Booking Script 1.0 has SQL Injection via the /list gender or city parameter.
GHSA-3rjf-4xj2-6g8f
** DISPUTED ** Race condition in Norman Security Suite PRO 8.0 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute.
GHSA-3rjc-xpqg-5mh4
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to delete or read arbitrary files on the underlying operating system. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
GHSA-3rjc-6hx2-f4rh
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "sta_log_htm" API which are not properly sanitized before being concatenated to OS level commands.
GHSA-3rjc-33r8-4463
Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1.3.5.1 and 11.1.1.6.0 allows remote attackers to affect integrity via unknown vectors related to Content Server.
GHSA-3rj9-ppgw-ffcc
In the PatientService.pl service, the "getPatientIdentifier" function is vulnerable to SQL injection through the "pesel" parameter.
GHSA-3rj8-qvqp-3335
Adobe Flash Player versions 29.0.0.171 and earlier have a Stack-based buffer overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.
GHSA-3rj8-qrpc-rrvr
HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints are accessible without any form of authentication in another browser. This allows any network user to invoke these APIs and interact with the application without verification of their identity or authorization level.
GHSA-3rj8-3jwx-jcjj
Amberdms Billing System (ABS) before 1.4.1, when a multi-instance installation is configured, might allow local users to obtain sensitive information by reading the cache in between runs of the include/cron/services_usage.php cron job.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3rjm-q6hg-6jw8 RealOne Player 2.0 Build 6.0.11.872 allows remote attackers to cause a denial of service (array out-of-bounds access and application crash) via a crafted .aiff file. | CVSS3: 5.5 | 1% Низкий | больше 4 лет назад | |
GHSA-3rjm-jwr3-fh58 Buffer overflow in the Napster client beta 5 allows remote attackers to cause a denial of service via a long message. | 1% Низкий | больше 4 лет назад | ||
GHSA-3rjj-rpg2-4f2q Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Branch Intelligent Management System Software Module (aka BIMS) allows remote attackers to obtain sensitive information via unknown vectors, aka ZDI-CAN-1607. | 38% Средний | больше 4 лет назад | ||
GHSA-3rjh-r4h7-c3mq Broadcast control frames can disconnect multiple aircraft simultaneously leading to delayed clearances and air traffic controller overload. This type of attack can be carried out remotely over radio frequency. | CVSS3: 5.3 | 0% Низкий | 23 дня назад | |
GHSA-3rjh-fcp5-cg7v In BIG-IQ 5.2.0-7.0.0, high availability (HA) synchronization is not secure by TLS and may allow on-path attackers to read / modify confidential data in transit. | 0% Низкий | больше 4 лет назад | ||
GHSA-3rjh-cgv2-5vr4 Directory traversal vulnerability in filemanager.asp for Hosting Controller 1.4.1 and earlier allows remote attackers to read and modify arbitrary files, and execute commands, via a .. (dot dot) in the OpenPath parameter. | 4% Низкий | больше 4 лет назад | ||
GHSA-3rjg-j65w-6v3j Rejected reason: Not used | 8 месяцев назад | |||
GHSA-3rjg-j575-7f6p Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'. | CVSS3: 4.7 | 3% Низкий | больше 4 лет назад | |
GHSA-3rjg-j22m-wrv3 A mediaforaction expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07). | 3% Низкий | больше 4 лет назад | ||
GHSA-3rjg-g3j8-q837 D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formLanguageChange. This vulnerability allows attackers to cause a Denial of Service (DoS) via the nextPage parameter. | CVSS3: 7.5 | 1% Низкий | больше 4 лет назад | |
GHSA-3rjg-ff6r-x2c7 A vulnerability was found in Rebuild up to 3.5.5. It has been classified as problematic. Affected is the function getFileOfData of the file /filex/read-raw. The manipulation of the argument url leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252456. | CVSS3: 3.5 | 1% Низкий | больше 2 лет назад | |
GHSA-3rjg-586v-gcmf Beauty Parlour Booking Script 1.0 has SQL Injection via the /list gender or city parameter. | CVSS3: 9.8 | 2% Низкий | больше 4 лет назад | |
GHSA-3rjf-4xj2-6g8f ** DISPUTED ** Race condition in Norman Security Suite PRO 8.0 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute. | 0% Низкий | больше 4 лет назад | ||
GHSA-3rjc-xpqg-5mh4 Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to delete or read arbitrary files on the underlying operating system. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. | CVSS3: 5.4 | 0% Низкий | больше 3 лет назад | |
GHSA-3rjc-6hx2-f4rh A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "sta_log_htm" API which are not properly sanitized before being concatenated to OS level commands. | CVSS3: 7.2 | 1% Низкий | почти 2 года назад | |
GHSA-3rjc-33r8-4463 Unspecified vulnerability in the Oracle WebCenter Content component in Oracle Fusion Middleware 10.1.3.5.1 and 11.1.1.6.0 allows remote attackers to affect integrity via unknown vectors related to Content Server. | 1% Низкий | больше 4 лет назад | ||
GHSA-3rj9-ppgw-ffcc In the PatientService.pl service, the "getPatientIdentifier" function is vulnerable to SQL injection through the "pesel" parameter. | 0% Низкий | около 1 года назад | ||
GHSA-3rj8-qvqp-3335 Adobe Flash Player versions 29.0.0.171 and earlier have a Stack-based buffer overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user. | CVSS3: 9.8 | 25% Средний | больше 4 лет назад | |
GHSA-3rj8-qrpc-rrvr HCL DFXServer is affected by a Missing Access Control vulnerability. This vulnerability states that certain endpoints are accessible without any form of authentication in another browser. This allows any network user to invoke these APIs and interact with the application without verification of their identity or authorization level. | CVSS3: 6.3 | 0% Низкий | около 2 месяцев назад | |
GHSA-3rj8-3jwx-jcjj Amberdms Billing System (ABS) before 1.4.1, when a multi-instance installation is configured, might allow local users to obtain sensitive information by reading the cache in between runs of the include/cron/services_usage.php cron job. | 0% Низкий | больше 4 лет назад |
Уязвимостей на страницу