Количество 364 867
Количество 364 867
GHSA-3r77-fgcp-4m6g
Unauthenticated Local File Inclusion in AirSupply <= 2.0.0 versions.
GHSA-3r77-48qc-c242
Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows attackers to cause a denial of service via unknown vectors, a different vulnerability than CVE-2010-3656.
GHSA-3r76-7gpf-jq4w
Failure to properly synchronize user's permissions in UAA in Cloud Foundry Foundation v40.17.0 https://github.com/cloudfoundry/cf-deployment/releases/tag/v40.17.0 , potentially resulting in users retaining access rights they should not have. This can allow them to perform operations beyond their intended permissions.
GHSA-3r75-xc34-5f44
Crawlee for Python: SSRF via sitemap-derived URLs
GHSA-3r75-wcfw-gxm8
Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.
GHSA-3r75-2r54-55vx
The Netic User Export add-on before 2.0.6 for Atlassian Jira does not perform authorization checks. This might allow an unauthenticated user to export all users from Jira by making an HTTP request to the affected endpoint.
GHSA-3r74-v83p-f4f4
Trufflehog vulnerable to Blind SSRF in some Detectors
GHSA-3r74-6x6g-cp8v
An issue was discovered in CapMon Access Manager 5.4.1.1005. A regular user can obtain local administrator privileges if they run any whitelisted application through the Custom App Launcher.
GHSA-3r74-3v78-7856
SQL injection vulnerability in modules/module.ab-testing.php in the Landing Pages plugin before 1.8.5 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the post parameter in an edit delete-variation action to wp-admin/post.php.
GHSA-3r73-wrgm-c3rm
The XP Server process (xp_server) in Sybase Adaptive Server Enterprise (ASE) XP Server 12.x before 12.5.3 ESD#1 allows attackers to cause a denial of service (process crash) via malformed data sent to the XP Server TCP port.
GHSA-3r73-v5gv-2jmq
A cross-site scripting (XSS) vulnerability in META-INF Kft. Email This Issue (Data Center) before 9.13.0-GA allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the recipient field of an e-mail message.
GHSA-3r73-959g-g38r
SQL injection vulnerability in directory.php in Prozilla Adult Directory allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action. NOTE: the original report indicated that this was the "photo" SourceForge project (aka Maan Bsat Photo Collection), but that was incorrect.
GHSA-3r72-p59x-qr4h
The Iptanus WordPress File Upload plugin before 4.3.3 for WordPress mishandles shortcode attributes.
GHSA-3r72-j9f5-r8j5
In BIG-IP 15.0.0, 14.1.0-14.1.0.6, 14.0.0-14.0.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, 11.5.1-11.6.4, BIG-IQ 7.0.0, 6.0.0-6.1.0,5.2.0-5.4.0, iWorkflow 2.3.0, and Enterprise Manager 3.1.1, the Configuration utility login page may not follow best security practices when handling a malicious request.
GHSA-3r72-fp6h-25pg
Type confusion in JavaScript in Google Chrome prior to 67.0.3396.87 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.
GHSA-3r6x-wmfj-r38f
Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally.
GHSA-3r6x-hxgf-2vcw
A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OCSP response from a remote peer during the TLS handshake. OCSP stapling validation is enabled by default for outgoing TLS connections. Affected scenarios require the remote peer to hold a certificate issued by the cluster's trusted certificate authority, or for the connection to traverse an untrusted network path.
GHSA-3r6x-7c69-fjhx
Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Marketing. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Marketing accessible data as well as unauthorized read access to a subset of Oracle Marketing accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Marketing. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L).
GHSA-3r6x-6cp5-6575
Hydra through 9.7, fixed in commit 9cc84c2, contains a stack buffer overflow in NTLM authentication across SMTP, POP3, IMAP, NNTP, HTTP, HTTP-Proxy, and HTTP-Proxy-Urlenum modules when processing malicious NTLM Type-2 challenges. A malicious server can send a crafted NTLM Type-2 challenge with an excessively long domain string, causing base64-encoded response data to overflow a 500-byte stack buffer by 18 to 330 bytes, enabling remote code execution on systems without stack protection.
GHSA-3r6w-qw5h-chw4
Cross-site request forgery (CSRF) vulnerability in CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.10 and earlier (excluding v2 and v3) allows remote attackers to hijack the authentication of administrators via unspecified vectors.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3r77-fgcp-4m6g Unauthenticated Local File Inclusion in AirSupply <= 2.0.0 versions. | CVSS3: 8.1 | 0% Низкий | 2 месяца назад | |
GHSA-3r77-48qc-c242 Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows attackers to cause a denial of service via unknown vectors, a different vulnerability than CVE-2010-3656. | 5% Низкий | больше 4 лет назад | ||
GHSA-3r76-7gpf-jq4w Failure to properly synchronize user's permissions in UAA in Cloud Foundry Foundation v40.17.0 https://github.com/cloudfoundry/cf-deployment/releases/tag/v40.17.0 , potentially resulting in users retaining access rights they should not have. This can allow them to perform operations beyond their intended permissions. | CVSS3: 3.9 | 0% Низкий | около 2 лет назад | |
GHSA-3r75-xc34-5f44 Crawlee for Python: SSRF via sitemap-derived URLs | 0% Низкий | 3 месяца назад | ||
GHSA-3r75-wcfw-gxm8 Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network. | CVSS3: 9.9 | 1% Низкий | 9 дней назад | |
GHSA-3r75-2r54-55vx The Netic User Export add-on before 2.0.6 for Atlassian Jira does not perform authorization checks. This might allow an unauthenticated user to export all users from Jira by making an HTTP request to the affected endpoint. | CVSS3: 5.3 | 0% Низкий | почти 4 года назад | |
GHSA-3r74-v83p-f4f4 Trufflehog vulnerable to Blind SSRF in some Detectors | CVSS3: 3.4 | 0% Низкий | около 2 лет назад | |
GHSA-3r74-6x6g-cp8v An issue was discovered in CapMon Access Manager 5.4.1.1005. A regular user can obtain local administrator privileges if they run any whitelisted application through the Custom App Launcher. | CVSS3: 7.8 | 0% Низкий | больше 4 лет назад | |
GHSA-3r74-3v78-7856 SQL injection vulnerability in modules/module.ab-testing.php in the Landing Pages plugin before 1.8.5 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the post parameter in an edit delete-variation action to wp-admin/post.php. | 4% Низкий | больше 4 лет назад | ||
GHSA-3r73-wrgm-c3rm The XP Server process (xp_server) in Sybase Adaptive Server Enterprise (ASE) XP Server 12.x before 12.5.3 ESD#1 allows attackers to cause a denial of service (process crash) via malformed data sent to the XP Server TCP port. | 2% Низкий | больше 4 лет назад | ||
GHSA-3r73-v5gv-2jmq A cross-site scripting (XSS) vulnerability in META-INF Kft. Email This Issue (Data Center) before 9.13.0-GA allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the recipient field of an e-mail message. | CVSS3: 5.4 | 0% Низкий | около 1 года назад | |
GHSA-3r73-959g-g38r SQL injection vulnerability in directory.php in Prozilla Adult Directory allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action. NOTE: the original report indicated that this was the "photo" SourceForge project (aka Maan Bsat Photo Collection), but that was incorrect. | 1% Низкий | больше 4 лет назад | ||
GHSA-3r72-p59x-qr4h The Iptanus WordPress File Upload plugin before 4.3.3 for WordPress mishandles shortcode attributes. | CVSS3: 5.4 | 4% Низкий | больше 4 лет назад | |
GHSA-3r72-j9f5-r8j5 In BIG-IP 15.0.0, 14.1.0-14.1.0.6, 14.0.0-14.0.0.5, 13.0.0-13.1.1.5, 12.1.0-12.1.4.1, 11.5.1-11.6.4, BIG-IQ 7.0.0, 6.0.0-6.1.0,5.2.0-5.4.0, iWorkflow 2.3.0, and Enterprise Manager 3.1.1, the Configuration utility login page may not follow best security practices when handling a malicious request. | CVSS3: 5.3 | 1% Низкий | больше 4 лет назад | |
GHSA-3r72-fp6h-25pg Type confusion in JavaScript in Google Chrome prior to 67.0.3396.87 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. | CVSS3: 8.8 | 1% Низкий | больше 4 лет назад | |
GHSA-3r6x-wmfj-r38f Null pointer dereference in Windows DirectX allows an authorized attacker to deny service locally. | CVSS3: 6.5 | 0% Низкий | 9 месяцев назад | |
GHSA-3r6x-hxgf-2vcw A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OCSP response from a remote peer during the TLS handshake. OCSP stapling validation is enabled by default for outgoing TLS connections. Affected scenarios require the remote peer to hold a certificate issued by the cluster's trusted certificate authority, or for the connection to traverse an untrusted network path. | CVSS3: 5.3 | 0% Низкий | около 1 месяца назад | |
GHSA-3r6x-7c69-fjhx Vulnerability in the Oracle Marketing product of Oracle E-Business Suite (component: Audience). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Marketing. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Marketing accessible data as well as unauthorized read access to a subset of Oracle Marketing accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Marketing. CVSS 3.1 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L). | CVSS3: 6.3 | 0% Низкий | около 1 месяца назад | |
GHSA-3r6x-6cp5-6575 Hydra through 9.7, fixed in commit 9cc84c2, contains a stack buffer overflow in NTLM authentication across SMTP, POP3, IMAP, NNTP, HTTP, HTTP-Proxy, and HTTP-Proxy-Urlenum modules when processing malicious NTLM Type-2 challenges. A malicious server can send a crafted NTLM Type-2 challenge with an excessively long domain string, causing base64-encoded response data to overflow a 500-byte stack buffer by 18 to 330 bytes, enabling remote code execution on systems without stack protection. | CVSS3: 8.8 | 2% Низкий | 2 месяца назад | |
GHSA-3r6w-qw5h-chw4 Cross-site request forgery (CSRF) vulnerability in CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.10 and earlier (excluding v2 and v3) allows remote attackers to hijack the authentication of administrators via unspecified vectors. | CVSS3: 8.8 | 1% Низкий | больше 4 лет назад |
Уязвимостей на страницу