Количество 364 463
Количество 364 463
GHSA-3q2f-qcg5-6425
A vulnerability in the TLS protocol implementation of legacy Cisco ASA 5500 Series (ASA 5505, 5510, 5520, 5540, and 5550) devices could allow an unauthenticated, remote attacker to access sensitive information, aka a Return of Bleichenbacher's Oracle Threat (ROBOT) attack. An attacker could iteratively query a server running a vulnerable TLS stack implementation to perform cryptanalytic operations that may allow decryption of previously captured TLS sessions. Cisco Bug IDs: CSCvg97652.
GHSA-3q2f-pq2q-f9qf
TP-Link TL-IPC42C V4.0_20211227_1.0.16 is vulnerable to command injection due to the lack of malicious code verification on both the frontend and backend.
GHSA-3q2f-m5vm-7r8q
An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions before 7.20A.202.307. A Cross-Site Request Forgery (CSRF) vulnerability in the management web interface allows remote attackers to execute malicious and unauthorized actions, because CSRFProtection=1 is not a default and is not documented.
GHSA-3q2f-h5rm-7qv7
An ACL bypass flaw was found in pacemaker before 1.1.24-rc1 and 2.0.5-rc2. An attacker having a local account on the cluster and in the haclient group could use IPC communication with various daemons directly to perform certain tasks that they would be prevented by ACLs from doing if they went through the configuration.
GHSA-3q2c-pvp5-3cqp
Verifying a certificate chain which contains a certificate with an unknown public key algorithm will cause Certificate.Verify to panic. This affects all crypto/tls clients, and servers that set Config.ClientAuth to VerifyClientCertIfGiven or RequireAndVerifyClientCert. The default behavior is for TLS servers to not verify client certificates.
GHSA-3q2c-9v2r-vjgj
Multiple cross-site scripting (XSS) vulnerabilities in WebTester 5.0.20060927 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to POST parameters to multiple files.
GHSA-3q29-89cr-qgvj
GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc.
GHSA-3q29-6c6h-84hh
The Guest account feature in Mattermost version 6.7.0 and earlier fails to properly restrict the permissions, which allows a guest user to fetch a list of all public channels in the team, in spite of not being part of those channels.
GHSA-3q28-xfw3-2q35
phpMyAdmin XSS Vulnerability
GHSA-3q28-wqh2-j2f3
An unlimited recursion in DxeCore in EDK II.
GHSA-3q28-qjrv-qr39
Tinyauth vulnerable to TOTP/2FA bypass via OIDC authorize endpoint
GHSA-3q28-p7pm-8p98
The firmware on Cisco Unified IP phones 8961, 9951, and 9971 uses weak permissions for memory block devices, which allows local users to gain privileges by mounting a device with a setuid file in its filesystem, aka Bug ID CSCui04382.
GHSA-3q28-p6jr-9gpc
This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted image may lead to arbitrary code execution.
GHSA-3q28-mmq2-xhcr
Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6220 before 1.1.0.100 and R6230 before 1.1.0.100.
GHSA-3q28-9x2c-2fcm
In aee driver, there is a possible reference count mistake due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06209201; Issue ID: ALPS06209201.
GHSA-3q28-7xrx-5524
An issue was discovered in Adobe Digital Editions 4.5.6 and earlier versions. An exploitable memory corruption vulnerability exists, which could lead to disclosure of memory addresses.
GHSA-3q28-538h-7pqq
Application is vulnerable to Cross Site Scripting (XSS) an authenticated attacker with users’ permissions can modify a variable with a payload.
GHSA-3q27-8g46-2vwm
Within Zabbix, users have the ability to directly modify memory pointers in the JavaScript engine.
GHSA-3q27-7qjq-p9c5
Grafana public dashboards disclose all direct mode datasources
GHSA-3q27-5m93-xfm4
Avi Load Balancer contains an unauthenticated blind SQL Injection vulnerability which was privately reported to VMware. Patches are available to remediate this vulnerability in affected VMware products. A malicious user with network access may be able to use specially crafted SQL queries to gain database access.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3q2f-qcg5-6425 A vulnerability in the TLS protocol implementation of legacy Cisco ASA 5500 Series (ASA 5505, 5510, 5520, 5540, and 5550) devices could allow an unauthenticated, remote attacker to access sensitive information, aka a Return of Bleichenbacher's Oracle Threat (ROBOT) attack. An attacker could iteratively query a server running a vulnerable TLS stack implementation to perform cryptanalytic operations that may allow decryption of previously captured TLS sessions. Cisco Bug IDs: CSCvg97652. | CVSS3: 5.9 | 13% Средний | больше 4 лет назад | |
GHSA-3q2f-pq2q-f9qf TP-Link TL-IPC42C V4.0_20211227_1.0.16 is vulnerable to command injection due to the lack of malicious code verification on both the frontend and backend. | CVSS3: 8 | 10% Средний | почти 2 года назад | |
GHSA-3q2f-m5vm-7r8q An issue was discovered on AudioCodes Mediant 500L-MSBR, 500-MBSR, M800B-MSBR and 800C-MSBR devices with firmware versions before 7.20A.202.307. A Cross-Site Request Forgery (CSRF) vulnerability in the management web interface allows remote attackers to execute malicious and unauthorized actions, because CSRFProtection=1 is not a default and is not documented. | CVSS3: 8.8 | 1% Низкий | больше 4 лет назад | |
GHSA-3q2f-h5rm-7qv7 An ACL bypass flaw was found in pacemaker before 1.1.24-rc1 and 2.0.5-rc2. An attacker having a local account on the cluster and in the haclient group could use IPC communication with various daemons directly to perform certain tasks that they would be prevented by ACLs from doing if they went through the configuration. | CVSS3: 7.2 | 2% Низкий | больше 4 лет назад | |
GHSA-3q2c-pvp5-3cqp Verifying a certificate chain which contains a certificate with an unknown public key algorithm will cause Certificate.Verify to panic. This affects all crypto/tls clients, and servers that set Config.ClientAuth to VerifyClientCertIfGiven or RequireAndVerifyClientCert. The default behavior is for TLS servers to not verify client certificates. | CVSS3: 5.9 | 1% Низкий | больше 2 лет назад | |
GHSA-3q2c-9v2r-vjgj Multiple cross-site scripting (XSS) vulnerabilities in WebTester 5.0.20060927 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to POST parameters to multiple files. | 2% Низкий | больше 4 лет назад | ||
GHSA-3q29-89cr-qgvj GNU Libc current is affected by: Mitigation bypass. The impact is: Attacker may bypass ASLR using cache of thread stack and heap. The component is: glibc. | CVSS3: 5.3 | 3% Низкий | больше 4 лет назад | |
GHSA-3q29-6c6h-84hh The Guest account feature in Mattermost version 6.7.0 and earlier fails to properly restrict the permissions, which allows a guest user to fetch a list of all public channels in the team, in spite of not being part of those channels. | CVSS3: 4.3 | 1% Низкий | около 4 лет назад | |
GHSA-3q28-xfw3-2q35 phpMyAdmin XSS Vulnerability | CVSS3: 6.1 | 2% Низкий | больше 4 лет назад | |
GHSA-3q28-wqh2-j2f3 An unlimited recursion in DxeCore in EDK II. | 0% Низкий | больше 4 лет назад | ||
GHSA-3q28-qjrv-qr39 Tinyauth vulnerable to TOTP/2FA bypass via OIDC authorize endpoint | CVSS3: 8.5 | 0% Низкий | 6 месяцев назад | |
GHSA-3q28-p7pm-8p98 The firmware on Cisco Unified IP phones 8961, 9951, and 9971 uses weak permissions for memory block devices, which allows local users to gain privileges by mounting a device with a setuid file in its filesystem, aka Bug ID CSCui04382. | 0% Низкий | больше 4 лет назад | ||
GHSA-3q28-p6jr-9gpc This issue was addressed with improved checks. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. Processing a maliciously crafted image may lead to arbitrary code execution. | 1% Низкий | больше 4 лет назад | ||
GHSA-3q28-mmq2-xhcr Certain NETGEAR devices are affected by command injection by an authenticated user. This affects R6220 before 1.1.0.100 and R6230 before 1.1.0.100. | 1% Низкий | больше 4 лет назад | ||
GHSA-3q28-9x2c-2fcm In aee driver, there is a possible reference count mistake due to incorrect error handling. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06209201; Issue ID: ALPS06209201. | CVSS3: 7.8 | 0% Низкий | больше 4 лет назад | |
GHSA-3q28-7xrx-5524 An issue was discovered in Adobe Digital Editions 4.5.6 and earlier versions. An exploitable memory corruption vulnerability exists, which could lead to disclosure of memory addresses. | CVSS3: 5.3 | 3% Низкий | больше 4 лет назад | |
GHSA-3q28-538h-7pqq Application is vulnerable to Cross Site Scripting (XSS) an authenticated attacker with users’ permissions can modify a variable with a payload. | CVSS3: 4.8 | 1% Низкий | почти 2 года назад | |
GHSA-3q27-8g46-2vwm Within Zabbix, users have the ability to directly modify memory pointers in the JavaScript engine. | CVSS3: 9.1 | 1% Низкий | около 2 лет назад | |
GHSA-3q27-7qjq-p9c5 Grafana public dashboards disclose all direct mode datasources | CVSS3: 6.5 | 0% Низкий | 5 месяцев назад | |
GHSA-3q27-5m93-xfm4 Avi Load Balancer contains an unauthenticated blind SQL Injection vulnerability which was privately reported to VMware. Patches are available to remediate this vulnerability in affected VMware products. A malicious user with network access may be able to use specially crafted SQL queries to gain database access. | CVSS3: 8.6 | 1% Низкий | больше 1 года назад |
Уязвимостей на страницу