Количество 358 043
Количество 358 043
GHSA-35rm-gh88-rf95
Cross-site scripting vulnerability in Splunk Enterprise 6.3.x prior to 6.3.5 and Splunk Light 6.3.x prior to 6.3.5 allows attacker with administrator rights to inject arbitrary web script or HTML via unspecified vectors.
GHSA-35rm-7j9c-2f7m
async-tar PAX extension-header desync enables tar entry/content smuggling
GHSA-35rm-77cm-584v
An issue was discovered on Samsung mobile devices with Q(10.0) (exynos9830 chipsets) software. RKP allows arbitrary code execution. The Samsung ID is SVE-2020-17435 (August 2020).
GHSA-35rj-j8qg-5vgh
daemon.c in cman (redhat-cluster-suite) before 20070622 does not clear a buffer for reading requests, which might allow local users to obtain sensitive information from previous requests.
GHSA-35rj-4m65-59q8
In getTrampolineIntent of SettingsActivity.java, there is a possible launch of arbitrary activity due to an Intent mismatch in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12L Android-13Android ID: A-246300272
GHSA-35rh-9jh6-cw7p
The barracudavpn component of the Barracuda VPN Client prior to version 5.0.2.7 for Linux, macOS, and OpenBSD runs as a privileged process and can allow an unprivileged local attacker to load a malicious library, resulting in arbitrary code executing as root.
GHSA-35rh-6mjx-86f8
VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple out-of-bounds read vulnerabilities in JPEG2000 parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may allow a View desktop to execute code or perform a Denial of Service on the Windows OS that runs the Horizon View Client. Exploitation is only possible if virtual printing has been enabled. This feature is not enabled by default on Workstation but it is enabled by default on Horizon View.
GHSA-35rg-pjrx-fc55
Directory traversal vulnerability in geohttpserver in Geovision Digital Video Surveillance System 8.2 allows remote attackers to read arbitrary files via a .. (dot dot) in a GET request.
GHSA-35rg-466w-77h3
Cross-site scripting in Products.CMFCore, Products.PluggableAuthService, Plone
GHSA-35rf-xg9j-vr62
Microsoft Office 2013 Gold, SP1, RT, and RT SP1 allows remote attackers to obtain sensitive token information via a web site that sends a crafted response during opening of an Office document, aka "Token Reuse Vulnerability."
GHSA-35rf-v5xv-3376
Snort 1.6, when running in straight ASCII packet logging mode or IDS mode with straight decoded ASCII packet logging selected, allows remote attackers to cause a denial of service (crash) by sending non-IP protocols that Snort does not know about, as demonstrated by an nmap protocol scan.
GHSA-35rf-v2jv-gfg7
Privilege escalation to cluster admin on multi-tenant environments
GHSA-35rf-7vhx-9phr
Redis v7.0 was discovered to contain a memory leak via the component streamGetEdgeID.
GHSA-35rf-2xxr-prvf
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Bowo System Dashboard allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects System Dashboard: from n/a through 2.8.18.
GHSA-35rc-qr7q-j9jm
Use after free issue due to using of invalidated iterator to delete an object in sensors HAL in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8096AU, MSM8909W, Nicobar, QCS605, SA6155P, SDA845, SDM429W, SDM670, SDM710, SDM845, SM6150, SM8150, SM8250, SXR1130, SXR2130
GHSA-35rc-fmpw-cvfv
An unauthenticated attacker can check the existence of usernames in the system by querying an API.
GHSA-35rc-2vcv-r6q5
A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location.
GHSA-35r9-gfqf-r6cw
Missing permission check in Jenkins vRealize Orchestrator Plugin
GHSA-35r8-c3gc-mfvr
Leave Management System Project v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'setearnleave' parameter of the admin/setleaves.php resource does not validate the characters received and they are sent unfiltered to the database.
GHSA-35r7-w24m-px2g
A configuration problem in the Ad Server Sample directory (AdSamples) in Microsoft Site Server 3.0 allows an attacker to obtain the SITE.CSC file, which exposes sensitive SQL database information.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-35rm-gh88-rf95 Cross-site scripting vulnerability in Splunk Enterprise 6.3.x prior to 6.3.5 and Splunk Light 6.3.x prior to 6.3.5 allows attacker with administrator rights to inject arbitrary web script or HTML via unspecified vectors. | CVSS3: 4.8 | 1% Низкий | около 4 лет назад | |
GHSA-35rm-7j9c-2f7m async-tar PAX extension-header desync enables tar entry/content smuggling | около 1 месяца назад | |||
GHSA-35rm-77cm-584v An issue was discovered on Samsung mobile devices with Q(10.0) (exynos9830 chipsets) software. RKP allows arbitrary code execution. The Samsung ID is SVE-2020-17435 (August 2020). | 1% Низкий | около 4 лет назад | ||
GHSA-35rj-j8qg-5vgh daemon.c in cman (redhat-cluster-suite) before 20070622 does not clear a buffer for reading requests, which might allow local users to obtain sensitive information from previous requests. | 1% Низкий | больше 4 лет назад | ||
GHSA-35rj-4m65-59q8 In getTrampolineIntent of SettingsActivity.java, there is a possible launch of arbitrary activity due to an Intent mismatch in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-12L Android-13Android ID: A-246300272 | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-35rh-9jh6-cw7p The barracudavpn component of the Barracuda VPN Client prior to version 5.0.2.7 for Linux, macOS, and OpenBSD runs as a privileged process and can allow an unprivileged local attacker to load a malicious library, resulting in arbitrary code executing as root. | CVSS3: 7.8 | 1% Низкий | больше 4 лет назад | |
GHSA-35rh-6mjx-86f8 VMware Workstation (12.x prior to 12.5.3) and Horizon View Client (4.x prior to 4.4.0) contain multiple out-of-bounds read vulnerabilities in JPEG2000 parser in the TPView.dll. On Workstation, this may allow a guest to execute code or perform a Denial of Service on the Windows OS that runs Workstation. In the case of a Horizon View Client, this may allow a View desktop to execute code or perform a Denial of Service on the Windows OS that runs the Horizon View Client. Exploitation is only possible if virtual printing has been enabled. This feature is not enabled by default on Workstation but it is enabled by default on Horizon View. | CVSS3: 7.8 | 0% Низкий | около 4 лет назад | |
GHSA-35rg-pjrx-fc55 Directory traversal vulnerability in geohttpserver in Geovision Digital Video Surveillance System 8.2 allows remote attackers to read arbitrary files via a .. (dot dot) in a GET request. | 4% Низкий | больше 4 лет назад | ||
GHSA-35rg-466w-77h3 Cross-site scripting in Products.CMFCore, Products.PluggableAuthService, Plone | CVSS3: 6.1 | 1% Низкий | около 5 лет назад | |
GHSA-35rf-xg9j-vr62 Microsoft Office 2013 Gold, SP1, RT, and RT SP1 allows remote attackers to obtain sensitive token information via a web site that sends a crafted response during opening of an Office document, aka "Token Reuse Vulnerability." | 10% Средний | больше 4 лет назад | ||
GHSA-35rf-v5xv-3376 Snort 1.6, when running in straight ASCII packet logging mode or IDS mode with straight decoded ASCII packet logging selected, allows remote attackers to cause a denial of service (crash) by sending non-IP protocols that Snort does not know about, as demonstrated by an nmap protocol scan. | 1% Низкий | больше 4 лет назад | ||
GHSA-35rf-v2jv-gfg7 Privilege escalation to cluster admin on multi-tenant environments | CVSS3: 8.8 | 2% Низкий | больше 4 лет назад | |
GHSA-35rf-7vhx-9phr Redis v7.0 was discovered to contain a memory leak via the component streamGetEdgeID. | CVSS3: 7.5 | 3% Низкий | около 4 лет назад | |
GHSA-35rf-2xxr-prvf Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Bowo System Dashboard allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects System Dashboard: from n/a through 2.8.18. | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
GHSA-35rc-qr7q-j9jm Use after free issue due to using of invalidated iterator to delete an object in sensors HAL in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in APQ8096AU, MSM8909W, Nicobar, QCS605, SA6155P, SDA845, SDM429W, SDM670, SDM710, SDM845, SM6150, SM8150, SM8250, SXR1130, SXR2130 | 0% Низкий | около 4 лет назад | ||
GHSA-35rc-fmpw-cvfv An unauthenticated attacker can check the existence of usernames in the system by querying an API. | CVSS3: 5.3 | 0% Низкий | больше 1 года назад | |
GHSA-35rc-2vcv-r6q5 A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location. | CVSS3: 10 | 74% Высокий | около 1 месяца назад | |
GHSA-35r9-gfqf-r6cw Missing permission check in Jenkins vRealize Orchestrator Plugin | CVSS3: 4.3 | 1% Низкий | около 4 лет назад | |
GHSA-35r8-c3gc-mfvr Leave Management System Project v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'setearnleave' parameter of the admin/setleaves.php resource does not validate the characters received and they are sent unfiltered to the database. | CVSS3: 8.8 | 1% Низкий | больше 2 лет назад | |
GHSA-35r7-w24m-px2g A configuration problem in the Ad Server Sample directory (AdSamples) in Microsoft Site Server 3.0 allows an attacker to obtain the SITE.CSC file, which exposes sensitive SQL database information. | 12% Средний | больше 4 лет назад |
Уязвимостей на страницу