Количество 356 366
Количество 356 366
GHSA-322r-7497-6cm7
On BIG-IP APM versions 15.1.x before 15.1.3, 14.1.x before 14.1.4.1, 13.1.x before 13.1.4, and all versions of 16.0.x, 12.1.x, and 11.6.x, an attacker may be able to bypass APM's internal restrictions and retrieve static content that is hosted within APM by sending specifically crafted requests to an APM Virtual Server. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
GHSA-322r-6qh8-9465
Out-of-bounds read in some Intel(R) oneVPL GPU software before version 22.6.5 may allow an authenticated user to potentially enable information disclosure via local access.
GHSA-322q-55f4-fqgr
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in nK Ghost Kit allows PHP Local File Inclusion. This issue affects Ghost Kit: from n/a through 3.4.1.
GHSA-322p-rrj6-j44g
bettercap Has an Integer Coercion Error in the ippReadChunkedBody Function
GHSA-322p-76c5-wqq3
WinRadius Server 2009 allows remote attackers to cause a denial of service (crash) via a long password in an Access-Request packet.
GHSA-322m-vpmh-c9m9
Mail Management Agent (MAILMA) (aka Mail Management Server) in Rockliffe MailSite 7.0.3.1 and earlier allows remote attackers to attempt authentication with an unlimited number of user account names and passwords without denying connections, limiting the rate of connections, or locking out an account.
GHSA-322m-p87g-xcpj
A vulnerability was determined in code-projects Intern Membership Management System 1.0. Affected is an unknown function of the file /intern/admin/check_admin.php. Executing a manipulation of the argument Username can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
GHSA-322m-p39j-r5m2
npm-script-demo is malware
GHSA-322j-cfcv-3q95
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Garrett Grimm Simple Popup allows Stored XSS.This issue affects Simple Popup: from n/a through 4.4.
GHSA-322h-m7q9-7x4q
Skype for Business and Lync Remote Code Execution Vulnerability
GHSA-322h-cqgv-7v8g
The navigator.plugins implementation in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 does not properly handle destruction of the DOM plugin array, which might allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via crafted access to the navigator object, related to a "dangling pointer vulnerability."
GHSA-322h-cmf7-6w72
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
GHSA-322g-vx47-pfp6
Unspecified vulnerability in the strfreectty function in the Special File System (SPECFS) in Sun Solaris 8 through 10 allows local users to cause a denial of service (system panic), related to passing a NULL pointer to the pgsignal function.
GHSA-322g-pxmj-97cc
OpenSSL 0.9.8f and 0.9.8g allows remote attackers to cause a denial of service (crash) via a TLS handshake that omits the Server Key Exchange message and uses "particular cipher suites," which triggers a NULL pointer dereference.
GHSA-322g-5x7j-7fgm
Microsoft Edge allows remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Edge Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0009, CVE-2017-0017, CVE-2017-0065, and CVE-2017-0068.
GHSA-322g-44wj-2m39
An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can cause a denial of service by sending a cleartext encryption pause request.
GHSA-322g-3p44-gp9p
Gila CMS 1.11.8 allows /admin/sql?query= SQL Injection.
GHSA-322f-wqw7-87q6
Multiple PHP remote file inclusion vulnerabilities in HIOX Browser Statistics (HBS) 2.0 allow remote attackers to execute arbitrary PHP code via a URL in the hm parameter to (1) hioxupdate.php and (2) hioxstats.php.
GHSA-322f-7555-6qf5
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.4. An app may be able to access a user's Photos Library.
GHSA-322c-5q8f-8999
The Intel G41 driver 6.14.10.5355 on Windows XP SP3 allows remote attackers to cause a denial of service (system crash) via a crafted web page that is visited with Google Chrome or Mozilla Firefox, as demonstrated by the lots-of-polys-example.html test page in the Khronos WebGL SDK.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-322r-7497-6cm7 On BIG-IP APM versions 15.1.x before 15.1.3, 14.1.x before 14.1.4.1, 13.1.x before 13.1.4, and all versions of 16.0.x, 12.1.x, and 11.6.x, an attacker may be able to bypass APM's internal restrictions and retrieve static content that is hosted within APM by sending specifically crafted requests to an APM Virtual Server. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 1% Низкий | около 4 лет назад | ||
GHSA-322r-6qh8-9465 Out-of-bounds read in some Intel(R) oneVPL GPU software before version 22.6.5 may allow an authenticated user to potentially enable information disclosure via local access. | CVSS3: 4.4 | 0% Низкий | около 3 лет назад | |
GHSA-322q-55f4-fqgr Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in nK Ghost Kit allows PHP Local File Inclusion. This issue affects Ghost Kit: from n/a through 3.4.1. | CVSS3: 8.1 | 0% Низкий | 12 месяцев назад | |
GHSA-322p-rrj6-j44g bettercap Has an Integer Coercion Error in the ippReadChunkedBody Function | CVSS3: 3.7 | 1% Низкий | 3 месяца назад | |
GHSA-322p-76c5-wqq3 WinRadius Server 2009 allows remote attackers to cause a denial of service (crash) via a long password in an Access-Request packet. | 8% Низкий | около 4 лет назад | ||
GHSA-322m-vpmh-c9m9 Mail Management Agent (MAILMA) (aka Mail Management Server) in Rockliffe MailSite 7.0.3.1 and earlier allows remote attackers to attempt authentication with an unlimited number of user account names and passwords without denying connections, limiting the rate of connections, or locking out an account. | 1% Низкий | больше 4 лет назад | ||
GHSA-322m-p87g-xcpj A vulnerability was determined in code-projects Intern Membership Management System 1.0. Affected is an unknown function of the file /intern/admin/check_admin.php. Executing a manipulation of the argument Username can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. | CVSS3: 7.3 | 0% Низкий | 7 месяцев назад | |
GHSA-322m-p39j-r5m2 npm-script-demo is malware | CVSS3: 9.8 | 1% Низкий | почти 6 лет назад | |
GHSA-322j-cfcv-3q95 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Garrett Grimm Simple Popup allows Stored XSS.This issue affects Simple Popup: from n/a through 4.4. | CVSS3: 5.9 | 0% Низкий | около 2 лет назад | |
GHSA-322h-m7q9-7x4q Skype for Business and Lync Remote Code Execution Vulnerability | CVSS3: 7.2 | 2% Низкий | около 4 лет назад | |
GHSA-322h-cqgv-7v8g The navigator.plugins implementation in Mozilla Firefox before 3.5.12 and 3.6.x before 3.6.9, Thunderbird before 3.0.7 and 3.1.x before 3.1.3, and SeaMonkey before 2.0.7 does not properly handle destruction of the DOM plugin array, which might allow remote attackers to cause a denial of service (application crash) or execute arbitrary code via crafted access to the navigator object, related to a "dangling pointer vulnerability." | 5% Низкий | около 4 лет назад | ||
GHSA-322h-cmf7-6w72 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | около 1 года назад | |||
GHSA-322g-vx47-pfp6 Unspecified vulnerability in the strfreectty function in the Special File System (SPECFS) in Sun Solaris 8 through 10 allows local users to cause a denial of service (system panic), related to passing a NULL pointer to the pgsignal function. | 0% Низкий | больше 4 лет назад | ||
GHSA-322g-pxmj-97cc OpenSSL 0.9.8f and 0.9.8g allows remote attackers to cause a denial of service (crash) via a TLS handshake that omits the Server Key Exchange message and uses "particular cipher suites," which triggers a NULL pointer dereference. | 5% Низкий | больше 4 лет назад | ||
GHSA-322g-5x7j-7fgm Microsoft Edge allows remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Edge Information Disclosure Vulnerability." This vulnerability is different from those described in CVE-2017-0009, CVE-2017-0017, CVE-2017-0065, and CVE-2017-0068. | CVSS3: 4.3 | 42% Средний | около 4 лет назад | |
GHSA-322g-44wj-2m39 An issue was discovered on Microchip RN4870 1.43 devices. An attacker within BLE radio range can cause a denial of service by sending a cleartext encryption pause request. | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад | |
GHSA-322g-3p44-gp9p Gila CMS 1.11.8 allows /admin/sql?query= SQL Injection. | CVSS3: 7.2 | 27% Средний | около 4 лет назад | |
GHSA-322f-wqw7-87q6 Multiple PHP remote file inclusion vulnerabilities in HIOX Browser Statistics (HBS) 2.0 allow remote attackers to execute arbitrary PHP code via a URL in the hm parameter to (1) hioxupdate.php and (2) hioxstats.php. | 3% Низкий | больше 4 лет назад | ||
GHSA-322f-7555-6qf5 A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.4. An app may be able to access a user's Photos Library. | CVSS3: 7.5 | 0% Низкий | больше 2 лет назад | |
GHSA-322c-5q8f-8999 The Intel G41 driver 6.14.10.5355 on Windows XP SP3 allows remote attackers to cause a denial of service (system crash) via a crafted web page that is visited with Google Chrome or Mozilla Firefox, as demonstrated by the lots-of-polys-example.html test page in the Khronos WebGL SDK. | 2% Низкий | около 4 лет назад |
Уязвимостей на страницу