Количество 324 922
Количество 324 922
GHSA-xqmq-3744-539p
Lack of stack protection exploit mechanisms in ASP Secure OS Trusted Execution Environment (TEE) may allow a privileged attacker with access to AMD signing keys to c006Frrupt the return address, causing a stack-based buffer overrun, potentially leading to a denial of service.
GHSA-xqmp-fxgv-xvq5
libp2p-gossipsub: Remote crash via unchecked Instant overflow in heartbeat backoff expiry handling
GHSA-xqmm-x45g-6wf4
Server-Side Request Forgery (SSRF) in Microsoft Power Apps allows an unauthorized attacker to disclose information over a network
GHSA-xqmh-wj7x-9rxf
Unknown vulnerability in the login program on AIX before 4.0 could allow remote users to specify 100 or more environment variables when logging on, which exceeds the length of a certain string, possibly triggering a buffer overflow.
GHSA-xqmh-c3cf-jrc8
IBM API Connect 5.0.0.0 through 5.0.8.6 developer portal could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 163681.
GHSA-xqmg-px4m-r5qm
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can pipe commands directly to the underlying operating system as user input is not sanitized in networkdiags.php.
GHSA-xqmg-px28-29cq
Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally.
GHSA-xqmg-8q55-7xxx
The libsecurity library in HP-UX 11.04 (VVOS) allows attackers to cause a denial of service.
GHSA-xqmf-wf6x-2cx6
Improper access control in the Intel(R) NUC HDMI Firmware Update Tool for NUC7i3DN, NUC7i5DN and NUC7i7DN before version 1.78.2.0.7 may allow an authenticated user to potentially enable escalation of privilege via local access.
GHSA-xqmc-wh95-fg2q
Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=result&searchfor=byfunction.
GHSA-xqmc-vc6c-2wmv
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 200966.
GHSA-xqmc-v3x5-h7p2
SAP Manufacturing Execution - versions 15.1, 15.2, 15.3, allows an attacker to exploit insufficient validation of a file path request parameter. The intended file path can be manipulated to allow arbitrary traversal of directories on the remote server. The file content within each directory can be read which may lead to information disclosure.
GHSA-xqmc-g86x-qfxp
Some Honor products are affected by out of bounds read vulnerability, successful exploitation could cause information leak.
GHSA-xqm9-hpfh-qm5m
Cross-site scripting (XSS) vulnerability in display.php in HyperVM 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via an encoded frm_action parameter. NOTE: the vendor disputes this issue, but it is not certain whether the dispute is about the severity of the issue, or its existence.
GHSA-xqm9-g4jx-xvgw
Metamail before 2.7-7.2 allows remote attackers to overwrite arbitrary files via an e-mail message containing a uuencoded attachment that specifies the full pathname for the file to be modified, which is processed by uuencode in Metamail scripts such as sun-audio-file.
GHSA-xqm9-6qmm-xrqh
Multiple authenticated stored cross-site scripting (XSS) vulnerabilities in the Permissions module of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Group, Category or Description parameters.
GHSA-xqm9-4fqc-qh7w
On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x, a stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to execute JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
GHSA-xqm9-2mv3-cvx4
A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application lacks sufficient authorization checks. This could allow an attacker to access confidential information, perform administrative functions, or lead to a denial-of-service condition.
GHSA-xqm8-jv67-vcvj
Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'demail' parameter of the update.php resource does not validate the characters received and they are sent unfiltered to the database.
GHSA-xqm8-c3rv-5vpf
FFmpeg n6.1.1 has a vulnerability in the DXA demuxer of the libavformat library allowing for an integer overflow, potentially resulting in a denial-of-service (DoS) condition or other undefined behavior.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xqmq-3744-539p Lack of stack protection exploit mechanisms in ASP Secure OS Trusted Execution Environment (TEE) may allow a privileged attacker with access to AMD signing keys to c006Frrupt the return address, causing a stack-based buffer overrun, potentially leading to a denial of service. | CVSS3: 5.2 | 0% Низкий | больше 1 года назад | |
GHSA-xqmp-fxgv-xvq5 libp2p-gossipsub: Remote crash via unchecked Instant overflow in heartbeat backoff expiry handling | CVSS3: 5.9 | 0% Низкий | 9 дней назад | |
GHSA-xqmm-x45g-6wf4 Server-Side Request Forgery (SSRF) in Microsoft Power Apps allows an unauthorized attacker to disclose information over a network | CVSS3: 9.1 | 3% Низкий | 11 месяцев назад | |
GHSA-xqmh-wj7x-9rxf Unknown vulnerability in the login program on AIX before 4.0 could allow remote users to specify 100 or more environment variables when logging on, which exceeds the length of a certain string, possibly triggering a buffer overflow. | 1% Низкий | почти 4 года назад | ||
GHSA-xqmh-c3cf-jrc8 IBM API Connect 5.0.0.0 through 5.0.8.6 developer portal could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 163681. | CVSS3: 7.5 | 0% Низкий | почти 4 года назад | |
GHSA-xqmg-px4m-r5qm In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can pipe commands directly to the underlying operating system as user input is not sanitized in networkdiags.php. | 1% Низкий | почти 4 года назад | ||
GHSA-xqmg-px28-29cq Integer overflow or wraparound in Virtual Hard Disk (VHDX) allows an unauthorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 9 месяцев назад | |
GHSA-xqmg-8q55-7xxx The libsecurity library in HP-UX 11.04 (VVOS) allows attackers to cause a denial of service. | 0% Низкий | почти 4 года назад | ||
GHSA-xqmf-wf6x-2cx6 Improper access control in the Intel(R) NUC HDMI Firmware Update Tool for NUC7i3DN, NUC7i5DN and NUC7i7DN before version 1.78.2.0.7 may allow an authenticated user to potentially enable escalation of privilege via local access. | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-xqmc-wh95-fg2q Complete Online Job Search System v1.0 is vulnerable to SQL Injection via /eris/index.php?q=result&searchfor=byfunction. | CVSS3: 7.2 | 0% Низкий | почти 4 года назад | |
GHSA-xqmc-vc6c-2wmv IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 200966. | 0% Низкий | почти 4 года назад | ||
GHSA-xqmc-v3x5-h7p2 SAP Manufacturing Execution - versions 15.1, 15.2, 15.3, allows an attacker to exploit insufficient validation of a file path request parameter. The intended file path can be manipulated to allow arbitrary traversal of directories on the remote server. The file content within each directory can be read which may lead to information disclosure. | CVSS3: 7.5 | 4% Низкий | больше 3 лет назад | |
GHSA-xqmc-g86x-qfxp Some Honor products are affected by out of bounds read vulnerability, successful exploitation could cause information leak. | CVSS3: 6 | 0% Низкий | больше 2 лет назад | |
GHSA-xqm9-hpfh-qm5m Cross-site scripting (XSS) vulnerability in display.php in HyperVM 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via an encoded frm_action parameter. NOTE: the vendor disputes this issue, but it is not certain whether the dispute is about the severity of the issue, or its existence. | 2% Низкий | почти 4 года назад | ||
GHSA-xqm9-g4jx-xvgw Metamail before 2.7-7.2 allows remote attackers to overwrite arbitrary files via an e-mail message containing a uuencoded attachment that specifies the full pathname for the file to be modified, which is processed by uuencode in Metamail scripts such as sun-audio-file. | 0% Низкий | почти 4 года назад | ||
GHSA-xqm9-6qmm-xrqh Multiple authenticated stored cross-site scripting (XSS) vulnerabilities in the Permissions module of Feehi CMS v2.1.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Group, Category or Description parameters. | 1 день назад | |||
GHSA-xqm9-4fqc-qh7w On version 16.0.x before 16.0.1.2, 15.1.x before 15.1.3.1, 14.1.x before 14.1.4.2, 13.1.x before 13.1.4.1, and all versions of 12.1.x, a stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IP Configuration utility that allows an attacker to execute JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | 0% Низкий | почти 4 года назад | ||
GHSA-xqm9-2mv3-cvx4 A vulnerability has been identified in QMS Automotive (All versions < V12.39). The QMS.Mobile module of the affected application lacks sufficient authorization checks. This could allow an attacker to access confidential information, perform administrative functions, or lead to a denial-of-service condition. | CVSS3: 8.8 | 0% Низкий | больше 2 лет назад | |
GHSA-xqm8-jv67-vcvj Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'demail' parameter of the update.php resource does not validate the characters received and they are sent unfiltered to the database. | CVSS3: 9.8 | 0% Низкий | больше 2 лет назад | |
GHSA-xqm8-c3rv-5vpf FFmpeg n6.1.1 has a vulnerability in the DXA demuxer of the libavformat library allowing for an integer overflow, potentially resulting in a denial-of-service (DoS) condition or other undefined behavior. | CVSS3: 6.2 | 0% Низкий | больше 1 года назад |
Уязвимостей на страницу