Количество 375 268
Количество 375 268
GHSA-3rjq-9j9w-pxr3
OSIsoft PI Vision, All versions of PI Vision prior to 2019. The affected product is vulnerable to a cross-site request forgery that may be introduced on the PI Vision administration site.
GHSA-3rjq-96vg-4j89
Missing Authorization vulnerability in G5Theme G5Plus April g5plus-april allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects G5Plus April: from n/a through <= 6.8.
GHSA-3rjp-hfjx-9689
In GraphicsMagick 1.4 snapshot-20190403 Q8, there is a use-after-free in ThrowException and ThrowLoggedException of magick/error.c.
GHSA-3rjp-6929-2mrw
HTTP server in Cisco Wireless Control System (WCS) for Linux and Windows before 3.2(51) stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain usernames and directory paths via a direct URL request.
GHSA-3rjm-xww9-gmm6
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to bypass intended access restrictions via unspecified vectors.
GHSA-3rjm-q6hg-6jw8
RealOne Player 2.0 Build 6.0.11.872 allows remote attackers to cause a denial of service (array out-of-bounds access and application crash) via a crafted .aiff file.
GHSA-3rjm-jwr3-fh58
Buffer overflow in the Napster client beta 5 allows remote attackers to cause a denial of service via a long message.
GHSA-3rjj-rpg2-4f2q
Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Branch Intelligent Management System Software Module (aka BIMS) allows remote attackers to obtain sensitive information via unknown vectors, aka ZDI-CAN-1607.
GHSA-3rjh-r4h7-c3mq
Broadcast control frames can disconnect multiple aircraft simultaneously leading to delayed clearances and air traffic controller overload. This type of attack can be carried out remotely over radio frequency.
GHSA-3rjh-fcp5-cg7v
In BIG-IQ 5.2.0-7.0.0, high availability (HA) synchronization is not secure by TLS and may allow on-path attackers to read / modify confidential data in transit.
GHSA-3rjh-cgv2-5vr4
Directory traversal vulnerability in filemanager.asp for Hosting Controller 1.4.1 and earlier allows remote attackers to read and modify arbitrary files, and execute commands, via a .. (dot dot) in the OpenPath parameter.
GHSA-3rjg-j65w-6v3j
Rejected reason: Not used
GHSA-3rjg-j575-7f6p
Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.
GHSA-3rjg-j22m-wrv3
A mediaforaction expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07).
GHSA-3rjg-g3j8-q837
D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formLanguageChange. This vulnerability allows attackers to cause a Denial of Service (DoS) via the nextPage parameter.
GHSA-3rjg-ff6r-x2c7
A vulnerability was found in Rebuild up to 3.5.5. It has been classified as problematic. Affected is the function getFileOfData of the file /filex/read-raw. The manipulation of the argument url leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252456.
GHSA-3rjg-586v-gcmf
Beauty Parlour Booking Script 1.0 has SQL Injection via the /list gender or city parameter.
GHSA-3rjf-4xj2-6g8f
** DISPUTED ** Race condition in Norman Security Suite PRO 8.0 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute.
GHSA-3rjc-xpqg-5mh4
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to delete or read arbitrary files on the underlying operating system. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
GHSA-3rjc-6hx2-f4rh
A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "sta_log_htm" API which are not properly sanitized before being concatenated to OS level commands.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3rjq-9j9w-pxr3 OSIsoft PI Vision, All versions of PI Vision prior to 2019. The affected product is vulnerable to a cross-site request forgery that may be introduced on the PI Vision administration site. | 1% Низкий | больше 4 лет назад | ||
GHSA-3rjq-96vg-4j89 Missing Authorization vulnerability in G5Theme G5Plus April g5plus-april allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects G5Plus April: from n/a through <= 6.8. | CVSS3: 5.3 | 0% Низкий | 5 месяцев назад | |
GHSA-3rjp-hfjx-9689 In GraphicsMagick 1.4 snapshot-20190403 Q8, there is a use-after-free in ThrowException and ThrowLoggedException of magick/error.c. | CVSS3: 9.8 | 3% Низкий | больше 4 лет назад | |
GHSA-3rjp-6929-2mrw HTTP server in Cisco Wireless Control System (WCS) for Linux and Windows before 3.2(51) stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain usernames and directory paths via a direct URL request. | 2% Низкий | больше 4 лет назад | ||
GHSA-3rjm-xww9-gmm6 Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to bypass intended access restrictions via unspecified vectors. | CVSS3: 9.8 | 5% Низкий | больше 4 лет назад | |
GHSA-3rjm-q6hg-6jw8 RealOne Player 2.0 Build 6.0.11.872 allows remote attackers to cause a denial of service (array out-of-bounds access and application crash) via a crafted .aiff file. | CVSS3: 5.5 | 1% Низкий | больше 4 лет назад | |
GHSA-3rjm-jwr3-fh58 Buffer overflow in the Napster client beta 5 allows remote attackers to cause a denial of service via a long message. | 1% Низкий | больше 4 лет назад | ||
GHSA-3rjj-rpg2-4f2q Unspecified vulnerability in HP Intelligent Management Center (iMC) and HP IMC Branch Intelligent Management System Software Module (aka BIMS) allows remote attackers to obtain sensitive information via unknown vectors, aka ZDI-CAN-1607. | 38% Средний | больше 4 лет назад | ||
GHSA-3rjh-r4h7-c3mq Broadcast control frames can disconnect multiple aircraft simultaneously leading to delayed clearances and air traffic controller overload. This type of attack can be carried out remotely over radio frequency. | CVSS3: 5.3 | 0% Низкий | около 1 месяца назад | |
GHSA-3rjh-fcp5-cg7v In BIG-IQ 5.2.0-7.0.0, high availability (HA) synchronization is not secure by TLS and may allow on-path attackers to read / modify confidential data in transit. | 0% Низкий | больше 4 лет назад | ||
GHSA-3rjh-cgv2-5vr4 Directory traversal vulnerability in filemanager.asp for Hosting Controller 1.4.1 and earlier allows remote attackers to read and modify arbitrary files, and execute commands, via a .. (dot dot) in the OpenPath parameter. | 4% Низкий | больше 4 лет назад | ||
GHSA-3rjg-j65w-6v3j Rejected reason: Not used | 8 месяцев назад | |||
GHSA-3rjg-j575-7f6p Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'. | CVSS3: 4.7 | 3% Низкий | больше 4 лет назад | |
GHSA-3rjg-j22m-wrv3 A mediaforaction expression language injection remote code execution vulnerability was discovered in HPE Intelligent Management Center (iMC) version(s): Prior to iMC PLAT 7.3 (E0705P07). | 3% Низкий | больше 4 лет назад | ||
GHSA-3rjg-g3j8-q837 D-Link DIR-619 Ax v1.00 was discovered to contain a stack overflow in the function formLanguageChange. This vulnerability allows attackers to cause a Denial of Service (DoS) via the nextPage parameter. | CVSS3: 7.5 | 1% Низкий | больше 4 лет назад | |
GHSA-3rjg-ff6r-x2c7 A vulnerability was found in Rebuild up to 3.5.5. It has been classified as problematic. Affected is the function getFileOfData of the file /filex/read-raw. The manipulation of the argument url leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-252456. | CVSS3: 3.5 | 1% Низкий | больше 2 лет назад | |
GHSA-3rjg-586v-gcmf Beauty Parlour Booking Script 1.0 has SQL Injection via the /list gender or city parameter. | CVSS3: 9.8 | 3% Низкий | больше 4 лет назад | |
GHSA-3rjf-4xj2-6g8f ** DISPUTED ** Race condition in Norman Security Suite PRO 8.0 on Windows XP allows local users to bypass kernel-mode hook handlers, and execute dangerous code that would otherwise be blocked by a handler but not blocked by signature-based malware detection, via certain user-space memory changes during hook-handler execution, aka an argument-switch attack or a KHOBE attack. NOTE: this issue is disputed by some third parties because it is a flaw in a protection mechanism for situations where a crafted program has already begun to execute. | 0% Низкий | больше 4 лет назад | ||
GHSA-3rjc-xpqg-5mh4 Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to delete or read arbitrary files on the underlying operating system. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. | CVSS3: 5.4 | 0% Низкий | больше 3 лет назад | |
GHSA-3rjc-6hx2-f4rh A CWE-78 "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')" was discovered affecting the following devices manufactured by Advantech: EKI-6333AC-2G (<= 1.6.3), EKI-6333AC-2GD (<= v1.6.3) and EKI-6333AC-1GPO (<= v1.2.1). The source of the vulnerability relies on multiple parameters belonging to the "sta_log_htm" API which are not properly sanitized before being concatenated to OS level commands. | CVSS3: 7.2 | 1% Низкий | почти 2 года назад |
Уязвимостей на страницу