Количество 373 892
Количество 373 892
GHSA-3pc4-pj89-2j67
A Reliance on Untrusted Inputs in a Security Decision vulnerability in the login proxy of the openSUSE Build service allowed attackers to present users with a expected login form that then sends the clear text credentials to an attacker specified server. This issue affects: openSUSE Build service login-proxy-scripts versions prior to dc000cdfe9b9b715fb92195b1a57559362f689ef.
GHSA-3pc4-7j85-539h
The SSH-1 protocol allows remote servers to conduct man-in-the-middle attacks and replay a client challenge response to a target server by creating a Session ID that matches the Session ID of the target, but which uses a public key pair that is weaker than the target's public key, which allows the attacker to compute the corresponding private key and use the target's Session ID with the compromised key pair to masquerade as the target.
GHSA-3pc3-xxxx-7pfj
A security flaw has been discovered in Open5GS up to 2.7.5. The impacted element is the function gmm_state_exception of the file src/amf/gmm-sm.c. The manipulation results in reachable assertion. It is possible to launch the attack remotely. The exploit has been released to the public and may be exploited. The patch is identified as 8e5fed16114f2f5e40bee1b161914b592b2b7b8f. Applying a patch is advised to resolve this issue.
GHSA-3pc3-vcqg-prf6
A deserialization of untrusted data vulnerability exists in NI VeriStand DataLogging Server that may result in remote code execution. Successful exploitation requires an attacker to send a specially crafted message. These vulnerabilities affect NI VeriStand 2024 Q2 and prior versions.
GHSA-3pc3-p9j7-xvq6
In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.108, and 9.1.2312.204, a low-privileged user that does not hold the "admin" or "power" Splunk roles could change the maintenance mode state of App Key Value Store (KVStore) through a Cross-Site Request Forgery (CSRF).
GHSA-3pc3-3mfc-x5vj
The Connection Conversation Manager (aka CuCsMgr) process in Cisco Unity Connection 8.5 before 8.5(1)SU7, 8.6 before 8.6(2a)SU4, 9.x before 9.1(2)SU2, and 10.0 before 10.0(1)SU1, when SIP trunk integration is enabled, allows remote attackers to cause a denial of service (core dump and restart) via crafted SIP INVITE messages, aka Bug ID CSCul26267.
GHSA-3pc2-v6g3-vwg9
Unauthenticated Cross Site Scripting (XSS) in ChatBot <= 8.3.2 versions.
GHSA-3pc2-fm7p-q2vg
Cross-site Scripting in October
GHSA-3pc2-c878-63rj
A path traversal vulnerability in the “account_print.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow a remote authenticated attacker with administrator privileges to execute unauthorized OS commands in the “tmp” directory by uploading a crafted file if the hotspot function were enabled.
GHSA-3p9x-xxx6-2w4p
Broken Access Control in 3rd party TYPO3 extension "femanager"
GHSA-3p9x-xxjc-hw5p
The Qards plugin through 2017-10-11 for WordPress has XSS via a remote document specified in the url parameter to html2canvasproxy.php.
GHSA-3p9x-fj5f-w25c
A vulnerability in the remote access VPN session manager of Cisco Adaptive Security Appliance (ASA) Software could allow a unauthenticated, remote attacker to cause a denial of service (DoS) condition on the remote access VPN services. The vulnerability is due to an issue with the remote access VPN session manager. An attacker could exploit this vulnerability by requesting an excessive number of remote access VPN sessions. An exploit could allow the attacker to cause a DoS condition.
GHSA-3p9x-34w6-f58v
Cross-site scripting (XSS) vulnerability in the Webform Framework API in IBM Forms Server 4.0.x, 8.0.x, 8.1, and 8.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 110006.
GHSA-3p9w-wq67-w93f
libgadu before 1.8.2 allows remote servers to cause a denial of service (crash) via a contact description with a large length, which triggers a buffer over-read.
GHSA-3p9w-w3x4-vc62
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5 and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-Force ID: 140973.
GHSA-3p9w-w3g3-89rg
Open redirect vulnerability in the Login Page (index.php) in ownCloud before 5.0.6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect_url parameter.
GHSA-3p9w-pv5h-crrp
The Contact Form Advanced Database WordPress plugin through 1.0.8 does not have any authorisation as well as CSRF checks in its delete_cf7_data and export_cf7_data AJAX actions, available to any authenticated users, which could allow users with a role as low as subscriber to call them. The delete_cf7_data would lead to arbitrary metadata deletion, as well as PHP Object Injection if a suitable gadget chain is present in another plugin, as user data is passed to the maybe_unserialize() function without being first validated.
GHSA-3p9w-cf27-62fv
Microsoft Message Queuing Remote Code Execution Vulnerability
GHSA-3p9w-7x8w-2m9v
PHP remote file inclusion vulnerability in index.php in GrapAgenda 0.11 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the page parameter.
GHSA-3p9v-xp6w-wcmc
QuickAppsCMS Cross-Site Request Forgery (CSRF)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3pc4-pj89-2j67 A Reliance on Untrusted Inputs in a Security Decision vulnerability in the login proxy of the openSUSE Build service allowed attackers to present users with a expected login form that then sends the clear text credentials to an attacker specified server. This issue affects: openSUSE Build service login-proxy-scripts versions prior to dc000cdfe9b9b715fb92195b1a57559362f689ef. | CVSS3: 8.8 | 1% Низкий | больше 4 лет назад | |
GHSA-3pc4-7j85-539h The SSH-1 protocol allows remote servers to conduct man-in-the-middle attacks and replay a client challenge response to a target server by creating a Session ID that matches the Session ID of the target, but which uses a public key pair that is weaker than the target's public key, which allows the attacker to compute the corresponding private key and use the target's Session ID with the compromised key pair to masquerade as the target. | 6% Низкий | больше 4 лет назад | ||
GHSA-3pc3-xxxx-7pfj A security flaw has been discovered in Open5GS up to 2.7.5. The impacted element is the function gmm_state_exception of the file src/amf/gmm-sm.c. The manipulation results in reachable assertion. It is possible to launch the attack remotely. The exploit has been released to the public and may be exploited. The patch is identified as 8e5fed16114f2f5e40bee1b161914b592b2b7b8f. Applying a patch is advised to resolve this issue. | CVSS3: 5.3 | 1% Низкий | около 1 года назад | |
GHSA-3pc3-vcqg-prf6 A deserialization of untrusted data vulnerability exists in NI VeriStand DataLogging Server that may result in remote code execution. Successful exploitation requires an attacker to send a specially crafted message. These vulnerabilities affect NI VeriStand 2024 Q2 and prior versions. | CVSS3: 9.8 | 1% Низкий | около 2 лет назад | |
GHSA-3pc3-p9j7-xvq6 In Splunk Enterprise versions below 9.3.1, 9.2.3, and 9.1.6 and Splunk Cloud Platform versions below 9.2.2403.108, and 9.1.2312.204, a low-privileged user that does not hold the "admin" or "power" Splunk roles could change the maintenance mode state of App Key Value Store (KVStore) through a Cross-Site Request Forgery (CSRF). | CVSS3: 4.3 | 0% Низкий | почти 2 года назад | |
GHSA-3pc3-3mfc-x5vj The Connection Conversation Manager (aka CuCsMgr) process in Cisco Unity Connection 8.5 before 8.5(1)SU7, 8.6 before 8.6(2a)SU4, 9.x before 9.1(2)SU2, and 10.0 before 10.0(1)SU1, when SIP trunk integration is enabled, allows remote attackers to cause a denial of service (core dump and restart) via crafted SIP INVITE messages, aka Bug ID CSCul26267. | 2% Низкий | больше 4 лет назад | ||
GHSA-3pc2-v6g3-vwg9 Unauthenticated Cross Site Scripting (XSS) in ChatBot <= 8.3.2 versions. | CVSS3: 7.1 | 0% Низкий | 3 месяца назад | |
GHSA-3pc2-fm7p-q2vg Cross-site Scripting in October | CVSS3: 3.7 | 1% Низкий | около 6 лет назад | |
GHSA-3pc2-c878-63rj A path traversal vulnerability in the “account_print.cgi” CGI program of Zyxel USG FLEX series firmware versions 4.50 through 5.35, and VPN series firmware versions 4.30 through 5.35, which could allow a remote authenticated attacker with administrator privileges to execute unauthorized OS commands in the “tmp” directory by uploading a crafted file if the hotspot function were enabled. | CVSS3: 7.2 | 1% Низкий | около 3 лет назад | |
GHSA-3p9x-xxx6-2w4p Broken Access Control in 3rd party TYPO3 extension "femanager" | CVSS3: 8.6 | 1% Низкий | больше 3 лет назад | |
GHSA-3p9x-xxjc-hw5p The Qards plugin through 2017-10-11 for WordPress has XSS via a remote document specified in the url parameter to html2canvasproxy.php. | 2% Низкий | больше 4 лет назад | ||
GHSA-3p9x-fj5f-w25c A vulnerability in the remote access VPN session manager of Cisco Adaptive Security Appliance (ASA) Software could allow a unauthenticated, remote attacker to cause a denial of service (DoS) condition on the remote access VPN services. The vulnerability is due to an issue with the remote access VPN session manager. An attacker could exploit this vulnerability by requesting an excessive number of remote access VPN sessions. An exploit could allow the attacker to cause a DoS condition. | CVSS3: 5.9 | 2% Низкий | больше 4 лет назад | |
GHSA-3p9x-34w6-f58v Cross-site scripting (XSS) vulnerability in the Webform Framework API in IBM Forms Server 4.0.x, 8.0.x, 8.1, and 8.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 110006. | CVSS3: 6.1 | 1% Низкий | больше 4 лет назад | |
GHSA-3p9w-wq67-w93f libgadu before 1.8.2 allows remote servers to cause a denial of service (crash) via a contact description with a large length, which triggers a buffer over-read. | 1% Низкий | больше 4 лет назад | ||
GHSA-3p9w-w3x4-vc62 IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5 and 11.1 is vulnerable to a buffer overflow, which could allow an authenticated local attacker to execute arbitrary code on the system as root. IBM X-Force ID: 140973. | CVSS3: 7.8 | 1% Низкий | больше 4 лет назад | |
GHSA-3p9w-w3g3-89rg Open redirect vulnerability in the Login Page (index.php) in ownCloud before 5.0.6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirect_url parameter. | 2% Низкий | больше 4 лет назад | ||
GHSA-3p9w-pv5h-crrp The Contact Form Advanced Database WordPress plugin through 1.0.8 does not have any authorisation as well as CSRF checks in its delete_cf7_data and export_cf7_data AJAX actions, available to any authenticated users, which could allow users with a role as low as subscriber to call them. The delete_cf7_data would lead to arbitrary metadata deletion, as well as PHP Object Injection if a suitable gadget chain is present in another plugin, as user data is passed to the maybe_unserialize() function without being first validated. | CVSS3: 4.3 | 0% Низкий | почти 5 лет назад | |
GHSA-3p9w-cf27-62fv Microsoft Message Queuing Remote Code Execution Vulnerability | CVSS3: 9.8 | 2% Низкий | около 3 лет назад | |
GHSA-3p9w-7x8w-2m9v PHP remote file inclusion vulnerability in index.php in GrapAgenda 0.11 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the page parameter. | 4% Низкий | больше 4 лет назад | ||
GHSA-3p9v-xp6w-wcmc QuickAppsCMS Cross-Site Request Forgery (CSRF) | CVSS3: 8.8 | 1% Низкий | больше 4 лет назад |
Уязвимостей на страницу