Количество 353 883
Количество 353 883
GHSA-2mg9-59xm-chrg
The `/etc/passwd` and `/etc/shadow` files reveal hard-coded password hashes for the operating system "root" user. The credentials are shipped with the update files. There is no option for deleting or changing their passwords for an enduser. An attacker can use the credentials to log into the device. Authentication can be performed via SSH backdoor or likely via physical access (UART shell).
GHSA-2mg8-v7rr-mpqj
NVIDIA DGX Spark GB10 contains a vulnerability in OSROOT firmware, where an attacker could cause an invalid memory read. A successful exploit of this vulnerability might lead to denial of service.
GHSA-2mg8-pqjg-f272
Buffer overflow in Labtam ProFTP 2.9 allows remote FTP servers to cause a denial of service (application crash) or execute arbitrary code via a long 220 reply (aka connection greeting or welcome message).
GHSA-2mg8-jrmg-qq5v
The simple-add-pages-or-posts plugin before 1.7 for WordPress has CSRF for deleting users.
GHSA-2mg8-8fqw-hq49
Multiple cross-site request forgery (CSRF) vulnerabilities in the Our Team Showcase (our-team-enhanced) plugin before 1.3 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) change plugin settings via unspecified vectors or (2) conduct cross-site scripting (XSS) attacks via the sc_our_team_member_count parameter in the sc_team_settings page to wp-admin/edit.php.
GHSA-2mg8-3gq9-25w2
The useredit_account.wdm module in Alt-N WebAdmin 3.2.5 running with MDaemon 9.0.6, and possibly earlier versions, allows remote authenticated domain administrators to gain privileges and obtain access to the system mail queue by modifying the mailbox of the MDaemon user account to use the mailbox of another account.
GHSA-2mg7-w9r8-29mw
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Wikimedia Foundation Mediawiki - Cargo Extension allows Stored XSS.This issue affects Mediawiki - Cargo Extension: before 3.8.7.
GHSA-2mg7-924f-g32v
The srtp_add_address function in epan/dissectors/packet-rtp.c in the RTP dissector in Wireshark 1.10.x before 1.10.7 does not properly update SRTP conversation data, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.
GHSA-2mg6-cgrh-mg4j
In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Fix double free in error path If the uvc_status_init() function fails to allocate the int_urb, it will free the dev->status pointer but doesn't reset the pointer to NULL. This results in the kfree() call in uvc_status_cleanup() trying to double-free the memory. Fix it by resetting the dev->status pointer to NULL after freeing it. Reviewed by: Ricardo Ribalda <ribalda@chromium.org>
GHSA-2mg5-34rx-c3p8
ServiceNow has addressed a reflected cross-site scripting vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could result in arbitrary code being executed within the browsers of ServiceNow users who click on a specially crafted link. ServiceNow has addressed this vulnerability by deploying a relevant security update to the majority of hosted instances. Relevant security updates also have been provided to ServiceNow self-hosted customers, partners, and hosted customers with unique configurations. Further, the vulnerability is addressed in the listed patches and hot fixes. We recommend customers promptly apply appropriate updates or upgrade if they have not already done so.
GHSA-2mg5-26r6-fpmg
Stack-based buffer overflow in the SymSpamHelper ActiveX component (symspam.dll) in Norton AntiSpam 2004, as used in Norton Internet Security 2004, allows remote attackers to execute arbitrary code via a long parameter to the LaunchCustomRuleWizard method.
GHSA-2mg4-pfgx-64cf
AVideo's WebSocket Token Never Expires Due to Commented-Out Timeout Validation in verifyTokenSocket()
GHSA-2mg4-fmh8-qqh3
Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
GHSA-2mg4-7347-xp3j
** DISPUTED ** 3Com TippingPoint IPS allows remote attackers to cause a denial of service (device hang) via a flood of packets on TCP port 80 with sequentially increasing source ports, related to a "badly written loop." NOTE: the vendor disputes this issue, stating that the product has "performed as expected with no DoS emerging."
GHSA-2mg4-3x37-m4wx
Rejected reason: Not used
GHSA-2mg3-gq68-7gq2
An issue was discovered in Veritas Resiliency Platform (VRP) before 3.4 HF1. An arbitrary command execution vulnerability allows a malicious VRP user to execute commands with root privilege within the VRP virtual machine, related to resiliency plans and custom script functionality.
GHSA-2mg3-562w-27qp
A vulnerability in the ERS API of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system of an affected device. To exploit this vulnerability, an attacker must have valid Administrator-level privileges on the affected device. This vulnerability is due to improper privilege management in the ERS API. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to elevate their privileges beyond the sphere of their intended access level, which would allow them to obtain sensitive information from the underlying operating system. Note: The ERS is not enabled by default. To verify the status of the ERS API in the Admin GUI, choose Administration > Settings > API Settings > API Service Settings.
GHSA-2mg2-p7r7-g27f
Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service
GHSA-2mg2-8p2q-47h9
Novell NetWare 5.0 allows remote attackers to cause a denial of service by flooding port 40193 with random data.
GHSA-2mfx-wqj9-m26w
IBM Security AppScan Enterprise 8.x before 8.8 sends a cleartext AppScan Source database password in a response, which allows remote authenticated users to obtain sensitive information, and subsequently conduct man-in-the-middle attacks, by examining the response content.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2mg9-59xm-chrg The `/etc/passwd` and `/etc/shadow` files reveal hard-coded password hashes for the operating system "root" user. The credentials are shipped with the update files. There is no option for deleting or changing their passwords for an enduser. An attacker can use the credentials to log into the device. Authentication can be performed via SSH backdoor or likely via physical access (UART shell). | CVSS3: 7.7 | 0% Низкий | около 1 года назад | |
GHSA-2mg8-v7rr-mpqj NVIDIA DGX Spark GB10 contains a vulnerability in OSROOT firmware, where an attacker could cause an invalid memory read. A successful exploit of this vulnerability might lead to denial of service. | CVSS3: 5.7 | 0% Низкий | 8 месяцев назад | |
GHSA-2mg8-pqjg-f272 Buffer overflow in Labtam ProFTP 2.9 allows remote FTP servers to cause a denial of service (application crash) or execute arbitrary code via a long 220 reply (aka connection greeting or welcome message). | 28% Средний | больше 4 лет назад | ||
GHSA-2mg8-jrmg-qq5v The simple-add-pages-or-posts plugin before 1.7 for WordPress has CSRF for deleting users. | CVSS3: 6.5 | 1% Низкий | около 4 лет назад | |
GHSA-2mg8-8fqw-hq49 Multiple cross-site request forgery (CSRF) vulnerabilities in the Our Team Showcase (our-team-enhanced) plugin before 1.3 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) change plugin settings via unspecified vectors or (2) conduct cross-site scripting (XSS) attacks via the sc_our_team_member_count parameter in the sc_team_settings page to wp-admin/edit.php. | 1% Низкий | около 4 лет назад | ||
GHSA-2mg8-3gq9-25w2 The useredit_account.wdm module in Alt-N WebAdmin 3.2.5 running with MDaemon 9.0.6, and possibly earlier versions, allows remote authenticated domain administrators to gain privileges and obtain access to the system mail queue by modifying the mailbox of the MDaemon user account to use the mailbox of another account. | 1% Низкий | больше 4 лет назад | ||
GHSA-2mg7-w9r8-29mw Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Wikimedia Foundation Mediawiki - Cargo Extension allows Stored XSS.This issue affects Mediawiki - Cargo Extension: before 3.8.7. | CVSS3: 6.1 | 0% Низкий | 4 месяца назад | |
GHSA-2mg7-924f-g32v The srtp_add_address function in epan/dissectors/packet-rtp.c in the RTP dissector in Wireshark 1.10.x before 1.10.7 does not properly update SRTP conversation data, which allows remote attackers to cause a denial of service (application crash) via a crafted packet. | 2% Низкий | около 4 лет назад | ||
GHSA-2mg6-cgrh-mg4j In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Fix double free in error path If the uvc_status_init() function fails to allocate the int_urb, it will free the dev->status pointer but doesn't reset the pointer to NULL. This results in the kfree() call in uvc_status_cleanup() trying to double-free the memory. Fix it by resetting the dev->status pointer to NULL after freeing it. Reviewed by: Ricardo Ribalda <ribalda@chromium.org> | CVSS3: 7.8 | 0% Низкий | больше 1 года назад | |
GHSA-2mg5-34rx-c3p8 ServiceNow has addressed a reflected cross-site scripting vulnerability that was identified in the ServiceNow AI Platform. This vulnerability could result in arbitrary code being executed within the browsers of ServiceNow users who click on a specially crafted link. ServiceNow has addressed this vulnerability by deploying a relevant security update to the majority of hosted instances. Relevant security updates also have been provided to ServiceNow self-hosted customers, partners, and hosted customers with unique configurations. Further, the vulnerability is addressed in the listed patches and hot fixes. We recommend customers promptly apply appropriate updates or upgrade if they have not already done so. | 0% Низкий | 10 месяцев назад | ||
GHSA-2mg5-26r6-fpmg Stack-based buffer overflow in the SymSpamHelper ActiveX component (symspam.dll) in Norton AntiSpam 2004, as used in Norton Internet Security 2004, allows remote attackers to execute arbitrary code via a long parameter to the LaunchCustomRuleWizard method. | 67% Средний | больше 4 лет назад | ||
GHSA-2mg4-pfgx-64cf AVideo's WebSocket Token Never Expires Due to Commented-Out Timeout Validation in verifyTokenSocket() | CVSS3: 5.4 | 0% Низкий | 4 месяца назад | |
GHSA-2mg4-fmh8-qqh3 Untrusted pointer dereference in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network. | CVSS3: 4.3 | 1% Низкий | 9 месяцев назад | |
GHSA-2mg4-7347-xp3j ** DISPUTED ** 3Com TippingPoint IPS allows remote attackers to cause a denial of service (device hang) via a flood of packets on TCP port 80 with sequentially increasing source ports, related to a "badly written loop." NOTE: the vendor disputes this issue, stating that the product has "performed as expected with no DoS emerging." | 2% Низкий | больше 4 лет назад | ||
GHSA-2mg4-3x37-m4wx Rejected reason: Not used | больше 1 года назад | |||
GHSA-2mg3-gq68-7gq2 An issue was discovered in Veritas Resiliency Platform (VRP) before 3.4 HF1. An arbitrary command execution vulnerability allows a malicious VRP user to execute commands with root privilege within the VRP virtual machine, related to resiliency plans and custom script functionality. | CVSS3: 7.2 | 4% Низкий | около 4 лет назад | |
GHSA-2mg3-562w-27qp A vulnerability in the ERS API of Cisco ISE could allow an authenticated, remote attacker to read arbitrary files on the underlying operating system of an affected device. To exploit this vulnerability, an attacker must have valid Administrator-level privileges on the affected device. This vulnerability is due to improper privilege management in the ERS API. An attacker could exploit this vulnerability by sending a crafted request to an affected device. A successful exploit could allow the attacker to elevate their privileges beyond the sphere of their intended access level, which would allow them to obtain sensitive information from the underlying operating system. Note: The ERS is not enabled by default. To verify the status of the ERS API in the Admin GUI, choose Administration > Settings > API Settings > API Service Settings. | CVSS3: 4.9 | 1% Низкий | почти 3 года назад | |
GHSA-2mg2-p7r7-g27f Coder: Zip upload decompression lacks aggregate size limit, enabling denial of service | CVSS3: 6.5 | 0% Низкий | 27 дней назад | |
GHSA-2mg2-8p2q-47h9 Novell NetWare 5.0 allows remote attackers to cause a denial of service by flooding port 40193 with random data. | 3% Низкий | больше 4 лет назад | ||
GHSA-2mfx-wqj9-m26w IBM Security AppScan Enterprise 8.x before 8.8 sends a cleartext AppScan Source database password in a response, which allows remote authenticated users to obtain sensitive information, and subsequently conduct man-in-the-middle attacks, by examining the response content. | 1% Низкий | около 4 лет назад |
Уязвимостей на страницу