Количество 373 892
Количество 373 892
GHSA-3p42-w5ch-gg42
TYPO3 CMS has an Open Redirect Vulnerability via Core Utilities
GHSA-3p42-c2wq-v9gc
A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary JavaScript code via a vulnerable delete_file parameter.
GHSA-3p42-8gxw-6cw4
Stack-based buffer overflow in gen_jumpex.dll in Winamp before 5.64 Build 3418 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a package with a long Skin directory name. NOTE: a second buffer overflow involving a long GUI Search field to ml_local.dll was also reported. However, since it is only exploitable by the user of the application, this issue would not cross privilege boundaries unless Winamp is running under a highly restricted environment such as a kiosk.
GHSA-3p42-7grr-wj6x
HPE Universal CMDB 10.0 through 10.21, Universal CMDB Configuration Manager 10.0 through 10.21, and Universal Discovery 10.0 through 10.21 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library.
GHSA-3p3x-vg38-6g9q
Issue summary: Checking excessively long DH keys or parameters may be very slow. Impact summary: Applications that use the functions DH_check(), DH_check_ex() or EVP_PKEY_param_check() to check a DH key or DH parameters may experience long delays. Where the key or parameters that are being checked have been obtained from an untrusted source this may lead to a Denial of Service. The function DH_check() performs various checks on DH parameters. One of those checks confirms that the modulus ('p' parameter) is not too large. Trying to use a very large modulus is slow and OpenSSL will not normally use a modulus which is over 10,000 bits in length. However the DH_check() function checks numerous aspects of the key or parameters that have been supplied. Some of those checks use the supplied modulus value even if it has already been found to be too large. An application that calls DH_check() and supplies a key or parameters obtained from an untrusted source could be vulernable to a Deni...
GHSA-3p3x-8v96-cq98
A vulnerability was found in Campcodes Online Apartment Visitor Management System 1.0. Impacted is an unknown function of the file /admin-profile.php. Performing manipulation of the argument mobilenumber results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
GHSA-3p3w-92gc-7p27
Buffer overflow in BIOS firmware for 8th, 9th, 10th Generation Intel(R) Core(TM), Intel(R) Celeron(R) Processor 4000 & 5000 Series Processors may allow an authenticated user to potentially enable elevation of privilege or denial of service via adjacent access.
GHSA-3p3w-8fvr-q4gw
Multiple unspecified vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, 5.0 Update 29 and earlier, and 1.4.2_31 and earlier allow remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.
GHSA-3p3v-qhpw-qrgr
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stun-user parameter to /cgi-bin/cstecgi.cgi.
GHSA-3p3r-fjqw-f7g3
A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.3 and iPadOS 13.3, watchOS 6.1.1, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra, tvOS 13.3. An application may be able to execute arbitrary code with kernel privileges.
GHSA-3p3q-w36v-m4vj
Buffer overflow in the Multimedia PC Client in Nortel Multimedia Communication Server (MCS) before Maintenance Release 3.5.8.3 and 4.0.25.3 allows remote attackers to cause a denial of service (crash) via a flood of "extraneous" messages, as demonstrated by the Nessus "Generic flood" denial of service plugin.
GHSA-3p3q-5gjp-wvmc
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
GHSA-3p3p-qg5g-j2p5
SQL injection vulnerability in view.php in Butterfly Organizer 2.0.1 allows remote attackers to execute arbitrary SQL commands via the mytable parameter. NOTE: the id vector is covered by another CVE name.
GHSA-3p3p-pvm7-cggr
Winston 1.5.4 devices are vulnerable to command injection via the API.
GHSA-3p3p-cgj7-vgw3
RSSHub vulnerable to Server-Side Request Forgery
GHSA-3p3m-mqcr-8mfw
Inappropriate implementation in Cast UI in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to spoof browser UI via a crafted HTML page. (Chromium security severity: Low)
GHSA-3p3m-h26v-9r73
The Quectel RG502Q-EA modem before 2022-02-23 allow OS Command Injection.
GHSA-3p3m-4x7c-p4pw
unsafe parameter handing in `wsrep_notify_cmd`
GHSA-3p3h-qghp-hvh2
Open Redirect in werkzeug
GHSA-3p3h-j9q4-q239
Incorrect access control in the firmware update and download processes of IVY Smart v4.5.0 allows attackers to access sensitive information by analyzing the code and data within the APK file.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3p42-w5ch-gg42 TYPO3 CMS has an Open Redirect Vulnerability via Core Utilities | 0% Низкий | 3 месяца назад | ||
GHSA-3p42-c2wq-v9gc A Cross Site Scripting vulnerability in Microworld Technologies eScan Management console v.14.0.1400.2281 allows a remote attacker to execute arbitrary JavaScript code via a vulnerable delete_file parameter. | CVSS3: 5.4 | 1% Низкий | около 3 лет назад | |
GHSA-3p42-8gxw-6cw4 Stack-based buffer overflow in gen_jumpex.dll in Winamp before 5.64 Build 3418 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a package with a long Skin directory name. NOTE: a second buffer overflow involving a long GUI Search field to ml_local.dll was also reported. However, since it is only exploitable by the user of the application, this issue would not cross privilege boundaries unless Winamp is running under a highly restricted environment such as a kiosk. | 17% Средний | больше 4 лет назад | ||
GHSA-3p42-7grr-wj6x HPE Universal CMDB 10.0 through 10.21, Universal CMDB Configuration Manager 10.0 through 10.21, and Universal Discovery 10.0 through 10.21 allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections (ACC) library. | CVSS3: 9.8 | 5% Низкий | больше 4 лет назад | |
GHSA-3p3x-vg38-6g9q Issue summary: Checking excessively long DH keys or parameters may be very slow. Impact summary: Applications that use the functions DH_check(), DH_check_ex() or EVP_PKEY_param_check() to check a DH key or DH parameters may experience long delays. Where the key or parameters that are being checked have been obtained from an untrusted source this may lead to a Denial of Service. The function DH_check() performs various checks on DH parameters. One of those checks confirms that the modulus ('p' parameter) is not too large. Trying to use a very large modulus is slow and OpenSSL will not normally use a modulus which is over 10,000 bits in length. However the DH_check() function checks numerous aspects of the key or parameters that have been supplied. Some of those checks use the supplied modulus value even if it has already been found to be too large. An application that calls DH_check() and supplies a key or parameters obtained from an untrusted source could be vulernable to a Deni... | CVSS3: 5.3 | 7% Низкий | около 3 лет назад | |
GHSA-3p3x-8v96-cq98 A vulnerability was found in Campcodes Online Apartment Visitor Management System 1.0. Impacted is an unknown function of the file /admin-profile.php. Performing manipulation of the argument mobilenumber results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used. | CVSS3: 4.7 | 0% Низкий | 11 месяцев назад | |
GHSA-3p3w-92gc-7p27 Buffer overflow in BIOS firmware for 8th, 9th, 10th Generation Intel(R) Core(TM), Intel(R) Celeron(R) Processor 4000 & 5000 Series Processors may allow an authenticated user to potentially enable elevation of privilege or denial of service via adjacent access. | 1% Низкий | больше 4 лет назад | ||
GHSA-3p3w-8fvr-q4gw Multiple unspecified vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, 5.0 Update 29 and earlier, and 1.4.2_31 and earlier allow remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. | 6% Низкий | больше 4 лет назад | ||
GHSA-3p3v-qhpw-qrgr An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stun-user parameter to /cgi-bin/cstecgi.cgi. | CVSS3: 6.5 | 0% Низкий | 5 месяцев назад | |
GHSA-3p3r-fjqw-f7g3 A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.3 and iPadOS 13.3, watchOS 6.1.1, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra, tvOS 13.3. An application may be able to execute arbitrary code with kernel privileges. | 1% Низкий | больше 4 лет назад | ||
GHSA-3p3q-w36v-m4vj Buffer overflow in the Multimedia PC Client in Nortel Multimedia Communication Server (MCS) before Maintenance Release 3.5.8.3 and 4.0.25.3 allows remote attackers to cause a denial of service (crash) via a flood of "extraneous" messages, as demonstrated by the Nessus "Generic flood" denial of service plugin. | 2% Низкий | больше 4 лет назад | ||
GHSA-3p3q-5gjp-wvmc Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | больше 1 года назад | |||
GHSA-3p3p-qg5g-j2p5 SQL injection vulnerability in view.php in Butterfly Organizer 2.0.1 allows remote attackers to execute arbitrary SQL commands via the mytable parameter. NOTE: the id vector is covered by another CVE name. | 1% Низкий | больше 4 лет назад | ||
GHSA-3p3p-pvm7-cggr Winston 1.5.4 devices are vulnerable to command injection via the API. | 4% Низкий | больше 4 лет назад | ||
GHSA-3p3p-cgj7-vgw3 RSSHub vulnerable to Server-Side Request Forgery | CVSS3: 6.5 | 1% Низкий | больше 2 лет назад | |
GHSA-3p3m-mqcr-8mfw Inappropriate implementation in Cast UI in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to spoof browser UI via a crafted HTML page. (Chromium security severity: Low) | CVSS3: 4.3 | 1% Низкий | около 3 лет назад | |
GHSA-3p3m-h26v-9r73 The Quectel RG502Q-EA modem before 2022-02-23 allow OS Command Injection. | CVSS3: 9.8 | 3% Низкий | около 4 лет назад | |
GHSA-3p3m-4x7c-p4pw unsafe parameter handing in `wsrep_notify_cmd` | CVSS3: 10 | 2% Низкий | 4 месяца назад | |
GHSA-3p3h-qghp-hvh2 Open Redirect in werkzeug | CVSS3: 6.1 | 2% Низкий | больше 5 лет назад | |
GHSA-3p3h-j9q4-q239 Incorrect access control in the firmware update and download processes of IVY Smart v4.5.0 allows attackers to access sensitive information by analyzing the code and data within the APK file. | CVSS3: 8.4 | 0% Низкий | почти 2 года назад |
Уязвимостей на страницу