Количество 353 714
Количество 353 714
GHSA-2h9p-fvvm-92g9
Tablet Windows User Interface Application Core Elevation of Privilege Vulnerability.
GHSA-2h9m-7wj7-h654
IBM MQ Appliance 9.3 LTS and 9.3 CD could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request to view arbitrary files on the system. IBM X-Force ID: 269536.
GHSA-2h9j-hxw7-2jf3
Use after free in Microsoft Office allows an unauthorized attacker to execute code locally.
GHSA-2h9h-wfvh-5r96
Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involving PREAUTH, which is a less secure behavior than the alternative of closing the connection and letting the user decide what they would like to do.
GHSA-2h9h-pcw6-4f34
A buffer overflow in the g_cfg.MaxUsers component of LightFTP v2.0 allows attackers to cause a Denial of Service (DoS) via a crafted input.
GHSA-2h9h-4f6p-xvfc
Cross-site scripting (XSS) vulnerability in view.php in eTicket 1.5.5.2 allows remote attackers to inject arbitrary web script or HTML via the s parameter.
GHSA-2h9g-8p3q-w23q
A vulnerability has been found in code-projects Real State Services 1.0. This impacts an unknown function of the file /loginuser.php of the component Login. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
GHSA-2h9f-xm25-q379
In wlan STA, there is a possible way to trick a client to connect to an AP with spoofed SSID. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08990446 / ALPS09057442; Issue ID: MSV-1598.
GHSA-2h9f-vrvc-wfwh
An information disclosure vulnerability exists in Windows 8.1, Windows RT 8.1, Windows Server 2012 R2, Windows 10, and Windows Server 2016 when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user's system, a.k.a. "Windows Kernel Information Disclosure Vulnerability."
GHSA-2h9f-vc99-85c4
A system-critical Windows NT registry key has inappropriate permissions.
GHSA-2h9f-ppj9-gcvv
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Piotnet Piotnet Addons For Elementor allows Stored XSS.This issue affects Piotnet Addons For Elementor: from n/a through 2.4.26.
GHSA-2h9f-48qh-w996
Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_support/index.php?page=edit_customer.
GHSA-2h9c-p959-263w
Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally.
GHSA-2h9c-gjwm-vfqx
Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme Rara Business allows Cross Site Request Forgery.This issue affects Rara Business: from n/a through 1.2.5.
GHSA-2h9c-34v6-3qmr
Kubernetes in OpenShift3 Access Control Misconfiguration
GHSA-2h98-r334-3wg6
siteadmin/useredit.php in AlstraSoft Video Share Enterprise does not check authentication, which allows remote attackers to obtain or modify user information via a direct request.
GHSA-2h98-6q8m-mm63
textract before 1.5.0 allows OS Command Injection attacks via a filename in a call to the process function. This may be a remote attack if a web application accepts names of arbitrary uploaded files.
GHSA-2h97-jww5-mwvc
Permissive Cross-Origin Resource Sharing (CORS) in the REST API (helix-rest, org.apache.helix.rest.server.filters.CORSFilter) in Apache Helix through 2.0.0 on all platforms allows a remote attacker controlling a web page visited by an authorized user to read responses from and issue cross-origin requests to administrative REST endpoints via a cross-origin request from an arbitrary origin, since the filter unconditionally returns Access-Control-Allow-Origin: * together with Access-Control-Allow-Credentials: true and reflects arbitrary Access-Control-Request-Method / Access-Control-Request-Headers values in preflight responses. Users are recommended to upgrade to version 2.0.1, which fixes this issue.
GHSA-2h97-8375-29wg
Symantec Advanced Secure Gateway (ASG) and ProxySG are susceptible to an HTTP desync vulnerability. When a remote unauthenticated attacker and other web clients communicate through the proxy with the same web server, the attacker can send crafted HTTP requests and cause the proxy to forward web server responses to unintended clients. Severity/CVSSv3: High / 8.1 AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
GHSA-2h97-526w-g59p
The "block fragmented IP Packets" option in Symantec Norton Personal Firewall 2002 (NPW) does not properly protect against certain attacks on Windows vulnerabilities such as jolt2 (CVE-2000-0305).
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-2h9p-fvvm-92g9 Tablet Windows User Interface Application Core Elevation of Privilege Vulnerability. | CVSS3: 7 | 1% Низкий | около 4 лет назад | |
GHSA-2h9m-7wj7-h654 IBM MQ Appliance 9.3 LTS and 9.3 CD could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request to view arbitrary files on the system. IBM X-Force ID: 269536. | CVSS3: 6.5 | 1% Низкий | больше 2 лет назад | |
GHSA-2h9j-hxw7-2jf3 Use after free in Microsoft Office allows an unauthorized attacker to execute code locally. | CVSS3: 7.8 | 0% Низкий | 18 дней назад | |
GHSA-2h9h-wfvh-5r96 Alpine before 2.23 silently proceeds to use an insecure connection after a /tls is sent in certain circumstances involving PREAUTH, which is a less secure behavior than the alternative of closing the connection and letting the user decide what they would like to do. | CVSS3: 7.5 | 2% Низкий | около 4 лет назад | |
GHSA-2h9h-pcw6-4f34 A buffer overflow in the g_cfg.MaxUsers component of LightFTP v2.0 allows attackers to cause a Denial of Service (DoS) via a crafted input. | CVSS3: 6.5 | 0% Низкий | 8 месяцев назад | |
GHSA-2h9h-4f6p-xvfc Cross-site scripting (XSS) vulnerability in view.php in eTicket 1.5.5.2 allows remote attackers to inject arbitrary web script or HTML via the s parameter. | 2% Низкий | около 4 лет назад | ||
GHSA-2h9g-8p3q-w23q A vulnerability has been found in code-projects Real State Services 1.0. This impacts an unknown function of the file /loginuser.php of the component Login. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. | CVSS3: 7.3 | 0% Низкий | 2 месяца назад | |
GHSA-2h9f-xm25-q379 In wlan STA, there is a possible way to trick a client to connect to an AP with spoofed SSID. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08990446 / ALPS09057442; Issue ID: MSV-1598. | CVSS3: 7.5 | 0% Низкий | больше 1 года назад | |
GHSA-2h9f-vrvc-wfwh An information disclosure vulnerability exists in Windows 8.1, Windows RT 8.1, Windows Server 2012 R2, Windows 10, and Windows Server 2016 when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user's system, a.k.a. "Windows Kernel Information Disclosure Vulnerability." | CVSS3: 5.5 | 6% Низкий | около 4 лет назад | |
GHSA-2h9f-vc99-85c4 A system-critical Windows NT registry key has inappropriate permissions. | 2% Низкий | больше 4 лет назад | ||
GHSA-2h9f-ppj9-gcvv Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Piotnet Piotnet Addons For Elementor allows Stored XSS.This issue affects Piotnet Addons For Elementor: from n/a through 2.4.26. | CVSS3: 6.5 | 0% Низкий | больше 2 лет назад | |
GHSA-2h9f-48qh-w996 Customer Support System v1 was discovered to contain a SQL injection vulnerability via the id parameter at /customer_support/index.php?page=edit_customer. | CVSS3: 4.3 | 1% Низкий | больше 2 лет назад | |
GHSA-2h9c-p959-263w Out-of-bounds read in Windows Kernel allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 18 дней назад | |
GHSA-2h9c-gjwm-vfqx Cross-Site Request Forgery (CSRF) vulnerability in Rara Theme Rara Business allows Cross Site Request Forgery.This issue affects Rara Business: from n/a through 1.2.5. | CVSS3: 4.3 | 0% Низкий | больше 1 года назад | |
GHSA-2h9c-34v6-3qmr Kubernetes in OpenShift3 Access Control Misconfiguration | CVSS3: 3.1 | 1% Низкий | около 4 лет назад | |
GHSA-2h98-r334-3wg6 siteadmin/useredit.php in AlstraSoft Video Share Enterprise does not check authentication, which allows remote attackers to obtain or modify user information via a direct request. | 2% Низкий | больше 4 лет назад | ||
GHSA-2h98-6q8m-mm63 textract before 1.5.0 allows OS Command Injection attacks via a filename in a call to the process function. This may be a remote attack if a web application accepts names of arbitrary uploaded files. | CVSS3: 7.8 | 2% Низкий | около 4 лет назад | |
GHSA-2h97-jww5-mwvc Permissive Cross-Origin Resource Sharing (CORS) in the REST API (helix-rest, org.apache.helix.rest.server.filters.CORSFilter) in Apache Helix through 2.0.0 on all platforms allows a remote attacker controlling a web page visited by an authorized user to read responses from and issue cross-origin requests to administrative REST endpoints via a cross-origin request from an arbitrary origin, since the filter unconditionally returns Access-Control-Allow-Origin: * together with Access-Control-Allow-Credentials: true and reflects arbitrary Access-Control-Request-Method / Access-Control-Request-Headers values in preflight responses. Users are recommended to upgrade to version 2.0.1, which fixes this issue. | CVSS3: 7.5 | 0% Низкий | 23 дня назад | |
GHSA-2h97-8375-29wg Symantec Advanced Secure Gateway (ASG) and ProxySG are susceptible to an HTTP desync vulnerability. When a remote unauthenticated attacker and other web clients communicate through the proxy with the same web server, the attacker can send crafted HTTP requests and cause the proxy to forward web server responses to unintended clients. Severity/CVSSv3: High / 8.1 AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N | CVSS3: 9.1 | 2% Низкий | около 4 лет назад | |
GHSA-2h97-526w-g59p The "block fragmented IP Packets" option in Symantec Norton Personal Firewall 2002 (NPW) does not properly protect against certain attacks on Windows vulnerabilities such as jolt2 (CVE-2000-0305). | 1% Низкий | больше 4 лет назад |
Уязвимостей на страницу