Количество 375 727
Количество 375 727
GHSA-3mjg-59rv-9hm8
In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can use the `printf` SPL function to perform a denial of service (DoS) against the Splunk Enterprise instance.
GHSA-3mjg-24q2-wgh5
In InputMethodInfo of InputMethodInfo.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.
GHSA-3mjf-x8rp-5rcp
IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of input size.
GHSA-3mjf-7c4r-qw77
Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability
GHSA-3mjc-mr9p-3j4r
Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure.
GHSA-3mjc-cvm2-cpqw
Improper Input Validation vulnerability exists in PowerChute Business Edition (software V9.0.x and earlier) which could cause remote code execution when a script is executed during a shutdown event.
GHSA-3mjc-9976-q699
CRLF injection vulnerability in load.php in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5 allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the javaVersion parameter.
GHSA-3mjc-8px4-f596
Multiple SQL injection vulnerabilities in MyPHP Forum 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the fid in forum.php, (2) the member parameter in member.php, (3) the email parameter in forgot.php, or (4) the nbuser or nbpass parameters in include.php. NOTE: it was later reported that vector 2 exists in 3.0 and earlier.
GHSA-3mjc-3jvj-6m9f
A vulnerability classified as problematic was found in Limbas 5.2.14. Affected by this vulnerability is an unknown functionality of the file main_admin.php. The manipulation of the argument tab_group leads to sql injection. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-254575. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
GHSA-3mj9-vrrp-55v4
A CRLF injection vulnerability in Kentico Xperience allows attackers to manipulate URL query string redirects via improper encoding in the routing engine. This could enable header injection and potentially facilitate further web application attacks.
GHSA-3mj9-r4cx-8mx5
Crash in the CMS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file
GHSA-3mj9-p2pr-gqr4
A vulnerability classified as critical has been found in uTorrent. This affects an unknown part. The manipulation leads to memory corruption. It is possible to initiate the attack remotely. It is recommended to upgrade the affected component.
GHSA-3mj9-c62w-jw5w
HTTP Protocol Stack Remote Code Execution Vulnerability
GHSA-3mj9-8h4m-j8f7
Server-Side Request Forgery (SSRF) in kubeflow/kubeflow
GHSA-3mj8-x4jc-gf23
Cross-site scripting (XSS) vulnerability in products/classified/headersearch.php in 2daybiz Online Classified Script allows remote attackers to inject arbitrary web script or HTML via the sid parameter.
GHSA-3mj8-wjf2-5v9c
HAMweather 2.x allows remote attackers to modify administrative settings and obtain sensitive information via a direct request to hwadmin.cgi.
GHSA-3mj8-v2cx-7x5g
An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. An Undocumented Backdoor exists, allowing shell access via a developer account.
GHSA-3mj8-5fpc-8c72
Cross-site scripting (XSS) vulnerability in default.asp in ClickTech Clickcart 6.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the cat parameter.
GHSA-3mj8-3cm6-5whc
openSUSE openbuildservice before 9.2.4 allowed authenticated users to delete packages on specific projects with project links.
GHSA-3mj6-p6q9-4j76
Improper access control vulnerability in ProfileSharingAccount in Group Sharing prior to versions 13.0.6.15 in Android S(12), 13.0.6.14 in Android R(11) and below allows attackers to identify the device.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3mjg-59rv-9hm8 In Splunk Enterprise versions lower than 8.2.12, 9.0.6, and 9.1.1, an attacker can use the `printf` SPL function to perform a denial of service (DoS) against the Splunk Enterprise instance. | CVSS3: 6.5 | 0% Низкий | около 3 лет назад | |
GHSA-3mjg-24q2-wgh5 In InputMethodInfo of InputMethodInfo.java, there is a possible permanent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. | CVSS3: 5.5 | 0% Низкий | 10 месяцев назад | |
GHSA-3mjf-x8rp-5rcp IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper validation of input size. | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
GHSA-3mjf-7c4r-qw77 Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability | CVSS3: 5.5 | 1% Низкий | около 3 лет назад | |
GHSA-3mjc-mr9p-3j4r Rejected reason: This CVE ID was rejected because it was reserved but not used for a vulnerability disclosure. | 9 месяцев назад | |||
GHSA-3mjc-cvm2-cpqw Improper Input Validation vulnerability exists in PowerChute Business Edition (software V9.0.x and earlier) which could cause remote code execution when a script is executed during a shutdown event. | 2% Низкий | больше 4 лет назад | ||
GHSA-3mjc-9976-q699 CRLF injection vulnerability in load.php in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5 allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the javaVersion parameter. | 1% Низкий | больше 4 лет назад | ||
GHSA-3mjc-8px4-f596 Multiple SQL injection vulnerabilities in MyPHP Forum 1.0 allow remote attackers to execute arbitrary SQL commands via (1) the fid in forum.php, (2) the member parameter in member.php, (3) the email parameter in forgot.php, or (4) the nbuser or nbpass parameters in include.php. NOTE: it was later reported that vector 2 exists in 3.0 and earlier. | 2% Низкий | больше 4 лет назад | ||
GHSA-3mjc-3jvj-6m9f A vulnerability classified as problematic was found in Limbas 5.2.14. Affected by this vulnerability is an unknown functionality of the file main_admin.php. The manipulation of the argument tab_group leads to sql injection. The complexity of an attack is rather high. The exploitation appears to be difficult. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-254575. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 3.9 | 1% Низкий | больше 2 лет назад | |
GHSA-3mj9-vrrp-55v4 A CRLF injection vulnerability in Kentico Xperience allows attackers to manipulate URL query string redirects via improper encoding in the routing engine. This could enable header injection and potentially facilitate further web application attacks. | CVSS3: 6.5 | 0% Низкий | 9 месяцев назад | |
GHSA-3mj9-r4cx-8mx5 Crash in the CMS protocol dissector in Wireshark 3.6.0 to 3.6.1 and 3.4.0 to 3.4.11 allows denial of service via packet injection or crafted capture file | CVSS3: 7.5 | 2% Низкий | больше 4 лет назад | |
GHSA-3mj9-p2pr-gqr4 A vulnerability classified as critical has been found in uTorrent. This affects an unknown part. The manipulation leads to memory corruption. It is possible to initiate the attack remotely. It is recommended to upgrade the affected component. | CVSS3: 8.8 | 1% Низкий | больше 4 лет назад | |
GHSA-3mj9-c62w-jw5w HTTP Protocol Stack Remote Code Execution Vulnerability | CVSS3: 9.8 | 100% Критический | больше 4 лет назад | |
GHSA-3mj9-8h4m-j8f7 Server-Side Request Forgery (SSRF) in kubeflow/kubeflow | CVSS3: 7.7 | 1% Низкий | почти 3 года назад | |
GHSA-3mj8-x4jc-gf23 Cross-site scripting (XSS) vulnerability in products/classified/headersearch.php in 2daybiz Online Classified Script allows remote attackers to inject arbitrary web script or HTML via the sid parameter. | 1% Низкий | больше 4 лет назад | ||
GHSA-3mj8-wjf2-5v9c HAMweather 2.x allows remote attackers to modify administrative settings and obtain sensitive information via a direct request to hwadmin.cgi. | 1% Низкий | больше 4 лет назад | ||
GHSA-3mj8-v2cx-7x5g An issue was discovered in CommScope Ruckus IoT Controller 1.7.1.0 and earlier. An Undocumented Backdoor exists, allowing shell access via a developer account. | 14% Средний | больше 4 лет назад | ||
GHSA-3mj8-5fpc-8c72 Cross-site scripting (XSS) vulnerability in default.asp in ClickTech Clickcart 6.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the cat parameter. | 2% Низкий | больше 4 лет назад | ||
GHSA-3mj8-3cm6-5whc openSUSE openbuildservice before 9.2.4 allowed authenticated users to delete packages on specific projects with project links. | CVSS3: 6.5 | 1% Низкий | больше 4 лет назад | |
GHSA-3mj6-p6q9-4j76 Improper access control vulnerability in ProfileSharingAccount in Group Sharing prior to versions 13.0.6.15 in Android S(12), 13.0.6.14 in Android R(11) and below allows attackers to identify the device. | CVSS3: 5.3 | 0% Низкий | почти 4 года назад |
Уязвимостей на страницу