Количество 376 989
Количество 376 989
GHSA-3p3w-8fvr-q4gw
Multiple unspecified vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, 5.0 Update 29 and earlier, and 1.4.2_31 and earlier allow remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D.
GHSA-3p3v-qhpw-qrgr
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stun-user parameter to /cgi-bin/cstecgi.cgi.
GHSA-3p3r-fjqw-f7g3
A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.3 and iPadOS 13.3, watchOS 6.1.1, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra, tvOS 13.3. An application may be able to execute arbitrary code with kernel privileges.
GHSA-3p3q-w36v-m4vj
Buffer overflow in the Multimedia PC Client in Nortel Multimedia Communication Server (MCS) before Maintenance Release 3.5.8.3 and 4.0.25.3 allows remote attackers to cause a denial of service (crash) via a flood of "extraneous" messages, as demonstrated by the Nessus "Generic flood" denial of service plugin.
GHSA-3p3q-5gjp-wvmc
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
GHSA-3p3p-qg5g-j2p5
SQL injection vulnerability in view.php in Butterfly Organizer 2.0.1 allows remote attackers to execute arbitrary SQL commands via the mytable parameter. NOTE: the id vector is covered by another CVE name.
GHSA-3p3p-pvm7-cggr
Winston 1.5.4 devices are vulnerable to command injection via the API.
GHSA-3p3p-cgj7-vgw3
RSSHub vulnerable to Server-Side Request Forgery
GHSA-3p3m-mqcr-8mfw
Inappropriate implementation in Cast UI in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to spoof browser UI via a crafted HTML page. (Chromium security severity: Low)
GHSA-3p3m-h26v-9r73
The Quectel RG502Q-EA modem before 2022-02-23 allow OS Command Injection.
GHSA-3p3m-4x7c-p4pw
unsafe parameter handing in `wsrep_notify_cmd`
GHSA-3p3h-qghp-hvh2
Open Redirect in werkzeug
GHSA-3p3h-j9q4-q239
Incorrect access control in the firmware update and download processes of IVY Smart v4.5.0 allows attackers to access sensitive information by analyzing the code and data within the APK file.
GHSA-3p3h-7wpm-9j2r
Centreon 22.04.0 is vulnerable to Cross Site Scripting (XSS) from the function Pollers > Broker Configuration by adding a crafted payload into the name parameter.
GHSA-3p3h-5g54-qmc8
ClassCMS <=4.8 is vulnerable to file inclusion in the nowView method in/class/cms/cms.php, which can include a file uploaded to the/class/template directory to execute PHP code.
GHSA-3p3g-vpw6-4w66
Authentication Bypass in hydra
GHSA-3p3g-v9c5-jwvw
An improper certificate validation vulnerability [CWE-295] in FortiOS 7.2.0 through 7.2.3, 7.0.0 through 7.0.7, 6.4 all versions, 6.2 all versions, 6.0 all versions and FortiProxy 7.0.0 through 7.0.6, 2.0 all versions, 1.2 all versions may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the FortiOS/FortiProxy device and remote servers hosting threat feeds (when the latter are configured as Fabric connectors in FortiOS/FortiProxy)
GHSA-3p3f-hgmm-72qv
Unspecified vulnerability in the Database Vault component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, and 11.2.0.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
GHSA-3p3f-h63v-47c5
A stack buffer overflow in speexenc.c of Speex v1.2 allows attackers to cause a denial of service (DoS) via a crafted WAV file.
GHSA-3p3f-cf7r-qqhf
FreeBSD 5.x to 5.4 on AMD64 does not properly initialize the IO permission bitmap used to allow user access to certain hardware, which allows local users to bypass intended access restrictions to cause a denial of service, obtain sensitive information, and possibly gain privileges.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-3p3w-8fvr-q4gw Multiple unspecified vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier, 5.0 Update 29 and earlier, and 1.4.2_31 and earlier allow remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. | 6% Низкий | больше 4 лет назад | ||
GHSA-3p3v-qhpw-qrgr An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the stun-user parameter to /cgi-bin/cstecgi.cgi. | CVSS3: 6.5 | 1% Низкий | 5 месяцев назад | |
GHSA-3p3r-fjqw-f7g3 A memory corruption issue was addressed by removing the vulnerable code. This issue is fixed in iOS 13.3 and iPadOS 13.3, watchOS 6.1.1, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra, tvOS 13.3. An application may be able to execute arbitrary code with kernel privileges. | 1% Низкий | больше 4 лет назад | ||
GHSA-3p3q-w36v-m4vj Buffer overflow in the Multimedia PC Client in Nortel Multimedia Communication Server (MCS) before Maintenance Release 3.5.8.3 and 4.0.25.3 allows remote attackers to cause a denial of service (crash) via a flood of "extraneous" messages, as demonstrated by the Nessus "Generic flood" denial of service plugin. | 2% Низкий | больше 4 лет назад | ||
GHSA-3p3q-5gjp-wvmc Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | больше 1 года назад | |||
GHSA-3p3p-qg5g-j2p5 SQL injection vulnerability in view.php in Butterfly Organizer 2.0.1 allows remote attackers to execute arbitrary SQL commands via the mytable parameter. NOTE: the id vector is covered by another CVE name. | 1% Низкий | больше 4 лет назад | ||
GHSA-3p3p-pvm7-cggr Winston 1.5.4 devices are vulnerable to command injection via the API. | 4% Низкий | больше 4 лет назад | ||
GHSA-3p3p-cgj7-vgw3 RSSHub vulnerable to Server-Side Request Forgery | CVSS3: 6.5 | 1% Низкий | больше 2 лет назад | |
GHSA-3p3m-mqcr-8mfw Inappropriate implementation in Cast UI in Google Chrome prior to 96.0.4664.45 allowed a remote attacker to spoof browser UI via a crafted HTML page. (Chromium security severity: Low) | CVSS3: 4.3 | 1% Низкий | около 3 лет назад | |
GHSA-3p3m-h26v-9r73 The Quectel RG502Q-EA modem before 2022-02-23 allow OS Command Injection. | CVSS3: 9.8 | 3% Низкий | больше 4 лет назад | |
GHSA-3p3m-4x7c-p4pw unsafe parameter handing in `wsrep_notify_cmd` | CVSS3: 10 | 2% Низкий | 4 месяца назад | |
GHSA-3p3h-qghp-hvh2 Open Redirect in werkzeug | CVSS3: 6.1 | 2% Низкий | больше 5 лет назад | |
GHSA-3p3h-j9q4-q239 Incorrect access control in the firmware update and download processes of IVY Smart v4.5.0 allows attackers to access sensitive information by analyzing the code and data within the APK file. | CVSS3: 8.4 | 0% Низкий | почти 2 года назад | |
GHSA-3p3h-7wpm-9j2r Centreon 22.04.0 is vulnerable to Cross Site Scripting (XSS) from the function Pollers > Broker Configuration by adding a crafted payload into the name parameter. | CVSS3: 5.4 | 1% Низкий | около 4 лет назад | |
GHSA-3p3h-5g54-qmc8 ClassCMS <=4.8 is vulnerable to file inclusion in the nowView method in/class/cms/cms.php, which can include a file uploaded to the/class/template directory to execute PHP code. | CVSS3: 9.8 | 1% Низкий | почти 2 года назад | |
GHSA-3p3g-vpw6-4w66 Authentication Bypass in hydra | CVSS3: 5.8 | 1% Низкий | больше 5 лет назад | |
GHSA-3p3g-v9c5-jwvw An improper certificate validation vulnerability [CWE-295] in FortiOS 7.2.0 through 7.2.3, 7.0.0 through 7.0.7, 6.4 all versions, 6.2 all versions, 6.0 all versions and FortiProxy 7.0.0 through 7.0.6, 2.0 all versions, 1.2 all versions may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel between the FortiOS/FortiProxy device and remote servers hosting threat feeds (when the latter are configured as Fabric connectors in FortiOS/FortiProxy) | CVSS3: 7.4 | 0% Низкий | больше 3 лет назад | |
GHSA-3p3f-hgmm-72qv Unspecified vulnerability in the Database Vault component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, and 11.2.0.1 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. | 2% Низкий | больше 4 лет назад | ||
GHSA-3p3f-h63v-47c5 A stack buffer overflow in speexenc.c of Speex v1.2 allows attackers to cause a denial of service (DoS) via a crafted WAV file. | CVSS3: 5.5 | 1% Низкий | больше 4 лет назад | |
GHSA-3p3f-cf7r-qqhf FreeBSD 5.x to 5.4 on AMD64 does not properly initialize the IO permission bitmap used to allow user access to certain hardware, which allows local users to bypass intended access restrictions to cause a denial of service, obtain sensitive information, and possibly gain privileges. | 0% Низкий | больше 4 лет назад |
Уязвимостей на страницу