Количество 375 356
Количество 375 356
GHSA-36hr-2pgw-4595
Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains a Plaintext Password Storage vulnerability. Database credentials are stored in plaintext in a configuration file. An authenticated malicious user with access to the configuration file may obtain the exposed password to gain access to the application database.
GHSA-36hq-xx3q-26mm
Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to a buffer overflow. An attacker can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_dmvpn function with the gre_ip and the gre_mask variables.
GHSA-36hq-v2fc-rpqp
Jenkins Folders Plugin information disclosure vulnerability
GHSA-36hq-fr9w-frm9
Cross-site scripting (XSS) vulnerability in the admin-login panel (admin/index.cgi) in Cosmoshop allows remote attackers to inject arbitrary web script or HTML via the username field (u_name parameter).
GHSA-36hp-jr8h-556f
Authentication Bypass
GHSA-36hp-4x3g-phrg
Apache Tomcat's CookieExample Vulnerable to XSS
GHSA-36hp-4q45-jxjc
Subscriber Path Traversal in Do Lasso <= 358 versions.
GHSA-36hm-qxxp-pg3m
Preact has JSON VNode Injection issue
GHSA-36hm-mqp3-4q69
A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted SPP file. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-20300)
GHSA-36hm-h89f-cr4p
Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally.
GHSA-36hm-c9f8-f8xc
Lyrion Music Server 9.2.0 contains an arbitrary directory listing vulnerability in its readdirectory query, exposed through both the CLI service (TCP port 9090) and the HTTP JSON-RPC endpoint (/jsonrpc.js). The query accepts a folder parameter and lists its contents with no restriction to the configured media directories and no authentication in the default configuration, allowing a remote, unauthenticated attacker to enumerate arbitrary locations on the host filesystem.
GHSA-36hm-c3f9-q57c
SQL Injection in GitHub repository instantsoft/icms2 prior to 2.16.1.
GHSA-36hm-353j-v57w
Insufficient input validation in Kernel Mode module for Intel(R) Graphics Driver before version 25.20.100.6519 may allow an authenticated user to potentially enable denial of service via local access.
GHSA-36hj-r7fq-q38m
Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to certain in-memory query methods may allow an unauthenticated party to obtain unintended disclosure of stored document data and to permanently remove stored records.
GHSA-36hj-m3c2-4ggw
Floating point exception in function Fraction in libheif 1.4.0, allows attackers to cause a Denial of Service or possibly other unspecified impacts.
GHSA-36hj-g8jh-r4rq
A CWE-23: Relative Path Traversal vulnerability exists in Telit Cinterion BGS5, Telit Cinterion EHS5/6/8, Telit Cinterion PDS5/6/8, Telit Cinterion ELS61/81, Telit Cinterion PLS62 that could allow a local, low privileged attacker to escape from virtual directories and get read/write access to protected files on the targeted system.
GHSA-36hj-f8vr-vxrj
Cross-site scripting vulnerability in WP-OliveCart versions prior to 3.1.3 and WP-OliveCartPro versions prior to 3.1.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
GHSA-36hh-x5p5-jgc8
@hapi/content header parser has a parameter smuggling issue that allows upload-filter bypass via duplicate parameters
GHSA-36hh-vpg6-r82h
Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and LibreOffice before 3.5.5 allow remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted Open Document Text (.odt) file with (1) a child tag within an incorrect parent tag, (2) duplicate tags, or (3) a Base64 ChecksumAttribute whose length is not evenly divisible by four.
GHSA-36hh-v57m-3mm5
NetIQ Privileged Account Manager before 3.1 Patch Update 3 allowed cross site scripting attacks via the "type" and "account" parameters of json requests.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-36hr-2pgw-4595 Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains a Plaintext Password Storage vulnerability. Database credentials are stored in plaintext in a configuration file. An authenticated malicious user with access to the configuration file may obtain the exposed password to gain access to the application database. | CVSS3: 7.8 | 0% Низкий | больше 4 лет назад | |
GHSA-36hq-xx3q-26mm Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to a buffer overflow. An attacker can send HTTP requests to trigger these vulnerabilities.This buffer overflow occurs in the set_dmvpn function with the gre_ip and the gre_mask variables. | CVSS3: 7.2 | 1% Низкий | около 3 лет назад | |
GHSA-36hq-v2fc-rpqp Jenkins Folders Plugin information disclosure vulnerability | CVSS3: 4.3 | 1% Низкий | около 3 лет назад | |
GHSA-36hq-fr9w-frm9 Cross-site scripting (XSS) vulnerability in the admin-login panel (admin/index.cgi) in Cosmoshop allows remote attackers to inject arbitrary web script or HTML via the username field (u_name parameter). | 1% Низкий | больше 4 лет назад | ||
GHSA-36hp-jr8h-556f Authentication Bypass | 88% Высокий | больше 5 лет назад | ||
GHSA-36hp-4x3g-phrg Apache Tomcat's CookieExample Vulnerable to XSS | 3% Низкий | больше 4 лет назад | ||
GHSA-36hp-4q45-jxjc Subscriber Path Traversal in Do Lasso <= 358 versions. | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
GHSA-36hm-qxxp-pg3m Preact has JSON VNode Injection issue | 0% Низкий | 9 месяцев назад | ||
GHSA-36hm-mqp3-4q69 A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted SPP file. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-20300) | CVSS3: 7.8 | 0% Низкий | больше 3 лет назад | |
GHSA-36hm-h89f-cr4p Heap-based buffer overflow in Windows Common Log File System Driver allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 1% Низкий | 10 месяцев назад | |
GHSA-36hm-c9f8-f8xc Lyrion Music Server 9.2.0 contains an arbitrary directory listing vulnerability in its readdirectory query, exposed through both the CLI service (TCP port 9090) and the HTTP JSON-RPC endpoint (/jsonrpc.js). The query accepts a folder parameter and lists its contents with no restriction to the configured media directories and no authentication in the default configuration, allowing a remote, unauthenticated attacker to enumerate arbitrary locations on the host filesystem. | CVSS3: 5.3 | 0% Низкий | 4 месяца назад | |
GHSA-36hm-c3f9-q57c SQL Injection in GitHub repository instantsoft/icms2 prior to 2.16.1. | CVSS3: 7.2 | 1% Низкий | около 3 лет назад | |
GHSA-36hm-353j-v57w Insufficient input validation in Kernel Mode module for Intel(R) Graphics Driver before version 25.20.100.6519 may allow an authenticated user to potentially enable denial of service via local access. | CVSS3: 5.5 | 0% Низкий | больше 4 лет назад | |
GHSA-36hj-r7fq-q38m Mongoid contains an unsafe reflection weakness in the query path used for embedded documents. An application that passes an externally supplied field name to certain in-memory query methods may allow an unauthenticated party to obtain unintended disclosure of stored document data and to permanently remove stored records. | CVSS3: 9.8 | 0% Низкий | 2 дня назад | |
GHSA-36hj-m3c2-4ggw Floating point exception in function Fraction in libheif 1.4.0, allows attackers to cause a Denial of Service or possibly other unspecified impacts. | 1% Низкий | больше 4 лет назад | ||
GHSA-36hj-g8jh-r4rq A CWE-23: Relative Path Traversal vulnerability exists in Telit Cinterion BGS5, Telit Cinterion EHS5/6/8, Telit Cinterion PDS5/6/8, Telit Cinterion ELS61/81, Telit Cinterion PLS62 that could allow a local, low privileged attacker to escape from virtual directories and get read/write access to protected files on the targeted system. | CVSS3: 4.4 | 0% Низкий | почти 3 года назад | |
GHSA-36hj-f8vr-vxrj Cross-site scripting vulnerability in WP-OliveCart versions prior to 3.1.3 and WP-OliveCartPro versions prior to 3.1.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | CVSS3: 6.1 | 1% Низкий | больше 4 лет назад | |
GHSA-36hh-x5p5-jgc8 @hapi/content header parser has a parameter smuggling issue that allows upload-filter bypass via duplicate parameters | 0% Низкий | 4 месяца назад | ||
GHSA-36hh-vpg6-r82h Multiple heap-based buffer overflows in the XML manifest encryption tag parsing functionality in OpenOffice.org and LibreOffice before 3.5.5 allow remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted Open Document Text (.odt) file with (1) a child tag within an incorrect parent tag, (2) duplicate tags, or (3) a Base64 ChecksumAttribute whose length is not evenly divisible by four. | 7% Низкий | больше 4 лет назад | ||
GHSA-36hh-v57m-3mm5 NetIQ Privileged Account Manager before 3.1 Patch Update 3 allowed cross site scripting attacks via the "type" and "account" parameters of json requests. | CVSS3: 6.1 | 1% Низкий | больше 4 лет назад |
Уязвимостей на страницу