Количество 364 463
Количество 364 463
GHSA-22jp-w3cg-gvmm
Liferay Portal has Stored Cross-Site Scripting Vulnerability via Message Boards Feature
GHSA-22jp-m5f3-q68p
Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier version, 2017.011.30138 and earlier version, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.
GHSA-22jm-p2vv-j2hc
Plone XSS
GHSA-22jm-gmg3-6r8v
Cross-site scripting (XSS) vulnerability in board.php in mowdBB RC-6 allows remote attackers to inject arbitrary web script or HTML via the forum_name[] parameter.
GHSA-22jm-4hxw-35jf
OpenStack Nova can leak consoleauth token into log files
GHSA-22jj-r264-9ffc
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PressTigers ZIP Code Based Content Protection allows SQL Injection. This issue affects ZIP Code Based Content Protection: from n/a through 1.0.0.
GHSA-22jj-744v-92v5
livehelperchat is vulnerable to Generation of Error Message Containing Sensitive Information
GHSA-22jh-hqf7-v4mw
Windows Network Address Translation (NAT) Denial of Service Vulnerability.
GHSA-22jh-6gx8-f944
Elastic APM agent for Python client CGI proxy redirection flaw
GHSA-22jh-5463-4m46
Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/blog/blogpublish.php.
GHSA-22jg-rc3r-96wc
Real Media RealServer (rmserver) 6.0.3.353 stores a password in plaintext in the world-readable rmserver.cfg file, which allows local users to gain privileges.
GHSA-22jf-r33c-m8rf
Stomper 5e2741e is vulnerable to Denial of Service. When a broker sends data to a client whose TCP connection was already closed by the peer, the server process receives SIGPIPE and immediately terminates, resulting in a denial of service. Any unauthenticated client can trigger the crash by closing the socket at specific points.
GHSA-22jf-gccc-jpfh
VCFTools vcfools prior to version 0.1.15 is affected by: Heap Use-After-Free. The impact is: Denial of Service or possibly unspecified impact (eg. code execution or information disclosure). The component is: The header::add_FILTER_descriptor method in header.cpp. The attack vector is: The victim must open a specially crafted VCF file.
GHSA-22jf-974v-hf7j
A race condition was addressed with improved locking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A malicious application may be able to elevate privileges. Apple is aware of a report that this issue may have been actively exploited..
GHSA-22jc-frmh-h993
TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the NTPSyncWithHost function via the hostTime parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request.
GHSA-22j9-95fq-2m3h
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or cause the web server to make HTTP requests to arbitrary domains. IBM X-Force ID: 147369.
GHSA-22j9-38hm-95cq
A stack-based buffer over-read was discovered in Mat_VarReadNextInfo5 in mat5.c in matio 1.5.17.
GHSA-22j8-wpwh-4rrr
An out-of-bounds write vulnerability was found in glibc before 2.31 when handling signal trampolines on PowerPC. Specifically, the backtrace function did not properly check the array bounds when storing the frame address, resulting in a denial of service or potential code execution. The highest threat from this vulnerability is to system availability.
GHSA-22j7-r3jq-5mv9
An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "PDFKit" component. It allows remote attackers to bypass intended restrictions on visiting URLs within a PDF document.
GHSA-22j7-69m5-2pqh
SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-22jp-w3cg-gvmm Liferay Portal has Stored Cross-Site Scripting Vulnerability via Message Boards Feature | 0% Низкий | около 1 года назад | ||
GHSA-22jp-m5f3-q68p Adobe Acrobat and Reader versions 2019.010.20100 and earlier, 2019.010.20099 and earlier, 2017.011.30140 and earlier version, 2017.011.30138 and earlier version, 2015.006.30495 and earlier, and 2015.006.30493 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution. | CVSS3: 6.5 | 10% Низкий | больше 4 лет назад | |
GHSA-22jm-p2vv-j2hc Plone XSS | CVSS3: 6.1 | 2% Низкий | больше 4 лет назад | |
GHSA-22jm-gmg3-6r8v Cross-site scripting (XSS) vulnerability in board.php in mowdBB RC-6 allows remote attackers to inject arbitrary web script or HTML via the forum_name[] parameter. | 1% Низкий | больше 4 лет назад | ||
GHSA-22jm-4hxw-35jf OpenStack Nova can leak consoleauth token into log files | CVSS3: 3.3 | 0% Низкий | больше 4 лет назад | |
GHSA-22jj-r264-9ffc Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PressTigers ZIP Code Based Content Protection allows SQL Injection. This issue affects ZIP Code Based Content Protection: from n/a through 1.0.0. | CVSS3: 7.6 | 0% Низкий | 12 месяцев назад | |
GHSA-22jj-744v-92v5 livehelperchat is vulnerable to Generation of Error Message Containing Sensitive Information | 1% Низкий | больше 4 лет назад | ||
GHSA-22jh-hqf7-v4mw Windows Network Address Translation (NAT) Denial of Service Vulnerability. | CVSS3: 7.5 | 3% Низкий | около 4 лет назад | |
GHSA-22jh-6gx8-f944 Elastic APM agent for Python client CGI proxy redirection flaw | CVSS3: 7.2 | 2% Низкий | больше 4 лет назад | |
GHSA-22jh-5463-4m46 Ecommerce-CodeIgniter-Bootstrap before 2020-08-03 allows XSS in application/modules/admin/views/blog/blogpublish.php. | 1% Низкий | больше 4 лет назад | ||
GHSA-22jg-rc3r-96wc Real Media RealServer (rmserver) 6.0.3.353 stores a password in plaintext in the world-readable rmserver.cfg file, which allows local users to gain privileges. | 1% Низкий | больше 4 лет назад | ||
GHSA-22jf-r33c-m8rf Stomper 5e2741e is vulnerable to Denial of Service. When a broker sends data to a client whose TCP connection was already closed by the peer, the server process receives SIGPIPE and immediately terminates, resulting in a denial of service. Any unauthenticated client can trigger the crash by closing the socket at specific points. | CVSS3: 7.5 | 3 дня назад | ||
GHSA-22jf-gccc-jpfh VCFTools vcfools prior to version 0.1.15 is affected by: Heap Use-After-Free. The impact is: Denial of Service or possibly unspecified impact (eg. code execution or information disclosure). The component is: The header::add_FILTER_descriptor method in header.cpp. The attack vector is: The victim must open a specially crafted VCF file. | больше 4 лет назад | |||
GHSA-22jf-974v-hf7j A race condition was addressed with improved locking. This issue is fixed in macOS Big Sur 11.2, Security Update 2021-001 Catalina, Security Update 2021-001 Mojave, watchOS 7.3, tvOS 14.4, iOS 14.4 and iPadOS 14.4. A malicious application may be able to elevate privileges. Apple is aware of a report that this issue may have been actively exploited.. | CVSS3: 7 | 2% Низкий | больше 4 лет назад | |
GHSA-22jc-frmh-h993 TOTOLINK CA600-PoE V5.3c.6665_B20180820 was found to contain a command injection vulnerability in the NTPSyncWithHost function via the hostTime parameter. This vulnerability allows attackers to execute arbitrary commands via a crafted request. | CVSS3: 6.5 | 1% Низкий | больше 1 года назад | |
GHSA-22j9-95fq-2m3h IBM Cognos Analytics 11.0 and 11.1 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or cause the web server to make HTTP requests to arbitrary domains. IBM X-Force ID: 147369. | CVSS3: 8.8 | 2% Низкий | больше 4 лет назад | |
GHSA-22j9-38hm-95cq A stack-based buffer over-read was discovered in Mat_VarReadNextInfo5 in mat5.c in matio 1.5.17. | 1% Низкий | больше 4 лет назад | ||
GHSA-22j8-wpwh-4rrr An out-of-bounds write vulnerability was found in glibc before 2.31 when handling signal trampolines on PowerPC. Specifically, the backtrace function did not properly check the array bounds when storing the frame address, resulting in a denial of service or potential code execution. The highest threat from this vulnerability is to system availability. | CVSS3: 7 | 1% Низкий | больше 4 лет назад | |
GHSA-22j7-r3jq-5mv9 An issue was discovered in certain Apple products. macOS before 10.13.4 is affected. The issue involves the "PDFKit" component. It allows remote attackers to bypass intended restrictions on visiting URLs within a PDF document. | CVSS3: 6.5 | 2% Низкий | больше 4 лет назад | |
GHSA-22j7-69m5-2pqh SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing "traverse to parent directory" are passed through to the file APIs. | CVSS3: 6.6 | 29% Средний | больше 4 лет назад |
Уязвимостей на страницу