Количество 373 892
Количество 373 892
GHSA-22qh-55gx-68jh
Multiple vulnerabilities in the H.323 protocol implementation for Cisco IOS 11.3T through 12.2T allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol.
GHSA-22qg-42rj-w8x8
Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function formDelWlRfPolicy.
GHSA-22qf-w2wm-5686
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the encryption of firmware update images. The issue results from the use of an inappropriate encryption algorithm. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of root. Was ZDI-CAN-9649.
GHSA-22qf-62f9-pj62
As a part of Tenable’s vulnerability disclosure program, a vulnerability in a Nessus plugin was identified and reported. This vulnerability could allow a malicious actor with sufficient permissions on a scan target to place a binary in a specific filesystem location, and abuse the impacted plugin in order to escalate privileges.
GHSA-22q9-m8j5-x7xg
cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_make32() function at cute_png.h.
GHSA-22q9-hqm5-mhmc
Cross-Site Scripting in swagger-ui
GHSA-22q9-7cmf-jjxp
The LDAP component in Fedora Directory Server 1.0 allow remote attackers to cause a denial of service (crash) via a certain "bad BER sequence" that results in a free of uninitialized memory, as demonstrated using the ProtoVer LDAP test suite.
GHSA-22q8-rwx9-62gg
A vulnerability was found in Campcodes Legal Case Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /admin/court-type. The manipulation of the argument court_name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263805 was assigned to this vulnerability.
GHSA-22q8-ghmq-63vf
libgit2-sys affected by memory corruption, denial of service, and arbitrary code execution in libgit2
GHSA-22q7-qw7f-w974
Norton Password Manager, prior to 6.6.2.5, may be susceptible to an information disclosure issue, which is a type of vulnerability whereby there is an unintentional disclosure of information to an actor that is not explicitly authorized to have access to that information.
GHSA-22q7-cg4r-p9mx
TYPO3 Cross-Site Scripting in Fluid ViewHelpers
GHSA-22q7-8jfc-2936
Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
GHSA-22q6-wwq7-2jj9
OpenStack Keystone Improper Authentication vulnerability
GHSA-22q6-rw64-5gjj
Zoho ManageEngine ADManager Plus before 7183 allows admin users to exploit an XXE issue to view files.
GHSA-22q6-hvj2-jgmw
IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 150905.
GHSA-22q6-9rvj-cmpf
Buffer Overflow in Emerson GE Automation Proficy Machine Edition v8.0 allows an attacker to cause a denial of service and application crash via crafted traffic from a Man-in-the-Middle (MITM) attack to the component "FrameworX.exe" in the module "MSVCR100.dll".
GHSA-22q6-7m3g-6r77
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
GHSA-22q5-qg84-2p5f
Unspecified vulnerability in the OCI component in Oracle Database Server 10.2.0.3, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect confidentiality and integrity via unknown vectors.
GHSA-22q5-9phm-744v
XWiki allows unregistered users to access private pages information through REST endpoint
GHSA-22q5-57p4-rxcv
Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The web application improperly protects credentials which could allow an attacker to obtain credentials for remote access to controllers.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-22qh-55gx-68jh Multiple vulnerabilities in the H.323 protocol implementation for Cisco IOS 11.3T through 12.2T allow remote attackers to cause a denial of service and possibly execute arbitrary code, as demonstrated by the NISCC/OUSPG PROTOS test suite for the H.225 protocol. | 5% Низкий | больше 4 лет назад | ||
GHSA-22qg-42rj-w8x8 Tenda M3 V1.0.0.12(4856) was discovered to contain a stack overflow via the function formDelWlRfPolicy. | CVSS3: 9.8 | 1% Низкий | больше 2 лет назад | |
GHSA-22qf-w2wm-5686 This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR R6700 V1.0.4.84_10.0.58 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the encryption of firmware update images. The issue results from the use of an inappropriate encryption algorithm. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of root. Was ZDI-CAN-9649. | 1% Низкий | больше 4 лет назад | ||
GHSA-22qf-62f9-pj62 As a part of Tenable’s vulnerability disclosure program, a vulnerability in a Nessus plugin was identified and reported. This vulnerability could allow a malicious actor with sufficient permissions on a scan target to place a binary in a specific filesystem location, and abuse the impacted plugin in order to escalate privileges. | CVSS3: 7.8 | 0% Низкий | больше 2 лет назад | |
GHSA-22q9-m8j5-x7xg cute_png v1.05 was discovered to contain a heap buffer overflow via the cp_make32() function at cute_png.h. | CVSS3: 7.8 | 0% Низкий | почти 2 года назад | |
GHSA-22q9-hqm5-mhmc Cross-Site Scripting in swagger-ui | около 6 лет назад | |||
GHSA-22q9-7cmf-jjxp The LDAP component in Fedora Directory Server 1.0 allow remote attackers to cause a denial of service (crash) via a certain "bad BER sequence" that results in a free of uninitialized memory, as demonstrated using the ProtoVer LDAP test suite. | 2% Низкий | больше 4 лет назад | ||
GHSA-22q8-rwx9-62gg A vulnerability was found in Campcodes Legal Case Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /admin/court-type. The manipulation of the argument court_name leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263805 was assigned to this vulnerability. | CVSS3: 3.5 | 1% Низкий | больше 2 лет назад | |
GHSA-22q8-ghmq-63vf libgit2-sys affected by memory corruption, denial of service, and arbitrary code execution in libgit2 | CVSS3: 8.6 | больше 2 лет назад | ||
GHSA-22q7-qw7f-w974 Norton Password Manager, prior to 6.6.2.5, may be susceptible to an information disclosure issue, which is a type of vulnerability whereby there is an unintentional disclosure of information to an actor that is not explicitly authorized to have access to that information. | 1% Низкий | больше 4 лет назад | ||
GHSA-22q7-cg4r-p9mx TYPO3 Cross-Site Scripting in Fluid ViewHelpers | CVSS3: 6.1 | больше 2 лет назад | ||
GHSA-22q7-8jfc-2936 Vulnerability in the Helidon product of Oracle Fusion Middleware (component: helidon-webserver). Supported versions that are affected are 4.0.0-4.5.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Helidon. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Helidon. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). | CVSS3: 7.5 | 0% Низкий | 2 дня назад | |
GHSA-22q6-wwq7-2jj9 OpenStack Keystone Improper Authentication vulnerability | CVSS3: 5.3 | 3% Низкий | больше 4 лет назад | |
GHSA-22q6-rw64-5gjj Zoho ManageEngine ADManager Plus before 7183 allows admin users to exploit an XXE issue to view files. | CVSS3: 4.9 | 3% Низкий | около 3 лет назад | |
GHSA-22q6-hvj2-jgmw IBM InfoSphere Information Server 11.3, 11.5, and 11.7 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 150905. | CVSS3: 7.1 | 2% Низкий | больше 4 лет назад | |
GHSA-22q6-9rvj-cmpf Buffer Overflow in Emerson GE Automation Proficy Machine Edition v8.0 allows an attacker to cause a denial of service and application crash via crafted traffic from a Man-in-the-Middle (MITM) attack to the component "FrameworX.exe" in the module "MSVCR100.dll". | 1% Низкий | больше 4 лет назад | ||
GHSA-22q6-7m3g-6r77 An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution. | CVSS3: 9.1 | 2% Низкий | около 2 лет назад | |
GHSA-22q5-qg84-2p5f Unspecified vulnerability in the OCI component in Oracle Database Server 10.2.0.3, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect confidentiality and integrity via unknown vectors. | 1% Низкий | больше 4 лет назад | ||
GHSA-22q5-9phm-744v XWiki allows unregistered users to access private pages information through REST endpoint | 1% Низкий | больше 1 года назад | ||
GHSA-22q5-57p4-rxcv Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The web application improperly protects credentials which could allow an attacker to obtain credentials for remote access to controllers. | CVSS3: 9.8 | 2% Низкий | больше 4 лет назад |
Уязвимостей на страницу