Количество 323 571
Количество 323 571
GHSA-xpxr-6mr7-m8w3
RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via a crafted sample size in a RealAudio file.
GHSA-xpxq-j6pj-5vxg
The RightFax web client uses predictable session numbers, which allows remote attackers to hijack user sessions.
GHSA-xpxq-cp94-87j2
A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations.
GHSA-xpxq-44xv-wmh3
A security flaw has been discovered in Portabilis i-Diario up to 1.5.0. Affected by this vulnerability is an unknown functionality of the file /password/email of the component Password Recovery Endpoint. The manipulation results in observable response discrepancy. It is possible to launch the attack remotely. This attack is characterized by high complexity. The exploitation appears to be difficult. The exploit has been released to the public and may be exploited.
GHSA-xpxq-36mx-cwhx
An issue was discovered in OXID eShop Enterprise Edition before 5.3.8, 6.0.x before 6.0.3, and 6.1.x before 6.1.0; Professional Edition before 4.10.8, 5.x and 6.0.x before 6.0.3, and 6.1.x before 6.1.0; and Community Edition before 4.10.8, 5.x and 6.0.x before 6.0.3, and 6.1.x before 6.1.0. An attacker could gain access to the admin panel or a customer account when using the password reset function. To do so, it is required to own a domain name similar to the one the victim uses for their e-mail accounts.
GHSA-xpxp-v33m-5jp9
phpMyAdmin Unsafe Fetching of Javascript Code
GHSA-xpxp-r8hf-wgf6
WSO2 products vulnerable to Cross-site Scripting
GHSA-xpxm-pf7g-2534
Cross-site scripting in media2click
GHSA-xpxm-j39p-5vcw
Vulnerability in gpm in Caldera Linux allows local users to delete arbitrary files or conduct a denial of service.
GHSA-xpxm-gwv9-2g2q
WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1.
GHSA-xpxm-9vvw-pjc3
There is a denial of service (DoS) vulnerability in eCNS280 versions V100R005C00, V100R005C10. Due to a design defect, remote unauthorized attackers send a large number of specific messages to affected devices, causing system resource exhaustion and web application DoS.
GHSA-xpxj-fcm9-9v47
Missing Authorization vulnerability in Adnan Analytify allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Analytify: from n/a through 5.5.1.
GHSA-xpxj-28xv-5xh7
Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the oname and oname2 parameters.
GHSA-xpxh-fh9m-hf5v
SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated TGA file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation.
GHSA-xpxg-5vmj-vx9g
Thunderbird allowed the Text Direction Override Unicode Character in filenames. An email attachment could be incorrectly shown as being a document file, while in fact it was an executable file. Newer versions of Thunderbird will strip the character and show the correct file extension. This vulnerability affects Thunderbird < 115.0.1.
GHSA-xpxf-p5mx-cq4f
It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a potential man-in-the-middle attack.
GHSA-xpxf-4p9g-j69p
The SearchIQ WordPress plugin before 3.9 contains a flag to disable the verification of CSRF nonces, granting unauthenticated attackers access to the siq_ajax AJAX action and allowing them to perform Cross-Site Scripting attacks due to the lack of sanitisation and escaping in the customCss parameter
GHSA-xpxc-7j8q-3794
Microsoft Windows 7 SP1 allows an attacker to execute arbitrary code in the context of the current user, due to how Microsoft browsers handle objects in memory, aka "Windows Shell Remote Code Execution Vulnerability".
GHSA-xpx9-f724-2jfc
Vulnerability in Scriptcase version 9.4.019 that consists of a Cross-Site Scripting (XSS), due to the lack of input validation, affecting the “id_form_msg_title” parameter, among others. This vulnerability could allow a remote user to send a specially crafted URL to a victim and retrieve their credentials.
GHSA-xpx9-9jmc-8j4w
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webvitaly Extra Shortcodes allows Stored XSS.This issue affects Extra Shortcodes: from n/a through 2.2.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xpxr-6mr7-m8w3 RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via a crafted sample size in a RealAudio file. | 2% Низкий | почти 4 года назад | ||
GHSA-xpxq-j6pj-5vxg The RightFax web client uses predictable session numbers, which allows remote attackers to hijack user sessions. | 1% Низкий | почти 4 года назад | ||
GHSA-xpxq-cp94-87j2 A flaw was found in Undertow. Denial of service can be achieved as Undertow server waits for the LAST_CHUNK forever for EJB invocations. | CVSS3: 4.9 | 1% Низкий | больше 3 лет назад | |
GHSA-xpxq-44xv-wmh3 A security flaw has been discovered in Portabilis i-Diario up to 1.5.0. Affected by this vulnerability is an unknown functionality of the file /password/email of the component Password Recovery Endpoint. The manipulation results in observable response discrepancy. It is possible to launch the attack remotely. This attack is characterized by high complexity. The exploitation appears to be difficult. The exploit has been released to the public and may be exploited. | CVSS3: 3.7 | 0% Низкий | 8 месяцев назад | |
GHSA-xpxq-36mx-cwhx An issue was discovered in OXID eShop Enterprise Edition before 5.3.8, 6.0.x before 6.0.3, and 6.1.x before 6.1.0; Professional Edition before 4.10.8, 5.x and 6.0.x before 6.0.3, and 6.1.x before 6.1.0; and Community Edition before 4.10.8, 5.x and 6.0.x before 6.0.3, and 6.1.x before 6.1.0. An attacker could gain access to the admin panel or a customer account when using the password reset function. To do so, it is required to own a domain name similar to the one the victim uses for their e-mail accounts. | CVSS3: 8.1 | 0% Низкий | почти 4 года назад | |
GHSA-xpxp-v33m-5jp9 phpMyAdmin Unsafe Fetching of Javascript Code | 0% Низкий | почти 4 года назад | ||
GHSA-xpxp-r8hf-wgf6 WSO2 products vulnerable to Cross-site Scripting | CVSS3: 5.2 | 0% Низкий | 10 месяцев назад | |
GHSA-xpxm-pf7g-2534 Cross-site scripting in media2click | CVSS3: 6.4 | 0% Низкий | почти 5 лет назад | |
GHSA-xpxm-j39p-5vcw Vulnerability in gpm in Caldera Linux allows local users to delete arbitrary files or conduct a denial of service. | 0% Низкий | почти 4 года назад | ||
GHSA-xpxm-gwv9-2g2q WebKit, as used in Apple iTunes before 10.2 on Windows, allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via vectors related to iTunes Store browsing, a different vulnerability than other CVEs listed in APPLE-SA-2011-03-02-1. | 1% Низкий | почти 4 года назад | ||
GHSA-xpxm-9vvw-pjc3 There is a denial of service (DoS) vulnerability in eCNS280 versions V100R005C00, V100R005C10. Due to a design defect, remote unauthorized attackers send a large number of specific messages to affected devices, causing system resource exhaustion and web application DoS. | CVSS3: 7.5 | 0% Низкий | почти 4 года назад | |
GHSA-xpxj-fcm9-9v47 Missing Authorization vulnerability in Adnan Analytify allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Analytify: from n/a through 5.5.1. | CVSS3: 4.3 | 0% Низкий | около 1 года назад | |
GHSA-xpxj-28xv-5xh7 Nagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the oname and oname2 parameters. | CVSS3: 6.1 | 21% Средний | почти 4 года назад | |
GHSA-xpxh-fh9m-hf5v SAP 3D Visual Enterprise Viewer, version - 9, allows a user to open manipulated TGA file received from untrusted sources which results in crashing of the application and becoming temporarily unavailable until the user restarts the application, this is caused due to Improper Input Validation. | 0% Низкий | почти 4 года назад | ||
GHSA-xpxg-5vmj-vx9g Thunderbird allowed the Text Direction Override Unicode Character in filenames. An email attachment could be incorrectly shown as being a document file, while in fact it was an executable file. Newer versions of Thunderbird will strip the character and show the correct file extension. This vulnerability affects Thunderbird < 115.0.1. | CVSS3: 7.5 | 0% Низкий | больше 2 лет назад | |
GHSA-xpxf-p5mx-cq4f It was found that apt-key in apt, all versions, do not correctly validate gpg keys with the master keyring, leading to a potential man-in-the-middle attack. | CVSS3: 3.7 | 2% Низкий | почти 4 года назад | |
GHSA-xpxf-4p9g-j69p The SearchIQ WordPress plugin before 3.9 contains a flag to disable the verification of CSRF nonces, granting unauthenticated attackers access to the siq_ajax AJAX action and allowing them to perform Cross-Site Scripting attacks due to the lack of sanitisation and escaping in the customCss parameter | CVSS3: 6.1 | 1% Низкий | почти 4 года назад | |
GHSA-xpxc-7j8q-3794 Microsoft Windows 7 SP1 allows an attacker to execute arbitrary code in the context of the current user, due to how Microsoft browsers handle objects in memory, aka "Windows Shell Remote Code Execution Vulnerability". | CVSS3: 7.5 | 26% Средний | почти 4 года назад | |
GHSA-xpx9-f724-2jfc Vulnerability in Scriptcase version 9.4.019 that consists of a Cross-Site Scripting (XSS), due to the lack of input validation, affecting the “id_form_msg_title” parameter, among others. This vulnerability could allow a remote user to send a specially crafted URL to a victim and retrieve their credentials. | CVSS3: 6.3 | 0% Низкий | больше 1 года назад | |
GHSA-xpx9-9jmc-8j4w Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webvitaly Extra Shortcodes allows Stored XSS.This issue affects Extra Shortcodes: from n/a through 2.2. | CVSS3: 6.5 | 0% Низкий | 3 месяца назад |
Уязвимостей на страницу