Количество 357 575
Количество 357 575
GHSA-xmc6-5pwj-wqwj
The Tightrope Media Carousel Seneca HDn Windows-based appliance 7.0.4.104 is shipped with a default local administrator username and password. This can be found by a limited user account in an "unattend.xml" file left over on the C: drive from the Sysprep process. An attacker with this username and password can leverage it to gain administrator-level access on the system.
GHSA-xmc5-7cww-2h26
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could allow a remote code execution when a file is saved. Affected Product: C-Bus Toolkit (V1.15.9 and prior), C-Gate Server (V2.11.7 and prior)
GHSA-xmc5-26p9-v4x6
WebExtensions could use the "mozAddonManager" API by modifying the CSP headers on sites with the appropriate permissions and then using host requests to redirect script loads to a malicious site. This allows a malicious extension to then install additional extensions without explicit user permission. This vulnerability affects Firefox < 51.
GHSA-xmc4-vj3p-mc7g
accounts/ValidateAnswers in the security-questions implementation in ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 makes it easier for remote attackers to reset user passwords, and consequently obtain access to arbitrary user accounts, via a modified (1) Hide_Captcha or (2) quesList parameter in a validateAll action.
GHSA-xmc4-rjq5-7xw2
The CoreGraphics component in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2015-5925.
GHSA-xmc3-9m9j-w9x4
cocagne pysrp vulnerable to side channel leaks
GHSA-xmc3-8wf5-r59w
Memory corruption in Boot while running a ListVars test in UEFI Menu during boot.
GHSA-xmc2-qrxf-m6gc
The vips-7.22 script in VIPS 7.22.2 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
GHSA-xmc2-ppwc-cgqq
Microsoft Internet Explorer 11 and Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2447.
GHSA-xmc2-gfmw-wmhg
Buffer overflow in the (1) oracle and (2) oracleO programs in Oracle 9i Database 9.0.x and 9.2.x before 9.2.0.4 allows local users to execute arbitrary code via a long command line argument.
GHSA-xm9x-vjcf-6hvv
Wi-SUN unexpected 4- Way Handshake packet receptions may lead to predictable keys and potentially leading to Man in the middle (MitM) attack
GHSA-xm9w-v2cj-mwmg
admin/radera/tabort.asp in Hogstorps hogstorp guestbook 2.0 does not verify user credentials, which allows remote attackers to delete arbitrary posts via a modified delID parameter.
GHSA-xm9w-228p-45pp
An issue was discovered on KuWFi GC111 GC111-GL-LM321_V3.0_20191211 devices. The TELNET service is enabled by default and exposed over the WAN interface without authentication.
GHSA-xm9v-wf8j-hjg7
A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 in filter_frame at libavfilter/vf_fieldorder.c, which might lead to memory corruption and other potential consequences.
GHSA-xm9v-fg48-44v7
HCL DRYiCE Optibot Reset Station is impacted by a missing Strict Transport Security Header. This could allow an attacker to intercept or manipulate data during redirection.
GHSA-xm9r-hq6w-wmg8
An out-of-bounds read vulnerability was discovered in linux kernel in the smc protocol stack, causing remote dos.
GHSA-xm9q-wvh7-2637
PostMaster 1.0 in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that contains a long URL.
GHSA-xm9p-q7g6-fm6p
The AcquireDaemonLock function in ipcdUnix.cpp in Sun Innotek VirtualBox before 2.0.6 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/.vbox-$USER-ipc/lock temporary file.
GHSA-xm9p-57xv-vxwc
Stored XSS via TLS peer-certificate DN in stream-management UI (sibling of V-11)
GHSA-xm9m-jhp8-mhhx
The Website LLMs.txt plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xmc6-5pwj-wqwj The Tightrope Media Carousel Seneca HDn Windows-based appliance 7.0.4.104 is shipped with a default local administrator username and password. This can be found by a limited user account in an "unattend.xml" file left over on the C: drive from the Sysprep process. An attacker with this username and password can leverage it to gain administrator-level access on the system. | CVSS3: 8.8 | 1% Низкий | около 4 лет назад | |
GHSA-xmc5-7cww-2h26 A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could allow a remote code execution when a file is saved. Affected Product: C-Bus Toolkit (V1.15.9 and prior), C-Gate Server (V2.11.7 and prior) | 2% Низкий | больше 4 лет назад | ||
GHSA-xmc5-26p9-v4x6 WebExtensions could use the "mozAddonManager" API by modifying the CSP headers on sites with the appropriate permissions and then using host requests to redirect script loads to a malicious site. This allows a malicious extension to then install additional extensions without explicit user permission. This vulnerability affects Firefox < 51. | CVSS3: 6.1 | 1% Низкий | около 4 лет назад | |
GHSA-xmc4-vj3p-mc7g accounts/ValidateAnswers in the security-questions implementation in ZOHO ManageEngine ADSelfService Plus before 4.5 Build 4500 makes it easier for remote attackers to reset user passwords, and consequently obtain access to arbitrary user accounts, via a modified (1) Hide_Captcha or (2) quesList parameter in a validateAll action. | 4% Низкий | около 4 лет назад | ||
GHSA-xmc4-rjq5-7xw2 The CoreGraphics component in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2015-5925. | 2% Низкий | около 4 лет назад | ||
GHSA-xmc3-9m9j-w9x4 cocagne pysrp vulnerable to side channel leaks | CVSS3: 7.5 | 1% Низкий | больше 3 лет назад | |
GHSA-xmc3-8wf5-r59w Memory corruption in Boot while running a ListVars test in UEFI Menu during boot. | CVSS3: 7.8 | 0% Низкий | больше 2 лет назад | |
GHSA-xmc2-qrxf-m6gc The vips-7.22 script in VIPS 7.22.2 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. | 0% Низкий | около 4 лет назад | ||
GHSA-xmc2-ppwc-cgqq Microsoft Internet Explorer 11 and Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," a different vulnerability than CVE-2015-2447. | 16% Средний | около 4 лет назад | ||
GHSA-xmc2-gfmw-wmhg Buffer overflow in the (1) oracle and (2) oracleO programs in Oracle 9i Database 9.0.x and 9.2.x before 9.2.0.4 allows local users to execute arbitrary code via a long command line argument. | 1% Низкий | больше 4 лет назад | ||
GHSA-xm9x-vjcf-6hvv Wi-SUN unexpected 4- Way Handshake packet receptions may lead to predictable keys and potentially leading to Man in the middle (MitM) attack | 0% Низкий | 11 месяцев назад | ||
GHSA-xm9w-v2cj-mwmg admin/radera/tabort.asp in Hogstorps hogstorp guestbook 2.0 does not verify user credentials, which allows remote attackers to delete arbitrary posts via a modified delID parameter. | 3% Низкий | больше 4 лет назад | ||
GHSA-xm9w-228p-45pp An issue was discovered on KuWFi GC111 GC111-GL-LM321_V3.0_20191211 devices. The TELNET service is enabled by default and exposed over the WAN interface without authentication. | CVSS3: 9.8 | 0% Низкий | около 1 года назад | |
GHSA-xm9v-wf8j-hjg7 A heap-based Buffer Overflow vulnerability exists in FFmpeg 4.2 in filter_frame at libavfilter/vf_fieldorder.c, which might lead to memory corruption and other potential consequences. | 2% Низкий | около 4 лет назад | ||
GHSA-xm9v-fg48-44v7 HCL DRYiCE Optibot Reset Station is impacted by a missing Strict Transport Security Header. This could allow an attacker to intercept or manipulate data during redirection. | CVSS3: 3.7 | 0% Низкий | около 2 лет назад | |
GHSA-xm9r-hq6w-wmg8 An out-of-bounds read vulnerability was discovered in linux kernel in the smc protocol stack, causing remote dos. | CVSS3: 7.5 | 1% Низкий | почти 4 года назад | |
GHSA-xm9q-wvh7-2637 PostMaster 1.0 in BeOS r5 pro and earlier allows remote attackers to conduct a denial of service via a message that contains a long URL. | 1% Низкий | больше 4 лет назад | ||
GHSA-xm9p-q7g6-fm6p The AcquireDaemonLock function in ipcdUnix.cpp in Sun Innotek VirtualBox before 2.0.6 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/.vbox-$USER-ipc/lock temporary file. | 0% Низкий | около 4 лет назад | ||
GHSA-xm9p-57xv-vxwc Stored XSS via TLS peer-certificate DN in stream-management UI (sibling of V-11) | 22 дня назад | |||
GHSA-xm9m-jhp8-mhhx The Website LLMs.txt plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 8.2.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled. | CVSS3: 4.4 | 0% Низкий | 4 месяца назад |
Уязвимостей на страницу