Количество 357 575
Количество 357 575
GHSA-xm99-6pv5-q363
Disputed: OS Command injection in github.com/kardianos/service
GHSA-xm98-p8mq-5j7x
Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 12.0.3 allows remote authenticated users to affect confidentiality via vectors related to Accounts.
GHSA-xm98-9qfh-q6g4
Horner Automation Cscape versions prior to 10.2 SP3 are vulnerable to an Out-of-Bounds Read vulnerability through parsing CSP files. Successful exploitation of this vulnerability could allow an attacker to disclose information and execute arbitrary code.
GHSA-xm98-722w-4373
IBM Planning Analytics Local 2.0.9.2 and IBM Planning Analytics Workspace 57 could expose data to non-privleged users by not invalidating TM1Web user sessions. IBM X-Force ID: 186022.
GHSA-xm97-jwxx-3wfh
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.8.2, macOS Sequoia 15.7.2. An app with root privileges may be able to access private information.
GHSA-xm97-9w7x-8vx8
In ncurses 6.0, there is a stack-based buffer overflow in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack.
GHSA-xm97-7rvr-ppc2
Direct static code injection vulnerability in sysinfo.cgi in sysinfo 1.21 and possibly other versions before 2.25 allows remote attackers to execute arbitrary commands via a leading ; (semicolon) in the name parameter in a systemdoc action, which is injected into phpinfo.php.
GHSA-xm97-4p58-pfr9
Multiple use-after-free vulnerabilities in libarchive 2.8.4 and 2.8.5 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted (1) TAR archive or (2) ISO9660 image.
GHSA-xm96-gfjx-jcrc
ORAS Java: Path traversal in pullArtifact via attacker-controlled org.opencontainers.image.title annotation
GHSA-xm95-m7m8-r568
Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: UI Infrastructure). Supported versions that are affected are 6.4.3 and 6.5.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Transportation Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Transportation Management. CVSS 3.1 Base Score 5.4 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L).
GHSA-xm94-xrhg-42m4
SQL injection vulnerability in Infoticketing. This vulnerability allows an unauthenticated attacker to retrieve, create, update, and delete the database by sending a POST request using the 'code' parameter in '/components/cart/cartApplyDiscount.php'.
GHSA-xm94-m277-f852
Invalid pointer in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150.
GHSA-xm94-gcw3-hgpv
The readmsg action in myhome.php in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to read arbitrary messages by modifying the id parameter.
GHSA-xm94-9jw8-p6hw
Insertion of Sensitive Information into Externally-Accessible File or Directory in Jenkins Credentials Plugin
GHSA-xm94-78r5-v85h
Unspecified vulnerability in IBM WebSphere Commerce 6.0 Enterprise before 6.0.0.8, when trace is enabled, allows local users to obtain sensitive information via unknown vectors.
GHSA-xm93-cr5j-3294
PHP remote file inclusion vulnerability in index.php in Knusperleicht Guestbook 3.5 allows remote attackers to execute arbitrary PHP code via a URL in the GB_PATH parameter.
GHSA-xm93-639c-r743
Opera Mini for Android allows attackers to bypass intended restrictions on .apk file download/installation via an RTLO (aka Right to Left Override) approach, as demonstrated by misinterpretation of malicious%E2%80%AEtxt.apk as maliciouskpa.txt. This affects 44.1.2254.142553, 44.1.2254.142659, and 44.1.2254.143214.
GHSA-xm92-v2mq-842q
Apache Struts improper action name cleanup
GHSA-xm92-rf24-h74w
Apache Geronimo Application Server multiple directory traversal vulnerabilities
GHSA-xm92-qf3w-36f3
IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 170964.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xm99-6pv5-q363 Disputed: OS Command injection in github.com/kardianos/service | CVSS3: 7.8 | 0% Низкий | больше 4 лет назад | |
GHSA-xm98-p8mq-5j7x Unspecified vulnerability in the Oracle FLEXCUBE Direct Banking component in Oracle Financial Services Software 12.0.3 allows remote authenticated users to affect confidentiality via vectors related to Accounts. | CVSS3: 5.7 | 1% Низкий | около 4 лет назад | |
GHSA-xm98-9qfh-q6g4 Horner Automation Cscape versions prior to 10.2 SP3 are vulnerable to an Out-of-Bounds Read vulnerability through parsing CSP files. Successful exploitation of this vulnerability could allow an attacker to disclose information and execute arbitrary code. | 0% Низкий | около 2 месяцев назад | ||
GHSA-xm98-722w-4373 IBM Planning Analytics Local 2.0.9.2 and IBM Planning Analytics Workspace 57 could expose data to non-privleged users by not invalidating TM1Web user sessions. IBM X-Force ID: 186022. | 1% Низкий | около 4 лет назад | ||
GHSA-xm97-jwxx-3wfh A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sonoma 14.8.2, macOS Sequoia 15.7.2. An app with root privileges may be able to access private information. | CVSS3: 4.4 | 0% Низкий | 9 месяцев назад | |
GHSA-xm97-9w7x-8vx8 In ncurses 6.0, there is a stack-based buffer overflow in the fmt_entry function. A crafted input will lead to a remote arbitrary code execution attack. | CVSS3: 9.8 | 5% Низкий | больше 4 лет назад | |
GHSA-xm97-7rvr-ppc2 Direct static code injection vulnerability in sysinfo.cgi in sysinfo 1.21 and possibly other versions before 2.25 allows remote attackers to execute arbitrary commands via a leading ; (semicolon) in the name parameter in a systemdoc action, which is injected into phpinfo.php. | 8% Низкий | больше 4 лет назад | ||
GHSA-xm97-4p58-pfr9 Multiple use-after-free vulnerabilities in libarchive 2.8.4 and 2.8.5 allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted (1) TAR archive or (2) ISO9660 image. | 1% Низкий | около 4 лет назад | ||
GHSA-xm96-gfjx-jcrc ORAS Java: Path traversal in pullArtifact via attacker-controlled org.opencontainers.image.title annotation | CVSS3: 8.1 | 3 месяца назад | ||
GHSA-xm95-m7m8-r568 Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: UI Infrastructure). Supported versions that are affected are 6.4.3 and 6.5.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Transportation Management. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Transportation Management accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Transportation Management. CVSS 3.1 Base Score 5.4 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L). | CVSS3: 5.4 | 1% Низкий | почти 4 года назад | |
GHSA-xm94-xrhg-42m4 SQL injection vulnerability in Infoticketing. This vulnerability allows an unauthenticated attacker to retrieve, create, update, and delete the database by sending a POST request using the 'code' parameter in '/components/cart/cartApplyDiscount.php'. | 0% Низкий | 6 месяцев назад | ||
GHSA-xm94-m277-f852 Invalid pointer in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 150. | CVSS3: 5.3 | 0% Низкий | 4 месяца назад | |
GHSA-xm94-gcw3-hgpv The readmsg action in myhome.php in Open Bulletin Board (OpenBB) 1.0.6 and earlier allows remote attackers to read arbitrary messages by modifying the id parameter. | 3% Низкий | больше 4 лет назад | ||
GHSA-xm94-9jw8-p6hw Insertion of Sensitive Information into Externally-Accessible File or Directory in Jenkins Credentials Plugin | CVSS3: 4.3 | 1% Низкий | около 4 лет назад | |
GHSA-xm94-78r5-v85h Unspecified vulnerability in IBM WebSphere Commerce 6.0 Enterprise before 6.0.0.8, when trace is enabled, allows local users to obtain sensitive information via unknown vectors. | 0% Низкий | больше 4 лет назад | ||
GHSA-xm93-cr5j-3294 PHP remote file inclusion vulnerability in index.php in Knusperleicht Guestbook 3.5 allows remote attackers to execute arbitrary PHP code via a URL in the GB_PATH parameter. | 3% Низкий | больше 4 лет назад | ||
GHSA-xm93-639c-r743 Opera Mini for Android allows attackers to bypass intended restrictions on .apk file download/installation via an RTLO (aka Right to Left Override) approach, as demonstrated by misinterpretation of malicious%E2%80%AEtxt.apk as maliciouskpa.txt. This affects 44.1.2254.142553, 44.1.2254.142659, and 44.1.2254.143214. | 1% Низкий | около 4 лет назад | ||
GHSA-xm92-v2mq-842q Apache Struts improper action name cleanup | CVSS3: 9.8 | 7% Низкий | около 4 лет назад | |
GHSA-xm92-rf24-h74w Apache Geronimo Application Server multiple directory traversal vulnerabilities | 36% Средний | около 4 лет назад | ||
GHSA-xm92-qf3w-36f3 IBM Cognos Analytics 11.0 and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 170964. | 1% Низкий | около 4 лет назад |
Уязвимостей на страницу