Количество 358 043
Количество 358 043
GHSA-xm2v-8rrw-w9pm
Division by 0 in `Conv2DBackpropInput`
GHSA-xm2v-2mf7-36mm
An issue was discovered in the method push.lite.avtech.com.AvtechLib.GetHttpsResponse in AVTECH EagleEyes Lite 2.0.0, the GetHttpsResponse method transmits sensitive information - including internal server URLs, account IDs, passwords, and device tokens - as plaintext query parameters over HTTPS
GHSA-xm2r-rc6j-6pp4
In the Linux kernel, the following vulnerability has been resolved: powerpc/64s: Fix VAS mm use after free The refcount on mm is dropped before the coprocessor is detached.
GHSA-xm2r-9p7m-8c7h
An information disclosure vulnerability in Webadmin allows an unauthenticated remote attacker to read the device serial number in Sophos Firewall version v18.5 MR2 and older.
GHSA-xm2r-2g3f-xg38
In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-off" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection.
GHSA-xm2q-h8v9-r8j8
An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions may allow an attacker able to intercept and modify a user's captive portal authentication request to inject arbitrary headers via crafted HTTP requests.
GHSA-xm2p-w62m-c2hg
SQL injection vulnerability in info.php in CMS Faethon 2.2.0 Ultimate allows remote attackers to execute arbitrary SQL commands via the item parameter.
GHSA-xm2p-hxq8-xj3q
A Server-Side Request Forgery (SSRF) in pictureproxy.php of ChatGPT commit f9f4bbc allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the urlparameter.
GHSA-xm2p-chx4-g658
Package Managers Configurations Remote Code Execution Vulnerability
GHSA-xm2m-chg4-j873
ColdFusion Server 4.5.1 allows remote attackers to cause a denial of service by making repeated requests to a CFCACHE tagged cache file that is not stored in memory.
GHSA-xm2m-2q6h-22jw
Apache NiFi vulnerable to Code Injection
GHSA-xm2h-xmp5-3q8p
The Radiohead fan (aka nl.jborsje.android.bandnews.radiohead) application 4.6.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
GHSA-xm2g-rgpw-75v4
SQL injection vulnerability in WEB//NEWS 1.4 allows remote attackers to execute arbitrary SQL commands via the (1) wn_userpw parameter to startup.php, (2) cat, (3) id, or (4) stof parameter to news.php, or (5) id parameter to print.php.
GHSA-xm2g-jw84-7vcv
Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
GHSA-xm2f-q4jm-fwpf
In Text Services, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
GHSA-xm2f-jc7r-hmhj
The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 10.1.4, which fix the issue.
GHSA-xm2f-hpv7-49w8
IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote authenticated users to spoof administrator accounts by sending a modified login request over HTTP.
GHSA-xm2c-q8p4-pp7f
FreshService Windows Agent < 2.11.0 and FreshService macOS Agent < 4.2.0 and FreshService Linux Agent < 3.3.0. are vulnerable to Broken integrity checking via the FreshAgent client and scheduled update service.
GHSA-xm2c-mv2p-hffr
Use after free in BrowserTag in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Low)
GHSA-xm28-fw2x-fqv2
Denial of Service in foreman
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xm2v-8rrw-w9pm Division by 0 in `Conv2DBackpropInput` | CVSS3: 2.5 | 0% Низкий | около 5 лет назад | |
GHSA-xm2v-2mf7-36mm An issue was discovered in the method push.lite.avtech.com.AvtechLib.GetHttpsResponse in AVTECH EagleEyes Lite 2.0.0, the GetHttpsResponse method transmits sensitive information - including internal server URLs, account IDs, passwords, and device tokens - as plaintext query parameters over HTTPS | CVSS3: 8.8 | 0% Низкий | 11 месяцев назад | |
GHSA-xm2r-rc6j-6pp4 In the Linux kernel, the following vulnerability has been resolved: powerpc/64s: Fix VAS mm use after free The refcount on mm is dropped before the coprocessor is detached. | CVSS3: 7.8 | 0% Низкий | 8 месяцев назад | |
GHSA-xm2r-9p7m-8c7h An information disclosure vulnerability in Webadmin allows an unauthenticated remote attacker to read the device serial number in Sophos Firewall version v18.5 MR2 and older. | CVSS3: 5.3 | 1% Низкий | больше 4 лет назад | |
GHSA-xm2r-2g3f-xg38 In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-off" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection. | CVSS3: 9.8 | 3% Низкий | около 4 лет назад | |
GHSA-xm2q-h8v9-r8j8 An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions may allow an attacker able to intercept and modify a user's captive portal authentication request to inject arbitrary headers via crafted HTTP requests. | CVSS3: 3.1 | 0% Низкий | около 1 месяца назад | |
GHSA-xm2p-w62m-c2hg SQL injection vulnerability in info.php in CMS Faethon 2.2.0 Ultimate allows remote attackers to execute arbitrary SQL commands via the item parameter. | 2% Низкий | больше 4 лет назад | ||
GHSA-xm2p-hxq8-xj3q A Server-Side Request Forgery (SSRF) in pictureproxy.php of ChatGPT commit f9f4bbc allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the urlparameter. | CVSS3: 6.5 | 41% Средний | больше 2 лет назад | |
GHSA-xm2p-chx4-g658 Package Managers Configurations Remote Code Execution Vulnerability | CVSS3: 8.4 | 2% Низкий | около 4 лет назад | |
GHSA-xm2m-chg4-j873 ColdFusion Server 4.5.1 allows remote attackers to cause a denial of service by making repeated requests to a CFCACHE tagged cache file that is not stored in memory. | 1% Низкий | больше 4 лет назад | ||
GHSA-xm2m-2q6h-22jw Apache NiFi vulnerable to Code Injection | CVSS3: 8.8 | 64% Средний | около 3 лет назад | |
GHSA-xm2h-xmp5-3q8p The Radiohead fan (aka nl.jborsje.android.bandnews.radiohead) application 4.6.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | 0% Низкий | около 4 лет назад | ||
GHSA-xm2g-rgpw-75v4 SQL injection vulnerability in WEB//NEWS 1.4 allows remote attackers to execute arbitrary SQL commands via the (1) wn_userpw parameter to startup.php, (2) cat, (3) id, or (4) stof parameter to news.php, or (5) id parameter to print.php. | 1% Низкий | больше 4 лет назад | ||
GHSA-xm2g-jw84-7vcv Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. | 60% Средний | около 4 лет назад | ||
GHSA-xm2f-q4jm-fwpf In Text Services, there is a possible way to determine whether an app is installed, without query permissions, due to side channel information disclosure. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. | CVSS3: 5.5 | 0% Низкий | почти 3 года назад | |
GHSA-xm2f-jc7r-hmhj The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 10.1.4, which fix the issue. | CVSS3: 8.1 | 1% Низкий | 16 дней назад | |
GHSA-xm2f-hpv7-49w8 IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote authenticated users to spoof administrator accounts by sending a modified login request over HTTP. | CVSS3: 8.8 | 2% Низкий | около 4 лет назад | |
GHSA-xm2c-q8p4-pp7f FreshService Windows Agent < 2.11.0 and FreshService macOS Agent < 4.2.0 and FreshService Linux Agent < 3.3.0. are vulnerable to Broken integrity checking via the FreshAgent client and scheduled update service. | CVSS3: 8.1 | 0% Низкий | почти 4 года назад | |
GHSA-xm2c-mv2p-hffr Use after free in BrowserTag in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: Low) | CVSS3: 8.8 | 0% Низкий | около 1 месяца назад | |
GHSA-xm28-fw2x-fqv2 Denial of Service in foreman | CVSS3: 7.5 | около 7 лет назад |
Уязвимостей на страницу