Количество 359 154
Количество 359 154
GHSA-xhp5-pvv6-r659
Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
GHSA-xhp4-6g9v-4xvj
setDeferredReply in networking.c in Valkey through 8.1.1 has an integer underflow for prev->size - prev->used.
GHSA-xhp3-g75g-8f9j
An attacker with non-administrative authorizations in SAP NetWeaver (BI CONT ADD ON) - versions 707, 737, 747, 757, can exploit a directory traversal flaw to over-write system files. Data from confidential files cannot be read but potentially some OS files can be over-written leading to system compromise.
GHSA-xhp2-qq28-gm5m
In J2 Innovations FIN Stack 4.0, the authentication webform is vulnerable to reflected XSS via the query string to /login.
GHSA-xhmx-mwfm-vrhx
includes/bootstrap.inc in Drupal 5.x before 5.12 and 6.x before 6.6, when the server is configured for "IP-based virtual hosts," allows remote attackers to include and execute arbitrary files via the HTTP Host header.
GHSA-xhmx-jv3j-5wf8
Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero.
GHSA-xhmx-j9vh-76xp
Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.49.31, 8.50.20, and 8.51.11 allows remote authenticated users to affect integrity via unknown vectors, a different vulnerability than CVE-2011-2274.
GHSA-xhmx-2vhp-f3pq
In USB driver, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-216825460References: Upstream kernel
GHSA-xhmw-wmwj-jvwr
Cross-Site Request Forgery (CSRF) vulnerability in ThemeinProgress WIP Custom Login plugin <= 1.2.9 versions.
GHSA-xhmw-j639-ph2m
A crafted NTFS image can cause an out-of-bounds access in ntfs_decompress in NTFS-3G < 2021.8.22.
GHSA-xhmw-hwm7-v657
In the Linux kernel, the following vulnerability has been resolved: gfs2: Always check inode size of inline inodes Check if the inode size of stuffed (inline) inodes is within the allowed range when reading inodes from disk (gfs2_dinode_in()). This prevents us from on-disk corruption. The two checks in stuffed_readpage() and gfs2_unstuffer_page() that just truncate inline data to the maximum allowed size don't actually make sense, and they can be removed now as well.
GHSA-xhmw-9xf2-ph22
Winston 1.5.4 devices do not enforce authorization. This is exploitable from the intranet, and can be combined with other vulnerabilities for remote exploitation.
GHSA-xhmv-px8h-fmgp
Emlog Pro v2.1.14 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/article.php?action=write.
GHSA-xhmv-mw7v-7gv2
Memory corruption when the channel ID passed by user is not validated and further used.
GHSA-xhmv-gf55-q7fw
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused
GHSA-xhmv-f9rq-3vrg
D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at genacgi_main.
GHSA-xhmr-rh9j-mc27
A vulnerability was identified in itsourcecode Online Cake Ordering System 1.0. The affected element is an unknown function of the file /updateproduct.php?action=edit. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
GHSA-xhmr-m6c6-4xcf
13enforme CMS 1.0 has Cross Site Scripting via the "content.php" id parameter.
GHSA-xhmr-j39f-mv9p
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability.
GHSA-xhmp-rwc3-2j56
A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xhp5-pvv6-r659 Multiple vulnerabilities in the REST API of Cisco UCS Director and Cisco UCS Director Express for Big Data may allow a remote attacker to bypass authentication or conduct directory traversal attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. | 39% Средний | около 4 лет назад | ||
GHSA-xhp4-6g9v-4xvj setDeferredReply in networking.c in Valkey through 8.1.1 has an integer underflow for prev->size - prev->used. | CVSS3: 3.1 | 0% Низкий | около 1 года назад | |
GHSA-xhp3-g75g-8f9j An attacker with non-administrative authorizations in SAP NetWeaver (BI CONT ADD ON) - versions 707, 737, 747, 757, can exploit a directory traversal flaw to over-write system files. Data from confidential files cannot be read but potentially some OS files can be over-written leading to system compromise. | CVSS3: 8.7 | 1% Низкий | около 3 лет назад | |
GHSA-xhp2-qq28-gm5m In J2 Innovations FIN Stack 4.0, the authentication webform is vulnerable to reflected XSS via the query string to /login. | CVSS3: 6.1 | 1% Низкий | больше 4 лет назад | |
GHSA-xhmx-mwfm-vrhx includes/bootstrap.inc in Drupal 5.x before 5.12 and 6.x before 6.6, when the server is configured for "IP-based virtual hosts," allows remote attackers to include and execute arbitrary files via the HTTP Host header. | 4% Низкий | около 4 лет назад | ||
GHSA-xhmx-jv3j-5wf8 Transient DOS while parsing the MBSSID IE from the beacons, when the MBSSID IE length is zero. | CVSS3: 7.5 | 0% Низкий | около 2 лет назад | |
GHSA-xhmx-j9vh-76xp Unspecified vulnerability in the PeopleSoft Enterprise PeopleTools component in Oracle PeopleSoft Products 8.49.31, 8.50.20, and 8.51.11 allows remote authenticated users to affect integrity via unknown vectors, a different vulnerability than CVE-2011-2274. | 1% Низкий | около 4 лет назад | ||
GHSA-xhmx-2vhp-f3pq In USB driver, there is a possible out of bounds read due to a heap buffer overflow. This could lead to local information disclosure with User execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-216825460References: Upstream kernel | CVSS3: 5.5 | 0% Низкий | около 4 лет назад | |
GHSA-xhmw-wmwj-jvwr Cross-Site Request Forgery (CSRF) vulnerability in ThemeinProgress WIP Custom Login plugin <= 1.2.9 versions. | CVSS3: 4.3 | 0% Низкий | около 3 лет назад | |
GHSA-xhmw-j639-ph2m A crafted NTFS image can cause an out-of-bounds access in ntfs_decompress in NTFS-3G < 2021.8.22. | CVSS3: 7.8 | 0% Низкий | около 4 лет назад | |
GHSA-xhmw-hwm7-v657 In the Linux kernel, the following vulnerability has been resolved: gfs2: Always check inode size of inline inodes Check if the inode size of stuffed (inline) inodes is within the allowed range when reading inodes from disk (gfs2_dinode_in()). This prevents us from on-disk corruption. The two checks in stuffed_readpage() and gfs2_unstuffer_page() that just truncate inline data to the maximum allowed size don't actually make sense, and they can be removed now as well. | CVSS3: 5.5 | 0% Низкий | больше 1 года назад | |
GHSA-xhmw-9xf2-ph22 Winston 1.5.4 devices do not enforce authorization. This is exploitable from the intranet, and can be combined with other vulnerabilities for remote exploitation. | 1% Низкий | около 4 лет назад | ||
GHSA-xhmv-px8h-fmgp Emlog Pro v2.1.14 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /admin/article.php?action=write. | CVSS3: 6.1 | 0% Низкий | больше 2 лет назад | |
GHSA-xhmv-mw7v-7gv2 Memory corruption when the channel ID passed by user is not validated and further used. | CVSS3: 7.8 | 0% Низкий | больше 2 лет назад | |
GHSA-xhmv-gf55-q7fw Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority because it is Unused | около 1 года назад | |||
GHSA-xhmv-f9rq-3vrg D-Link Go-RT-AC750 revA_v101b03 was discovered to contain a command injection vulnerability via the service parameter at genacgi_main. | CVSS3: 9.8 | 29% Средний | около 3 лет назад | |
GHSA-xhmr-rh9j-mc27 A vulnerability was identified in itsourcecode Online Cake Ordering System 1.0. The affected element is an unknown function of the file /updateproduct.php?action=edit. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit is publicly available and might be used. | CVSS3: 7.3 | 0% Низкий | 8 месяцев назад | |
GHSA-xhmr-m6c6-4xcf 13enforme CMS 1.0 has Cross Site Scripting via the "content.php" id parameter. | 1% Низкий | около 4 лет назад | ||
GHSA-xhmr-j39f-mv9p Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability. | CVSS3: 7.8 | 4% Низкий | больше 4 лет назад | |
GHSA-xhmp-rwc3-2j56 A privilege escalation vulnerability in the init-script for user-applications allows a low-privileged local user to execute arbitrary commands as root, resulting in full system compromise. | CVSS3: 7.8 | 0% Низкий | 17 дней назад |
Уязвимостей на страницу