Количество 359 267
Количество 359 267
GHSA-xh4h-63x5-gr2f
An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis control daemon (chassisd) of Juniper Networks Junos OS on SRX1600, SRX2300 and SRX4300 allows a local attacker with low privileges to cause a complete Denial of Service (DoS). When a specific 'show chassis' CLI command is executed, chassisd crashes and restarts which causes a momentary impact to all traffic until all modules are online again. This issue affects Junos OS on SRX1600, SRX2300 and SRX4300: * 24.4 versions before 24.4R1-S3, 24.4R2. This issue does not affect Junos OS versions before 24.4R1.
GHSA-xh4g-c9p6-5jxg
LibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/app/Http/Controllers/Table/EditPortsController.php
GHSA-xh4g-88qm-9p7r
SmarterTools SmarterMail 16.x through 100.x before 100.0.7803 allows remote code execution.
GHSA-xh4f-v933-c556
FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation).
GHSA-xh4c-c9p9-cjx3
SQL injection vulnerability in products.php in CommodityRentals Trade Manager Script allows remote attackers to execute arbitrary SQL commands via the cid parameter.
GHSA-xh49-j9w7-xf24
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in impleCode Product Catalog Simple plugin <= 1.6.17 versions.
GHSA-xh47-8qgr-7ww7
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface. Additionally, a malicious user could potentially cause interruptions to the availability of the web page.
GHSA-xh47-8887-mw3h
The Synergy Systems & Solutions (SSS) HUSKY RTU 6049-E70, with firmware Versions 5.0 and prior, has a Missing Authentication for Critical Function (CWE-306) vulnerability. The affected product does not require authentication for TELNET access, which may allow an attacker to change configuration or perform other malicious activities.
GHSA-xh46-6cwm-rgh4
The Solution Manager in SAP NetWeaver does not properly restrict access, which allows remote attackers to obtain sensitive information via unspecified vectors.
GHSA-xh45-57vp-7gw8
Cross-site scripting (XSS) vulnerability in the server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1 before IF6, 10.1.1 before IF5, 10.2 before IF7, 10.2.1 before IF4, and 10.2.1.1 before IF4 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter that is not properly handled during use of the Back button.
GHSA-xh44-f8rg-h6h3
The Extended Control List (ECL) feature of the Java Virtual Machine (JVM) in Lotus Notes Client R5 allows malicious web site operators to determine the existence of files on the client by measuring delays in the execution of the getSystemResource method.
GHSA-xh44-8w9g-3p27
McAfee IntruShield Security Management System allows remote authenticated users to access the "Generate Reports" feature and modify alerts by setting the Access option to true, as demonstrated using the (1) fullAccess or (2) fullAccessRight parameter in reports-column-center.jsp, or (3) fullAccess parameter to SystemEvent.jsp.
GHSA-xh44-7m8v-gqg4
A use-of-uninitialized-pointer vulnerability exists in the Forward Open connection_management_entry functionality of EIP Stack Group OpENer development commit 58ee13c. A specially-crafted EtherNet/IP request can lead to use of a null pointer, causing the server to crash. An attacker can send a series of EtherNet/IP requests to trigger this vulnerability.
GHSA-xh43-g2fq-wjrj
Angular SSR has an Open Redirect via X-Forwarded-Prefix
GHSA-xh42-fcvq-34r9
Unbound before 1.9.5 allows an integer overflow in the regional allocator via the ALIGN_UP macro.
GHSA-xh42-8p9x-c4x4
Unspecified vulnerability in dtterm in IBM AIX 5.2 and 5.3 allows local users to execute arbitrary code with root privileges via unspecified vectors.
GHSA-xh3x-wrg7-2m5m
mediaserver in Android 5.x before 5.1.1 LMY48T and 6.0 before 2015-10-01 allows attackers to gain privileges via a crafted application, aka internal bug 19573085, a different vulnerability than CVE-2015-6596.
GHSA-xh3w-v58r-2jxm
Possible out of bounds read due to incorrect validation of incoming buffer length in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile
GHSA-xh3w-9cjp-3cf8
The Data Services Management Console does not sufficiently encode user-controlled inputs, allowing an attacker to inject malicious script. When a targeted victim, who is already logged in, clicks on the compromised link, the injected script gets executed within the scope of victim�s browser. This potentially leads to an impact on confidentiality and integrity. Availability is not impacted.
GHSA-xh3v-6f9j-wxw3
Drupal core Information Disclosure vulnerability
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xh4h-63x5-gr2f An Improper Check for Unusual or Exceptional Conditions vulnerability in the chassis control daemon (chassisd) of Juniper Networks Junos OS on SRX1600, SRX2300 and SRX4300 allows a local attacker with low privileges to cause a complete Denial of Service (DoS). When a specific 'show chassis' CLI command is executed, chassisd crashes and restarts which causes a momentary impact to all traffic until all modules are online again. This issue affects Junos OS on SRX1600, SRX2300 and SRX4300: * 24.4 versions before 24.4R1-S3, 24.4R2. This issue does not affect Junos OS versions before 24.4R1. | CVSS3: 5.5 | 0% Низкий | 4 месяца назад | |
GHSA-xh4g-c9p6-5jxg LibreNMS has a Stored XSS ('Cross-site Scripting') in librenms/app/Http/Controllers/Table/EditPortsController.php | CVSS3: 7.5 | 0% Низкий | почти 2 года назад | |
GHSA-xh4g-88qm-9p7r SmarterTools SmarterMail 16.x through 100.x before 100.0.7803 allows remote code execution. | 2% Низкий | больше 4 лет назад | ||
GHSA-xh4f-v933-c556 FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation). | CVSS3: 7.5 | 1% Низкий | почти 3 года назад | |
GHSA-xh4c-c9p9-cjx3 SQL injection vulnerability in products.php in CommodityRentals Trade Manager Script allows remote attackers to execute arbitrary SQL commands via the cid parameter. | 1% Низкий | больше 4 лет назад | ||
GHSA-xh49-j9w7-xf24 Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in impleCode Product Catalog Simple plugin <= 1.6.17 versions. | CVSS3: 6.1 | 0% Низкий | больше 3 лет назад | |
GHSA-xh47-8qgr-7ww7 A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface. Additionally, a malicious user could potentially cause interruptions to the availability of the web page. | CVSS3: 4.7 | 1% Низкий | больше 3 лет назад | |
GHSA-xh47-8887-mw3h The Synergy Systems & Solutions (SSS) HUSKY RTU 6049-E70, with firmware Versions 5.0 and prior, has a Missing Authentication for Critical Function (CWE-306) vulnerability. The affected product does not require authentication for TELNET access, which may allow an attacker to change configuration or perform other malicious activities. | 1% Низкий | около 4 лет назад | ||
GHSA-xh46-6cwm-rgh4 The Solution Manager in SAP NetWeaver does not properly restrict access, which allows remote attackers to obtain sensitive information via unspecified vectors. | 1% Низкий | больше 4 лет назад | ||
GHSA-xh45-57vp-7gw8 Cross-site scripting (XSS) vulnerability in the server in IBM Cognos Business Intelligence (BI) 8.4.1, 10.1 before IF6, 10.1.1 before IF5, 10.2 before IF7, 10.2.1 before IF4, and 10.2.1.1 before IF4 allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter that is not properly handled during use of the Back button. | 1% Низкий | больше 4 лет назад | ||
GHSA-xh44-f8rg-h6h3 The Extended Control List (ECL) feature of the Java Virtual Machine (JVM) in Lotus Notes Client R5 allows malicious web site operators to determine the existence of files on the client by measuring delays in the execution of the getSystemResource method. | 3% Низкий | больше 4 лет назад | ||
GHSA-xh44-8w9g-3p27 McAfee IntruShield Security Management System allows remote authenticated users to access the "Generate Reports" feature and modify alerts by setting the Access option to true, as demonstrated using the (1) fullAccess or (2) fullAccessRight parameter in reports-column-center.jsp, or (3) fullAccess parameter to SystemEvent.jsp. | 1% Низкий | больше 4 лет назад | ||
GHSA-xh44-7m8v-gqg4 A use-of-uninitialized-pointer vulnerability exists in the Forward Open connection_management_entry functionality of EIP Stack Group OpENer development commit 58ee13c. A specially-crafted EtherNet/IP request can lead to use of a null pointer, causing the server to crash. An attacker can send a series of EtherNet/IP requests to trigger this vulnerability. | CVSS3: 7.5 | 8% Низкий | больше 3 лет назад | |
GHSA-xh43-g2fq-wjrj Angular SSR has an Open Redirect via X-Forwarded-Prefix | 0% Низкий | 6 месяцев назад | ||
GHSA-xh42-fcvq-34r9 Unbound before 1.9.5 allows an integer overflow in the regional allocator via the ALIGN_UP macro. | CVSS3: 9.8 | 2% Низкий | около 4 лет назад | |
GHSA-xh42-8p9x-c4x4 Unspecified vulnerability in dtterm in IBM AIX 5.2 and 5.3 allows local users to execute arbitrary code with root privileges via unspecified vectors. | 0% Низкий | больше 4 лет назад | ||
GHSA-xh3x-wrg7-2m5m mediaserver in Android 5.x before 5.1.1 LMY48T and 6.0 before 2015-10-01 allows attackers to gain privileges via a crafted application, aka internal bug 19573085, a different vulnerability than CVE-2015-6596. | 1% Низкий | больше 4 лет назад | ||
GHSA-xh3w-v58r-2jxm Possible out of bounds read due to incorrect validation of incoming buffer length in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile | CVSS3: 7.1 | 0% Низкий | около 4 лет назад | |
GHSA-xh3w-9cjp-3cf8 The Data Services Management Console does not sufficiently encode user-controlled inputs, allowing an attacker to inject malicious script. When a targeted victim, who is already logged in, clicks on the compromised link, the injected script gets executed within the scope of victim�s browser. This potentially leads to an impact on confidentiality and integrity. Availability is not impacted. | CVSS3: 4.4 | 0% Низкий | больше 1 года назад | |
GHSA-xh3v-6f9j-wxw3 Drupal core Information Disclosure vulnerability | CVSS3: 7.5 | 1% Низкий | около 4 лет назад |
Уязвимостей на страницу