Количество 359 267
Количество 359 267
GHSA-xgxr-qjxv-x6mv
Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Apache Tomcat.
GHSA-xgxr-7w9r-3m55
The zx-csv-upload plugin 1 for WordPress has SQL injection via the id parameter.
GHSA-xgxr-3384-47xm
A memory leak in the EFR32 Bluetooth LE stack 5.1.0 through 5.1.1 allows an attacker to send an invalid pairing message and cause future legitimate connection attempts to fail. A reset of the device immediately clears the error.
GHSA-xgxp-wxpw-r9x6
mount in util-linux 2.19 and earlier does not remove the /etc/mtab.tmp file after a failed attempt to add a mount entry, which allows local users to trigger corruption of the /etc/mtab file via multiple invocations.
GHSA-xgxp-f695-6vrp
In Soft Serve, an authenticated repo import can clone server-local private repositories
GHSA-xgxp-cc5r-jfjq
An issue was discovered in Stormshield SNS through 4.2.1. A brute-force attack can occur.
GHSA-xgxp-9x8p-gcw4
SQL Injection
GHSA-xgxp-5498-vvcw
Improper input validation in Microsoft PowerShell allows an authorized attacker to elevate privileges locally.
GHSA-xgxj-j98c-59rv
Mattermost fails to properly restrict the access of files attached to posts
GHSA-xgxj-cfph-mm49
** DISPUTED ** A vulnerability was found in whohas. It has been rated as problematic. This issue affects some unknown processing of the component Package Information Handler. The manipulation leads to cleartext transmission of sensitive information. The attack may be initiated remotely. The real existence of this vulnerability is still doubted at the moment. The name of the patch is 667c3e2e9178f15c23d7918b5db25cd0792c8472. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-216251. NOTE: Most sources redirect to the encrypted site which limits the possibilities of an attack.
GHSA-xgxh-897r-pw22
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, an authenticated user could run risky commands using the permissions of a higher-privileged user to bypass SPL safeguards for risky commands in the Analytics Workspace. The vulnerability requires the authenticated user to phish the victim by tricking them into initiating a request within their browser. The authenticated user should not be able to exploit the vulnerability at will.
GHSA-xgxg-vmfc-h42h
A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The BMP_Loader.dll library in affected applications lacks proper validation of user-supplied data when parsing BMP files. A malformed input file could result in double free of an allocated buffer that leads to a crash. An attacker could leverage this vulnerability to cause denial of service condition. (CNVD-C-2021-79295)
GHSA-xgxg-r58g-f7pr
Mutiny Standard before 4.5-1.12 allows remote attackers to execute arbitrary commands via the network-interface menu, related to a "command injection vulnerability."
GHSA-xgxg-m2p7-6pr3
An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows unauthenticated attackers to download log files and configuration data.
GHSA-xgxg-434x-64m4
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device. For more information about these vulnerabilities, see the Details section of this advisory.
GHSA-xgxg-3wg9-5qvg
The NHI card’s web service component has a stack-based buffer overflow vulnerability due to insufficient validation for network packet key parameter. A LAN attacker with general user privilege can exploit this vulnerability to disrupt service.
GHSA-xgxf-923g-4wjc
A vulnerability, which was classified as critical, has been found in ESAFENET CDG 5. Affected by this issue is some unknown functionality of the file /com/esafenet/servlet/policy/HookWhiteListService.java. The manipulation of the argument policyId leads to sql injection. The attack may be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way.
GHSA-xgxc-v2qg-chmh
Directory Traversal in Django
GHSA-xgxc-m69w-gg4w
Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Platform Security for Java. While the vulnerability is in Oracle Platform Security for Java, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
GHSA-xgxc-757p-24w9
Emerson OpenEnterprise versions through 3.3.4 may allow an attacker to run an arbitrary commands with system privileges or perform remote code execution via a specific communication service.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
GHSA-xgxr-qjxv-x6mv Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Apache Tomcat. | CVSS3: 7.3 | 1% Низкий | больше 4 лет назад | |
GHSA-xgxr-7w9r-3m55 The zx-csv-upload plugin 1 for WordPress has SQL injection via the id parameter. | 2% Низкий | около 4 лет назад | ||
GHSA-xgxr-3384-47xm A memory leak in the EFR32 Bluetooth LE stack 5.1.0 through 5.1.1 allows an attacker to send an invalid pairing message and cause future legitimate connection attempts to fail. A reset of the device immediately clears the error. | CVSS3: 5.3 | 0% Низкий | около 3 лет назад | |
GHSA-xgxp-wxpw-r9x6 mount in util-linux 2.19 and earlier does not remove the /etc/mtab.tmp file after a failed attempt to add a mount entry, which allows local users to trigger corruption of the /etc/mtab file via multiple invocations. | 0% Низкий | больше 4 лет назад | ||
GHSA-xgxp-f695-6vrp In Soft Serve, an authenticated repo import can clone server-local private repositories | 0% Низкий | 5 месяцев назад | ||
GHSA-xgxp-cc5r-jfjq An issue was discovered in Stormshield SNS through 4.2.1. A brute-force attack can occur. | 1% Низкий | около 4 лет назад | ||
GHSA-xgxp-9x8p-gcw4 SQL Injection | CVSS3: 8.8 | 46% Средний | больше 4 лет назад | |
GHSA-xgxp-5498-vvcw Improper input validation in Microsoft PowerShell allows an authorized attacker to elevate privileges locally. | CVSS3: 7.8 | 0% Низкий | 4 месяца назад | |
GHSA-xgxj-j98c-59rv Mattermost fails to properly restrict the access of files attached to posts | CVSS3: 3.1 | 0% Низкий | больше 2 лет назад | |
GHSA-xgxj-cfph-mm49 ** DISPUTED ** A vulnerability was found in whohas. It has been rated as problematic. This issue affects some unknown processing of the component Package Information Handler. The manipulation leads to cleartext transmission of sensitive information. The attack may be initiated remotely. The real existence of this vulnerability is still doubted at the moment. The name of the patch is 667c3e2e9178f15c23d7918b5db25cd0792c8472. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-216251. NOTE: Most sources redirect to the encrypted site which limits the possibilities of an attack. | CVSS3: 7.5 | 0% Низкий | больше 3 лет назад | |
GHSA-xgxh-897r-pw22 In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.200 and 9.1.2308.207, an authenticated user could run risky commands using the permissions of a higher-privileged user to bypass SPL safeguards for risky commands in the Analytics Workspace. The vulnerability requires the authenticated user to phish the victim by tricking them into initiating a request within their browser. The authenticated user should not be able to exploit the vulnerability at will. | CVSS3: 6.3 | 0% Низкий | около 2 лет назад | |
GHSA-xgxg-vmfc-h42h A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The BMP_Loader.dll library in affected applications lacks proper validation of user-supplied data when parsing BMP files. A malformed input file could result in double free of an allocated buffer that leads to a crash. An attacker could leverage this vulnerability to cause denial of service condition. (CNVD-C-2021-79295) | 1% Низкий | около 4 лет назад | ||
GHSA-xgxg-r58g-f7pr Mutiny Standard before 4.5-1.12 allows remote attackers to execute arbitrary commands via the network-interface menu, related to a "command injection vulnerability." | 27% Средний | больше 4 лет назад | ||
GHSA-xgxg-m2p7-6pr3 An access control issue in Wavlink WN530HG4 M30HG4.V5030.191116 allows unauthenticated attackers to download log files and configuration data. | CVSS3: 5.3 | 3% Низкий | около 4 лет назад | |
GHSA-xgxg-434x-64m4 Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit these vulnerabilities, an attacker must have valid credentials on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. | CVSS3: 6.5 | 1% Низкий | около 3 лет назад | |
GHSA-xgxg-3wg9-5qvg The NHI card’s web service component has a stack-based buffer overflow vulnerability due to insufficient validation for network packet key parameter. A LAN attacker with general user privilege can exploit this vulnerability to disrupt service. | CVSS3: 5.5 | 0% Низкий | около 4 лет назад | |
GHSA-xgxf-923g-4wjc A vulnerability, which was classified as critical, has been found in ESAFENET CDG 5. Affected by this issue is some unknown functionality of the file /com/esafenet/servlet/policy/HookWhiteListService.java. The manipulation of the argument policyId leads to sql injection. The attack may be launched remotely. The vendor was contacted early about this disclosure but did not respond in any way. | CVSS3: 6.3 | 1% Низкий | почти 2 года назад | |
GHSA-xgxc-v2qg-chmh Directory Traversal in Django | CVSS3: 5.3 | 4% Низкий | больше 5 лет назад | |
GHSA-xgxc-m69w-gg4w Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Platform Security for Java. While the vulnerability is in Oracle Platform Security for Java, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Platform Security for Java. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). | CVSS3: 9.9 | 0% Низкий | 26 дней назад | |
GHSA-xgxc-757p-24w9 Emerson OpenEnterprise versions through 3.3.4 may allow an attacker to run an arbitrary commands with system privileges or perform remote code execution via a specific communication service. | 3% Низкий | больше 4 лет назад |
Уязвимостей на страницу