CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
Airmagnet_enterprise, Cdm_agent_firmware_maintenance_release, Ngenius_client, Ngenius_express_appliance, Ngenius_flow_recorder, Ngenius_infinistream, Ngeniusone, Ngenius_performance_manager, Ngenius_probes, Ngenius_trace_analyzer_integrator
2021-10-04
N/A
6.5 MEDIUM
NEI in NETSCOUT nGeniusONE 6.3.0 build 1196 allows XML External Entity (XXE) attacks.
Airmagnet_enterprise, Cdm_agent_firmware_maintenance_release, Ngenius_client, Ngenius_express_appliance, Ngenius_flow_recorder, Ngenius_infinistream, Ngeniusone, Ngenius_performance_manager, Ngenius_probes, Ngenius_trace_analyzer_integrator
2021-10-04
N/A
4.8 MEDIUM
NETSCOUT nGeniusONE 6.3.0 build 1196 allows high-privileged users to achieve Stored Cross-Site Scripting (XSS) in FDSQueryService.
There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. The greatest impact of this flaw is to availability, with some potential impact to confidentiality and integrity as well.
Airmagnet_enterprise, Cdm_agent_firmware_maintenance_release, Ngenius_client, Ngenius_express_appliance, Ngenius_flow_recorder, Ngenius_infinistream, Ngeniusone, Ngenius_performance_manager, Ngenius_probes, Ngenius_trace_analyzer_integrator
2021-10-04
N/A
5.4 MEDIUM
NETSCOUT nGeniusONE 6.3.0 build 1196 and earlier allows Stored Cross-Site Scripting (XSS) in UploadFile.
Airmagnet_enterprise, Cdm_agent_firmware_maintenance_release, Ngenius_client, Ngenius_express_appliance, Ngenius_flow_recorder, Ngenius_infinistream, Ngeniusone, Ngenius_performance_manager, Ngenius_probes, Ngenius_trace_analyzer_integrator
2021-10-04
N/A
5.4 MEDIUM
NETSCOUT nGeniusONE 6.3.0 build 1004 and earlier allows Stored Cross-Site Scripting (XSS) in the Packet Analysis module.
In MediaWiki before 1.31.15, 1.32.x through 1.35.x before 1.35.3, and 1.36.x before 1.36.1, bots have certain unintended API access. When a bot account has a "sitewide block" applied, it is able to still "purge" pages through the MediaWiki Action API (which a "sitewide block" should have prevented).
** DISPUTED ** Manuskript through 0.12.0 allows remote attackers to execute arbitrary code via a crafted settings.pickle file in a project file, because there is insecure deserialization via the pickle.load() function in settings.py. NOTE: the vendor's position is that the product is not intended for opening an untrusted project file.
Patterson Application Service in Patterson Eaglesoft 18 through 21 accepts the same certificate authentication across different customers' installations (that have the same software version). This provides remote access to SQL database credentials. (In the normal use of the product, retrieving those credentials only occurs after a username/password authentication step; however, this authentication step is on the client side, and an attacker can develop their own client that skips this step.)
Legion_y520t_z370_firmware, Legion_y520t_z370, Aio310-20iap_firmware, Aio310-20iap, Aio510-22ish_firmware, Aio510-22ish, Aio510-23ish_firmware, Aio510-23ish, Aio520-22ikl_firmware, Aio520-22ikl
2021-11-19
N/A
6.8 MEDIUM
A vulnerability was reported in some Lenovo Desktop models that could allow unauthorized access to the boot menu, when the "BIOS Password At Boot Device List" BIOS setting is Yes.
Jboss_core_services, Enterprise_linux, Jboss_enterprise_application_platform, Enterprise_linux_server, Jboss_amq_clients_2, Openstack, Virtualization, Virtualization_host, Single_sign-on, Openshift_container_platform
2022-10-05
N/A
8.8 HIGH
There's a flaw in libxml2 in versions before 2.9.11. An attacker who is able to submit a crafted file to be processed by an application linked with libxml2 could trigger a use-after-free. The greatest impact from this flaw is to confidentiality, integrity, and availability.
