CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
In Sangoma Asterisk through 16.28.0, 17.x and 18.x through 18.14.0, and 19.x through 19.6.0, an incoming Setup message to addons/ooh323c/src/ooq931.c with a malformed Calling or Called Party IE can cause a crash.
A vulnerability was found in seccome Ehoney and classified as critical. Affected by this issue is some unknown functionality of the file /api/v1/bait/set. The manipulation of the argument Payload leads to sql injection. The attack may be launched remotely. VDB-212414 is the identifier assigned to this vulnerability.
Access_manager_agent, Access_manager_agent_for_iis_5.0/6.0, Access_manager_server, Ace_agent, Ace_server, Adaptive_authentication, Adaptive_authentication_(on_premise), Archer, Archer_egrc_platform, Archer_grc_platform
2022-08-29
N/A
6.1 MEDIUM
Archer Platform 6.9 SP2 P2 before 6.11 P3 (6.11.0.3) contain a reflected XSS vulnerability. A remote unauthenticated malicious Archer user could potentially exploit this vulnerability by tricking a victim application user into supplying malicious JavaScript code to the vulnerable web application. This code is then reflected to the victim and gets executed by the web browser in the context of the vulnerable web application. 6.10 P4 (6.10.0.4) and 6.11 P2 HF4 (6.11.0.2.4) are also fixed releases.
Access_manager_agent, Access_manager_agent_for_iis_5.0/6.0, Access_manager_server, Ace_agent, Ace_server, Adaptive_authentication, Adaptive_authentication_(on_premise), Archer, Archer_egrc_platform, Archer_grc_platform
2022-08-30
N/A
5.4 MEDIUM
Archer Platform 6.x before 6.11 P3 contain an HTML injection vulnerability. An authenticated remote attacker could potentially exploit this vulnerability by tricking a victim application user to execute malicious code in the context of the web application. 6.10 P4 (6.10.0.4) and 6.11 P2 HF4 (6.11.0.2.4) are also fixed releases.
Access_manager_agent, Access_manager_agent_for_iis_5.0/6.0, Access_manager_server, Ace_agent, Ace_server, Adaptive_authentication, Adaptive_authentication_(on_premise), Archer, Archer_egrc_platform, Archer_grc_platform
2022-08-30
N/A
6.5 MEDIUM
Archer Platform 6.8 before 6.11 P3 (6.11.0.3) contains an improper API access control vulnerability in a multi-instance system that could potentially present unauthorized metadata to an authenticated user of the affected system. 6.10 P3 HF1 (6.10.0.3.1) is also a fixed release.
graphql-go (aka GraphQL for Go) through 0.8.0 has infinite recursion in the type definition parser.
OX App Suite through 7.10.6 allows SSRF because the anti-SSRF protection mechanism only checks the first DNS AA or AAAA record.
OX App Suite through 7.10.6 has Uncontrolled Resource Consumption via a large request body containing a redirect URL to the deferrer servlet.
OX App Suite through 7.10.6 has Uncontrolled Resource Consumption via a large location request parameter to the redirect servlet.
OX App Suite through 7.10.6 allows XSS via a malicious capability to the metrics or help module, as demonstrated by a /#!!&app=io.ox/files&cap= URI.
