Show filters
334,747 Total Results
Displaying 41-50 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown

CVE-2018-9472

Disclosure Date: November 20, 2024 (last updated November 21, 2024)
In xmlMemStrdupLoc of xmlmemory.c, there is a possible out-of-bounds write due to an integer overflow. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is needed for exploitation.
0
Attacker Value
Unknown

CVE-2018-9471

Disclosure Date: November 20, 2024 (last updated November 21, 2024)
In the deserialization constructor of NanoAppFilter.java, there is a possible loss of data due to type confusion. This could lead to local escalation of privilege in the system server with no additional execution privileges needed. User interaction is not needed for exploitation.
0
Attacker Value
Unknown

CVE-2018-9470

Disclosure Date: November 20, 2024 (last updated November 21, 2024)
In bff_Scanner_addOutPos of Scanner.c, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege in an unprivileged app with no additional execution privileges needed. User interaction is needed for exploitation.
0
Attacker Value
Unknown

CVE-2024-52796

Disclosure Date: November 20, 2024 (last updated November 21, 2024)
Password Pusher, an open source application to communicate sensitive information over the web, comes with a configurable rate limiter. In versions prior to v1.49.0, the rate limiter could be bypassed by forging proxy headers allowing bad actors to send unlimited traffic to the site potentially causing a denial of service. In v1.49.0, a fix was implemented to only authorize proxies on local IPs which resolves this issue. As a workaround, one may add rules to one's proxy and/or firewall to not accept external proxy headers such as `X-Forwarded-*` from clients.
0
Attacker Value
Unknown

CVE-2024-52771

Disclosure Date: November 20, 2024 (last updated November 21, 2024)
DedeBIZ v6.3.0 was discovered to contain an arbitrary file deletion vulnerability via the component /admin/file_manage_view.
0
Attacker Value
Unknown

CVE-2024-52770

Disclosure Date: November 20, 2024 (last updated November 21, 2024)
An arbitrary file upload vulnerability in the component /admin/file_manage_control of DedeBIZ v6.3.0 allows attackers to execute arbitrary code via uploading a crafted file.
0
Attacker Value
Unknown

CVE-2024-52769

Disclosure Date: November 20, 2024 (last updated November 21, 2024)
An arbitrary file upload vulnerability in the component /admin/friendlink_edit of DedeBIZ v6.3.0 allows attackers to execute arbitrary code via uploading a crafted file.
0
Attacker Value
Unknown

CVE-2024-52725

Disclosure Date: November 20, 2024 (last updated November 21, 2024)
SemCms v4.8 was discovered to contain a SQL injection vulnerability. This allows an attacker to execute arbitrary code via the ldgid parameter in the SEMCMS_SeoAndTag.php component.
0
Attacker Value
Unknown

CVE-2024-51163

Disclosure Date: November 20, 2024 (last updated November 21, 2024)
Local File Inclusion vulnerability in Vegam Solutions Vegam 4i v.6.3.47.0 and earlier allows a remote attacker to obtain sensitive information via the print labelling function.
0
Attacker Value
Unknown

CVE-2024-51162

Disclosure Date: November 20, 2024 (last updated November 21, 2024)
An issue in Audimex EE v.15.1.20 and before allows a remote attacker to escalate privileges.
0