Show filters
334,747 Total Results
Displaying 41-50 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown
CVE-2018-9472
Disclosure Date: November 20, 2024 (last updated November 21, 2024)
In xmlMemStrdupLoc of xmlmemory.c, there is a possible out-of-bounds write due to an integer overflow. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is needed for exploitation.
0
Attacker Value
Unknown
CVE-2018-9471
Disclosure Date: November 20, 2024 (last updated November 21, 2024)
In the deserialization constructor of NanoAppFilter.java, there is a possible loss of data due to type confusion. This could lead to local escalation of privilege in the system server with no additional execution privileges needed. User interaction is not needed for exploitation.
0
Attacker Value
Unknown
CVE-2018-9470
Disclosure Date: November 20, 2024 (last updated November 21, 2024)
In bff_Scanner_addOutPos of Scanner.c, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege in an unprivileged app with no additional execution privileges needed. User interaction is needed for exploitation.
0
Attacker Value
Unknown
CVE-2024-52796
Disclosure Date: November 20, 2024 (last updated November 21, 2024)
Password Pusher, an open source application to communicate sensitive information over the web, comes with a configurable rate limiter. In versions prior to v1.49.0, the rate limiter could be bypassed by forging proxy headers allowing bad actors to send unlimited traffic to the site potentially causing a denial of service. In v1.49.0, a fix was implemented to only authorize proxies on local IPs which resolves this issue. As a workaround, one may add rules to one's proxy and/or firewall to not accept external proxy headers such as `X-Forwarded-*` from clients.
0
Attacker Value
Unknown
CVE-2024-52771
Disclosure Date: November 20, 2024 (last updated November 21, 2024)
DedeBIZ v6.3.0 was discovered to contain an arbitrary file deletion vulnerability via the component /admin/file_manage_view.
0
Attacker Value
Unknown
CVE-2024-52770
Disclosure Date: November 20, 2024 (last updated November 21, 2024)
An arbitrary file upload vulnerability in the component /admin/file_manage_control of DedeBIZ v6.3.0 allows attackers to execute arbitrary code via uploading a crafted file.
0
Attacker Value
Unknown
CVE-2024-52769
Disclosure Date: November 20, 2024 (last updated November 21, 2024)
An arbitrary file upload vulnerability in the component /admin/friendlink_edit of DedeBIZ v6.3.0 allows attackers to execute arbitrary code via uploading a crafted file.
0
Attacker Value
Unknown
CVE-2024-52725
Disclosure Date: November 20, 2024 (last updated November 21, 2024)
SemCms v4.8 was discovered to contain a SQL injection vulnerability. This allows an attacker to execute arbitrary code via the ldgid parameter in the SEMCMS_SeoAndTag.php component.
0
Attacker Value
Unknown
CVE-2024-51163
Disclosure Date: November 20, 2024 (last updated November 21, 2024)
Local File Inclusion vulnerability in Vegam Solutions Vegam 4i v.6.3.47.0 and earlier allows a remote attacker to obtain sensitive information via the print labelling function.
0
Attacker Value
Unknown
CVE-2024-51162
Disclosure Date: November 20, 2024 (last updated November 21, 2024)
An issue in Audimex EE v.15.1.20 and before allows a remote attacker to escalate privileges.
0