Show filters
422 Total Results
Displaying 141-150 of 422
Sort by:
Attacker Value
Unknown

CVE-2024-39459

Disclosure Date: June 26, 2024 (last updated February 26, 2025)
In rare cases Jenkins Plain Credentials Plugin 182.v468b_97b_9dcb_8 and earlier stores secret file credentials unencrypted (only Base64 encoded) on the Jenkins controller file system, where they can be viewed by users with access to the Jenkins controller file system (global credentials) or with Item/Extended Read permission (folder-scoped credentials).
0
Attacker Value
Unknown

CVE-2024-29953

Disclosure Date: June 26, 2024 (last updated February 26, 2025)
A vulnerability in the web interface in Brocade Fabric OS before v9.2.1, v9.2.0b, and v9.1.1d prints encoded session passwords on session storage for Virtual Fabric platforms. This could allow an authenticated user to view other users' session encoded passwords.
Attacker Value
Unknown

CVE-2024-35526

Disclosure Date: June 25, 2024 (last updated February 26, 2025)
An issue in Daemon PTY Limited FarCry Core framework before 7.2.14 allows attackers to access sensitive information in the /facade directory.
0
Attacker Value
Unknown

CVE-2024-6295

Disclosure Date: June 25, 2024 (last updated February 26, 2025)
udn News Android APP stores the unencrypted user session in the local database when user log into the application. A malicious APP or an attacker with physical access to the Android device can retrieve this session and use it to log into the news APP and other services provided by udn.
0
Attacker Value
Unknown

CVE-2024-37654

Disclosure Date: June 21, 2024 (last updated February 26, 2025)
An issue in BAS-IP AV-01D, AV-01MD, AV-01MFD, AV-01ED, AV-01KD, AV-01BD, AV-01KBD, AV-02D, AV-02IDE, AV-02IDR, AV-02IPD, AV-02FDE, AV-02FDR, AV-03D, AV-03BD, AV-04AFD, AV-04ASD, AV-04FD, AV-04SD, AV-05FD, AV-05SD, AA-07BD, AA-07BDI, BA-04BD, BA-04MD, BA-08BD, BA-08MD, BA-12BD, BA-12MD, CR-02BD before 3.9.2 allows a remote attacker to obtain sensitive information via a crafted HTTP GET request.
0
Attacker Value
Unknown

CVE-2024-36252

Disclosure Date: June 19, 2024 (last updated February 26, 2025)
Improper restriction of communication channel to intended endpoints issue exists in Ricoh Streamline NX PC Client ver.3.6.x and earlier. If this vulnerability is exploited, arbitrary code may be executed on the PC where the product is installed.
0
Attacker Value
Unknown

CVE-2024-38312

Disclosure Date: June 13, 2024 (last updated February 26, 2025)
When browsing private tabs, some data related to location history or webpage thumbnails could be persisted incorrectly within the sandboxed app bundle after app termination This vulnerability affects Firefox for iOS < 127.
Attacker Value
Unknown

CVE-2024-23445

Disclosure Date: June 12, 2024 (last updated February 26, 2025)
It was identified that if a cross-cluster API key https://www.elastic.co/guide/en/elasticsearch/reference/8.14/security-api-create-cross-cluster-api-key.html#security-api-create-cross-cluster-api-key-request-body  restricts search for a given index using the query or the field_security parameter, and the same cross-cluster API key also grants replication for the same index, the search restrictions are not enforced during cross cluster search operations and search results may include documents and terms that should not be returned. This issue only affects the API key based security model for remote clusters https://www.elastic.co/guide/en/elasticsearch/reference/8.14/remote-clusters.html#remote-clusters-security-models  that was previously a beta feature and is released as GA with 8.14.0
0
Attacker Value
Unknown

CVE-2024-31404

Disclosure Date: June 11, 2024 (last updated February 26, 2025)
Insertion of sensitive information into sent data issue exists in Cybozu Garoon 5.5.0 to 6.0.0, which may allow a user who can log in to the product to view the data of Scheduler.
0
Attacker Value
Unknown

CVE-2024-31400

Disclosure Date: June 11, 2024 (last updated February 26, 2025)
Insertion of sensitive information into sent data issue exists in Cybozu Garoon 5.0.0 to 5.15.0. If this vulnerability is exploited, unintended data may be left in forwarded mail.
0