Show filters
16 Total Results
Displaying 1-10 of 16
Sort by:
Attacker Value
Unknown

CVE-2024-5055

Disclosure Date: May 17, 2024 (last updated May 18, 2024)
Uncontrolled resource consumption vulnerability in XAMPP Windows, versions 7.3.2 and earlier. This vulnerability exists when XAMPP attempts to process many incomplete HTTP requests, resulting in resource consumption and system crashes.
0
Attacker Value
Unknown

CVE-2024-0338

Disclosure Date: February 02, 2024 (last updated February 10, 2024)
A buffer overflow vulnerability has been found in XAMPP affecting version 8.2.4 and earlier. An attacker could execute arbitrary code through a long file debug argument that controls the Structured Exception Handler (SEH).
Attacker Value
Unknown

CVE-2022-47637

Disclosure Date: September 12, 2023 (last updated October 08, 2023)
The installer in XAMPP through 8.1.12 allows local users to write to the C:\xampp directory. Common use cases execute files under C:\xampp with administrative privileges.
Attacker Value
Unknown

CVE-2017-20018

Disclosure Date: June 09, 2022 (last updated February 23, 2025)
A vulnerability was found in XAMPP 7.1.1-0-VC14. It has been classified as problematic. Affected is an unknown function of the component Installer. The manipulation leads to privilege escalation. It is possible to launch the attack remotely.
Attacker Value
Unknown

CVE-2022-29376

Disclosure Date: May 23, 2022 (last updated February 23, 2025)
Xampp for Windows v8.1.4 and below was discovered to contain insecure permissions for its install directory, allowing attackers to execute arbitrary code via overwriting binaries located in the directory.
Attacker Value
Unknown

CVE-2020-11107

Disclosure Date: April 02, 2020 (last updated February 21, 2025)
An issue was discovered in XAMPP before 7.2.29, 7.3.x before 7.3.16 , and 7.4.x before 7.4.4 on Windows. An unprivileged user can change a .exe configuration in xampp-contol.ini for all users (including admins) to enable arbitrary command execution.
Attacker Value
Unknown

CVE-2019-8920

Disclosure Date: July 09, 2019 (last updated November 27, 2024)
iart.php in XAMPP 1.7.0 has XSS, a related issue to CVE-2008-3569.
0
Attacker Value
Unknown

CVE-2019-8924

Disclosure Date: May 17, 2019 (last updated November 27, 2024)
XAMPP through 5.6.8 allows XSS via the cds-fpdf.php interpret or titel parameter. NOTE: This product is discontinued.
0
Attacker Value
Unknown

CVE-2019-8923

Disclosure Date: May 14, 2019 (last updated November 27, 2024)
XAMPP through 5.6.8 and previous allows SQL injection via the cds-fpdf.php jahr parameter. NOTE: This product is discontinued.
0
Attacker Value
Unknown

CVE-2013-2586

Disclosure Date: September 29, 2014 (last updated October 05, 2023)
XAMPP 1.8.1 does not properly restrict access to xampp/lang.php, which allows remote attackers to modify xampp/lang.tmp and execute cross-site scripting (XSS) attacks via the WriteIntoLocalDisk method.
0