Show filters
48 Total Results
Displaying 1-10 of 48
Sort by:
Attacker Value
Unknown
CVE-2022-4974
Disclosure Date: October 16, 2024 (last updated October 16, 2024)
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
0
Attacker Value
Unknown
CVE-2022-42944
Disclosure Date: October 21, 2022 (last updated February 24, 2025)
A malicious crafted dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
0
Attacker Value
Unknown
CVE-2022-42943
Disclosure Date: October 21, 2022 (last updated February 24, 2025)
A malicious crafted dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
0
Attacker Value
Unknown
CVE-2022-42942
Disclosure Date: October 21, 2022 (last updated February 24, 2025)
A malicious crafted dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
0
Attacker Value
Unknown
CVE-2022-42941
Disclosure Date: October 21, 2022 (last updated February 24, 2025)
A malicious crafted dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by read access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
0
Attacker Value
Unknown
CVE-2022-42940
Disclosure Date: October 21, 2022 (last updated February 24, 2025)
A malicious crafted TGA file when consumed through DesignReview.exe application could lead to memory corruption vulnerability. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
0
Attacker Value
Unknown
CVE-2022-42939
Disclosure Date: October 21, 2022 (last updated February 24, 2025)
A malicious crafted TGA file when consumed through DesignReview.exe application could lead to memory corruption vulnerability. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
0
Attacker Value
Unknown
CVE-2022-42938
Disclosure Date: October 21, 2022 (last updated February 24, 2025)
A malicious crafted TGA file when consumed through DesignReview.exe application could lead to memory corruption vulnerability. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
0
Attacker Value
Unknown
CVE-2022-42937
Disclosure Date: October 21, 2022 (last updated February 24, 2025)
A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
0
Attacker Value
Unknown
CVE-2022-42936
Disclosure Date: October 21, 2022 (last updated February 24, 2025)
A malicious crafted .dwf or .pct file when consumed through DesignReview.exe application could lead to memory corruption vulnerability by write access violation. This vulnerability in conjunction with other vulnerabilities could lead to code execution in the context of the current process.
0