Show filters
91 Total Results
Displaying 1-10 of 91
Sort by:
Attacker Value
Unknown
CVE-2024-45504
Disclosure Date: September 10, 2024 (last updated September 10, 2024)
Cross-site request forgery (CSRF) vulnerability in multiple Alps System Integration products and the OEM products allow a remote unauthenticated attacker to hijack the authentication of the user and to perform unintended operations if the user views a malicious page while logged in.
0
Attacker Value
Unknown
CVE-2023-49553
Disclosure Date: January 02, 2024 (last updated January 10, 2024)
An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_destroy function in the msj.c file.
0
Attacker Value
Unknown
CVE-2023-49552
Disclosure Date: January 02, 2024 (last updated January 10, 2024)
An Out of Bounds Write in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_op_json_stringify function in the msj.c file.
0
Attacker Value
Unknown
CVE-2023-49551
Disclosure Date: January 02, 2024 (last updated January 06, 2024)
An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_op_json_parse function in the msj.c file.
0
Attacker Value
Unknown
CVE-2023-49550
Disclosure Date: January 02, 2024 (last updated January 06, 2024)
An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs+0x4ec508 component.
0
Attacker Value
Unknown
CVE-2023-49549
Disclosure Date: January 02, 2024 (last updated January 10, 2024)
An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_getretvalpos function in the msj.c file.
0
Attacker Value
Unknown
CVE-2023-50044
Disclosure Date: December 20, 2023 (last updated December 29, 2023)
Cesanta MJS 2.20.0 has a getprop_builtin_foreign out-of-bounds read if a Built-in API name occurs in a substring of an input string.
0
Attacker Value
Unknown
CVE-2023-48094
Disclosure Date: November 14, 2023 (last updated December 07, 2023)
A cross-site scripting (XSS) vulnerability in CesiumJS v1.111 allows attackers to execute arbitrary code in the context of the victim's browser via sending a crafted payload to /container_files/public_html/doc/index.html. NOTE: the vendor’s position is that Apps/Sandcastle/standalone.html is part of the CesiumGS/cesium GitHub repository, but is demo code that is not part of the CesiumJS JavaScript library product.
0
Attacker Value
Unknown
CVE-2023-43338
Disclosure Date: September 23, 2023 (last updated October 08, 2023)
Cesanta mjs v2.20.0 was discovered to contain a function pointer hijacking vulnerability via the function mjs_get_ptr(). This vulnerability allows attackers to execute arbitrary code via a crafted input.
0
Attacker Value
Unknown
CVE-2023-34611
Disclosure Date: June 14, 2023 (last updated October 08, 2023)
An issue was discovered mjson thru 1.4.1 allows attackers to cause a denial of service or other unspecified impacts via crafted object that uses cyclic dependencies.
0