Show filters
557 Total Results
Displaying 11-20 of 557
Sort by:
Attacker Value
Unknown

CVE-2024-21547

Disclosure Date: December 18, 2024 (last updated December 18, 2024)
Versions of the package spatie/browsershot before 5.0.2 are vulnerable to Directory Traversal due to URI normalisation in the browser where the file:// check can be bypassed with file:\\. An attacker could read any file on the server by exploiting the normalization of \ into /.
0
Attacker Value
Unknown

CVE-2024-21544

Disclosure Date: December 13, 2024 (last updated December 18, 2024)
Versions of the package spatie/browsershot before 5.0.1 are vulnerable to Improper Input Validation due to improper URL validation through the setUrl method. An attacker can exploit this vulnerability by using leading whitespace (%20) before the file:// protocol, resulting in Local File Inclusion, which allows the attacker to read sensitive files on the server.
0
Attacker Value
Unknown

CVE-2024-50583

Disclosure Date: October 25, 2024 (last updated October 25, 2024)
Whale browser Installer before 3.1.0.0 allows an attacker to execute a malicious DLL in the user environment due to improper permission settings.
0
Attacker Value
Unknown

CVE-2024-37406

Disclosure Date: September 18, 2024 (last updated September 19, 2024)
In Brave Android prior to v1.67.116, domains in the Brave Shields popup are elided from the right instead of the left, which may lead to domain confusion.
0
Attacker Value
Unknown

CVE-2024-45504

Disclosure Date: September 10, 2024 (last updated September 10, 2024)
Cross-site request forgery (CSRF) vulnerability in multiple Alps System Integration products and the OEM products allow a remote unauthenticated attacker to hijack the authentication of the user and to perform unintended operations if the user views a malicious page while logged in.
0
Attacker Value
Unknown

CVE-2024-6473

Disclosure Date: September 03, 2024 (last updated September 06, 2024)
Yandex Browser for Desktop before 24.7.1.380 has a DLL Hijacking Vulnerability because an untrusted search path is used.
Attacker Value
Unknown

CVE-2024-23729

Disclosure Date: August 19, 2024 (last updated August 21, 2024)
The ColorOS Internet Browser com.heytap.browser application 45.10.3.4.1 for Android allows a remote attacker to execute arbitrary JavaScript code via the com.android.browser.RealBrowserActivity component.
Attacker Value
Unknown

CVE-2024-0981

Disclosure Date: July 23, 2024 (last updated July 24, 2024)
Okta Browser Plugin versions 6.5.0 through 6.31.0 (Chrome/Edge/Firefox/Safari) are vulnerable to cross-site scripting. This issue occurs when the plugin prompts the user to save these credentials within Okta Personal. A fix was implemented to properly escape these fields, addressing the vulnerability. Importantly, if Okta Personal is not added to the plugin to enable multi-account view, the Workforce Identity Cloud plugin is not affected by this issue. The vulnerability is fixed in Okta Browser Plugin version 6.32.0 for Chrome/Edge/Safari/Firefox.
0
Attacker Value
Unknown

CVE-2024-40618

Disclosure Date: July 11, 2024 (last updated July 11, 2024)
Whale browser before 3.26.244.21 allows an attacker to execute malicious JavaScript due to improper sanitization when processing a built-in extension.
0
Attacker Value
Unknown

CVE-2024-37865

Disclosure Date: July 09, 2024 (last updated August 20, 2024)
An issue in S3Browser v.11.4.5 and v.10.9.9 and fixed in v.11.5.7 allows a remote attacker to obtain sensitive information via the S3 compatible storage component.