Show filters
557 Total Results
Displaying 11-20 of 557
Sort by:
Attacker Value
Unknown
CVE-2024-21547
Disclosure Date: December 18, 2024 (last updated December 18, 2024)
Versions of the package spatie/browsershot before 5.0.2 are vulnerable to Directory Traversal due to URI normalisation in the browser where the file:// check can be bypassed with file:\\. An attacker could read any file on the server by exploiting the normalization of \ into /.
0
Attacker Value
Unknown
CVE-2024-21544
Disclosure Date: December 13, 2024 (last updated December 18, 2024)
Versions of the package spatie/browsershot before 5.0.1 are vulnerable to Improper Input Validation due to improper URL validation through the setUrl method.
An attacker can exploit this vulnerability by using leading whitespace (%20) before the file:// protocol, resulting in Local File Inclusion, which allows the attacker to read sensitive files on the server.
0
Attacker Value
Unknown
CVE-2024-50583
Disclosure Date: October 25, 2024 (last updated October 25, 2024)
Whale browser Installer before 3.1.0.0 allows an attacker to execute a malicious DLL in the user environment due to improper permission settings.
0
Attacker Value
Unknown
CVE-2024-37406
Disclosure Date: September 18, 2024 (last updated September 19, 2024)
In Brave Android prior to v1.67.116, domains in the Brave Shields popup are elided from the right instead of the left, which may lead to domain confusion.
0
Attacker Value
Unknown
CVE-2024-45504
Disclosure Date: September 10, 2024 (last updated September 10, 2024)
Cross-site request forgery (CSRF) vulnerability in multiple Alps System Integration products and the OEM products allow a remote unauthenticated attacker to hijack the authentication of the user and to perform unintended operations if the user views a malicious page while logged in.
0
Attacker Value
Unknown
CVE-2024-6473
Disclosure Date: September 03, 2024 (last updated September 06, 2024)
Yandex Browser for Desktop before 24.7.1.380 has a DLL Hijacking Vulnerability because an untrusted search path is used.
0
Attacker Value
Unknown
CVE-2024-23729
Disclosure Date: August 19, 2024 (last updated August 21, 2024)
The ColorOS Internet Browser com.heytap.browser application 45.10.3.4.1 for Android allows a remote attacker to execute arbitrary JavaScript code via the com.android.browser.RealBrowserActivity component.
0
Attacker Value
Unknown
CVE-2024-0981
Disclosure Date: July 23, 2024 (last updated July 24, 2024)
Okta Browser Plugin versions 6.5.0 through 6.31.0 (Chrome/Edge/Firefox/Safari) are vulnerable to cross-site scripting. This issue occurs when the plugin prompts the user to save these credentials within Okta Personal. A fix was implemented to properly escape these fields, addressing the vulnerability. Importantly, if Okta Personal is not added to the plugin to enable multi-account view, the Workforce Identity Cloud plugin is not affected by this issue. The vulnerability is fixed in Okta Browser Plugin version 6.32.0 for Chrome/Edge/Safari/Firefox.
0
Attacker Value
Unknown
CVE-2024-40618
Disclosure Date: July 11, 2024 (last updated July 11, 2024)
Whale browser before 3.26.244.21 allows an attacker to execute malicious JavaScript due to improper sanitization when processing a built-in extension.
0
Attacker Value
Unknown
CVE-2024-37865
Disclosure Date: July 09, 2024 (last updated August 20, 2024)
An issue in S3Browser v.11.4.5 and v.10.9.9 and fixed in v.11.5.7 allows a remote attacker to obtain sensitive information via the S3 compatible storage component.
0