Show filters
97 Total Results
Displaying 11-20 of 97
Sort by:
Attacker Value
Unknown
CVE-2022-46342
Disclosure Date: December 14, 2022 (last updated October 08, 2023)
A vulnerability was found in X.Org. This security flaw occurs because the handler for the XvdiSelectVideoNotify request may write to memory after it has been freed. This issue can lead to local privileges elevation on systems where the X se
0
Attacker Value
Unknown
CVE-2022-46341
Disclosure Date: December 14, 2022 (last updated October 08, 2023)
A vulnerability was found in X.Org. This security flaw occurs because the handler for the XIPassiveUngrab request accesses out-of-bounds memory when invoked with a high keycode or button code. This issue can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for ssh X forwarding sessions.
0
Attacker Value
Unknown
CVE-2022-46340
Disclosure Date: December 14, 2022 (last updated October 08, 2023)
A vulnerability was found in X.Org. This security flaw occurs becuase the swap handler for the XTestFakeInput request of the XTest extension may corrupt the stack if GenericEvents with lengths larger than 32 bytes are sent through a the XTestFakeInput request. This issue can lead to local privileges elevation on systems where the X server is running privileged and remote code execution for ssh X forwarding sessions. This issue does not affect systems where client and server use the same byte order.
0
Attacker Value
Unknown
CVE-2022-41741
Disclosure Date: October 19, 2022 (last updated November 08, 2023)
NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to corrupt NGINX worker memory, resulting in its termination or potential other impact using a specially crafted audio or video file. The issue affects only NGINX products that are built with the ngx_http_mp4_module, when the mp4 directive is used in the configuration file. Further, the attack is possible only if an attacker can trigger processing of a specially crafted audio or video file with the module ngx_http_mp4_module.
0
Attacker Value
Unknown
CVE-2022-31160
Disclosure Date: July 20, 2022 (last updated November 08, 2023)
jQuery UI is a curated set of user interface interactions, effects, widgets, and themes built on top of jQuery. Versions prior to 1.13.2 are potentially vulnerable to cross-site scripting. Initializing a checkboxradio widget on an input enclosed within a label makes that parent label contents considered as the input label. Calling `.checkboxradio( "refresh" )` on such a widget and the initial HTML contained encoded HTML entities will make them erroneously get decoded. This can lead to potentially executing JavaScript code. The bug has been patched in jQuery UI 1.13.2. To remediate the issue, someone who can change the initial HTML can wrap all the non-input contents of the `label` in a `span`.
0
Attacker Value
Unknown
CVE-2022-0730
Disclosure Date: March 03, 2022 (last updated October 07, 2023)
Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types.
0
Attacker Value
Unknown
CVE-2020-23226
Disclosure Date: August 27, 2021 (last updated February 23, 2025)
Multiple Cross Site Scripting (XSS) vulneratiblities exist in Cacti 1.2.12 in (1) reports_admin.php, (2) data_queries.php, (3) data_input.php, (4) graph_templates.php, (5) graphs.php, (6) reports_admin.php, and (7) data_input.php.
0
Attacker Value
Unknown
CVE-2021-33813
Disclosure Date: June 16, 2021 (last updated February 22, 2025)
An XXE issue in SAXBuilder in JDOM through 2.0.6 allows attackers to cause a denial of service via a crafted HTTP request.
0
Attacker Value
Unknown
CVE-2021-20228
Disclosure Date: April 29, 2021 (last updated February 22, 2025)
A flaw was found in the Ansible Engine 2.9.18, where sensitive info is not masked by default and is not protected by the no_log feature when using the sub-option feature of the basic.py module. This flaw allows an attacker to obtain sensitive information. The highest threat from this vulnerability is to confidentiality.
0
Attacker Value
Unknown
CVE-2020-25706
Disclosure Date: November 12, 2020 (last updated February 22, 2025)
A cross-site scripting (XSS) vulnerability exists in templates_import.php (Cacti 1.2.13) due to Improper escaping of error message during template import preview in the xml_path field
0