Show filters
18 Total Results
Displaying 11-18 of 18
Sort by:
Attacker Value
Unknown
CVE-2020-12439
Disclosure Date: May 05, 2020 (last updated February 21, 2025)
Grin before 3.1.0 allows attackers to adversely affect availability of data on a Mimblewimble blockchain.
0
Attacker Value
Unknown
CVE-2020-6638
Disclosure Date: January 21, 2020 (last updated February 21, 2025)
Grin through 2.1.1 has Insufficient Validation.
0
Attacker Value
Unknown
CVE-2019-9195
Disclosure Date: February 26, 2019 (last updated November 27, 2024)
util/src/zip.rs in Grin before 1.0.2 mishandles suspicious files. An attacker can execute arbitrary code via directory traversal in a ZIP archive.
0
Attacker Value
Unknown
CVE-2018-12909
Disclosure Date: June 27, 2018 (last updated November 08, 2023)
Webgrind 1.5 relies on user input to display a file, which lets anyone view files from the local filesystem (that the webserver user has access to) via an index.php?op=fileviewer&file= URI. NOTE: the vendor indicates that the product is not intended for a "publicly accessible environment.
0
Attacker Value
Unknown
CVE-2016-5060
Disclosure Date: December 13, 2016 (last updated November 25, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in nGrinder before 3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) description, (2) email, or (3) username parameter to user/save.
0
Attacker Value
Unknown
CVE-2012-1790
Disclosure Date: March 19, 2012 (last updated October 04, 2023)
Absolute path traversal vulnerability in Webgrind 1.0 and 1.0.2 allows remote attackers to read arbitrary files via a full pathname in the file parameter to index.php.
0
Attacker Value
Unknown
CVE-2008-4865
Disclosure Date: November 01, 2008 (last updated October 04, 2023)
Untrusted search path vulnerability in valgrind before 3.4.0 allows local users to execute arbitrary programs via a Trojan horse .valgrindrc file in the current working directory, as demonstrated using a malicious --db-command options. NOTE: the severity of this issue has been disputed, but CVE is including this issue because execution of a program from an untrusted directory is a common scenario.
0
Attacker Value
Unknown
CVE-2002-1948
Disclosure Date: December 31, 2002 (last updated February 22, 2025)
Multiple buffer overflows in Gringotts 0.5.9 allows local users to execute arbitrary commands via unknown attack vectors.
0