Show filters
464 Total Results
Displaying 11-20 of 464
Sort by:
Attacker Value
Unknown

CVE-2021-44302

Disclosure Date: February 19, 2022 (last updated October 07, 2023)
BaiCloud-cms v2.5.7 was discovered to contain multiple SQL injection vulnerabilities via the tongji and baidu_map parameters in /user/ztconfig.php.
Attacker Value
Unknown

CVE-2018-4302

Disclosure Date: December 23, 2021 (last updated October 07, 2023)
A null pointer dereference was addressed with improved validation. This issue is fixed in macOS High Sierra 10.13, iCloud for Windows 7.0, watchOS 4, iOS 11, iTunes 12.7 for Windows. Processing maliciously crafted XML may lead to an unexpected application termination or arbitrary code execution.
Attacker Value
Unknown

CVE-2021-41729

Disclosure Date: September 30, 2021 (last updated November 28, 2024)
BaiCloud-cms v2.5.7 is affected by an arbitrary file deletion vulnerability, which allows an attacker to delete arbitrary files on the server through /user/ppsave.php.
Attacker Value
Unknown

CVE-2021-1825

Disclosure Date: September 08, 2021 (last updated November 28, 2024)
An input validation issue was addressed with improved input validation. This issue is fixed in iTunes 12.11.3 for Windows, iCloud for Windows 12.3, macOS Big Sur 11.3, Safari 14.1, watchOS 7.4, tvOS 14.5, iOS 14.5 and iPadOS 14.5. Processing maliciously crafted web content may lead to a cross site scripting attack.
Attacker Value
Unknown

CVE-2021-1811

Disclosure Date: September 08, 2021 (last updated November 28, 2024)
A logic issue was addressed with improved state management. This issue is fixed in iTunes 12.11.3 for Windows, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iCloud for Windows 12.3, macOS Big Sur 11.3, watchOS 7.4, tvOS 14.5, iOS 14.5 and iPadOS 14.5. Processing a maliciously crafted font may result in the disclosure of process memory.
Attacker Value
Unknown

CVE-2021-1857

Disclosure Date: September 08, 2021 (last updated November 28, 2024)
A memory initialization issue was addressed with improved memory handling. This issue is fixed in iTunes 12.11.3 for Windows, Security Update 2021-002 Catalina, Security Update 2021-003 Mojave, iCloud for Windows 12.3, macOS Big Sur 11.3, watchOS 7.4, tvOS 14.5, iOS 14.5 and iPadOS 14.5. Processing maliciously crafted web content may disclose sensitive user information.
Attacker Value
Unknown

CVE-2021-30928

Disclosure Date: August 24, 2021 (last updated October 07, 2023)
A memory corruption issue was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.6, watchOS 8, tvOS 15, iOS 14.8 and iPadOS 14.8, iOS 15 and iPadOS 15. Processing a maliciously crafted image may lead to arbitrary code execution.
Attacker Value
Unknown

CVE-2020-4765

Disclosure Date: May 18, 2021 (last updated November 28, 2024)
IBM Cloud Pak for Multicloud Management prior to 2.3 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 188902.
Attacker Value
Unknown

CVE-2020-29611

Disclosure Date: April 02, 2021 (last updated November 28, 2024)
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 14.3, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, iCloud for Windows 12.0, watchOS 7.2. Processing a maliciously crafted image may lead to arbitrary code execution.
Attacker Value
Unknown

CVE-2020-29619

Disclosure Date: April 02, 2021 (last updated November 28, 2024)
An out-of-bounds read was addressed with improved input validation. This issue is fixed in tvOS 14.3, macOS Big Sur 11.1, Security Update 2020-001 Catalina, Security Update 2020-007 Mojave, iOS 14.3 and iPadOS 14.3, iCloud for Windows 12.0, watchOS 7.2. Processing a maliciously crafted image may lead to heap corruption.