Show filters
23 Total Results
Displaying 11-20 of 23
Sort by:
Attacker Value
Unknown
CVE-2020-28443
Disclosure Date: July 25, 2022 (last updated February 24, 2025)
This affects all versions of package sonar-wrapper. The injection point is located in lib/sonarRunner.js.
0
Attacker Value
Unknown
CVE-2022-30968
Disclosure Date: May 17, 2022 (last updated February 23, 2025)
Jenkins vboxwrapper Plugin 1.3 and earlier does not escape the name and description of VBox node parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
0
Attacker Value
Unknown
CVE-2020-6958
Disclosure Date: January 14, 2020 (last updated February 21, 2025)
An XXE vulnerability in JnlpSupport in Yet Another Java Service Wrapper (YAJSW) 12.14, as used in NSA Ghidra and other products, allows attackers to exfiltrate data from remote hosts and potentially cause denial-of-service.
0
Attacker Value
Unknown
CVE-2019-17206
Disclosure Date: October 05, 2019 (last updated November 27, 2024)
Uncontrolled deserialization of a pickled object in models.py in Frost Ming rediswrapper (aka Redis Wrapper) before 0.3.0 allows attackers to execute arbitrary scripts.
0
Attacker Value
Unknown
CVE-2019-11831
Disclosure Date: May 09, 2019 (last updated November 08, 2023)
The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attackers to bypass a deserialization protection mechanism, as demonstrated by a phar:///path/bad.phar/../good.phar URL.
0
Attacker Value
Unknown
CVE-2019-11830
Disclosure Date: May 09, 2019 (last updated November 08, 2023)
PharMetaDataInterceptor in the PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 mishandles Phar stub parsing, which allows attackers to bypass a deserialization protection mechanism.
0
Attacker Value
Unknown
CVE-2016-10671
Disclosure Date: June 04, 2018 (last updated November 26, 2024)
mystem-wrapper is a Yandex mystem app wrapper module. mystem-wrapper downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the network or positioned in between the user and the remote server.
0
Attacker Value
Unknown
CVE-2016-10628
Disclosure Date: June 01, 2018 (last updated November 26, 2024)
selenium-wrapper is a selenium server wrapper, including installation and chrome webdriver. selenium-wrapper downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.
0
Attacker Value
Unknown
CVE-2011-2486
Disclosure Date: November 19, 2012 (last updated October 05, 2023)
nspluginwrapper before 1.4.4 does not properly provide access to NPNVprivateModeBool variable settings, which could prevent Firefox plugins from determining if they should run in Private Browsing mode and allow remote attackers to bypass intended access restrictions, as demonstrated using Flash.
0
Attacker Value
Unknown
CVE-2007-4302
Disclosure Date: August 13, 2007 (last updated October 04, 2023)
Multiple race conditions in certain system call wrappers in Generic Software Wrappers Toolkit (GSWTK) allow local users to defeat system call interposition and possibly gain privileges or bypass auditing.
0