Show filters
23 Total Results
Displaying 11-20 of 23
Sort by:
Attacker Value
Unknown

CVE-2020-28443

Disclosure Date: July 25, 2022 (last updated February 24, 2025)
This affects all versions of package sonar-wrapper. The injection point is located in lib/sonarRunner.js.
Attacker Value
Unknown

CVE-2022-30968

Disclosure Date: May 17, 2022 (last updated February 23, 2025)
Jenkins vboxwrapper Plugin 1.3 and earlier does not escape the name and description of VBox node parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
Attacker Value
Unknown

CVE-2020-6958

Disclosure Date: January 14, 2020 (last updated February 21, 2025)
An XXE vulnerability in JnlpSupport in Yet Another Java Service Wrapper (YAJSW) 12.14, as used in NSA Ghidra and other products, allows attackers to exfiltrate data from remote hosts and potentially cause denial-of-service.
Attacker Value
Unknown

CVE-2019-17206

Disclosure Date: October 05, 2019 (last updated November 27, 2024)
Uncontrolled deserialization of a pickled object in models.py in Frost Ming rediswrapper (aka Redis Wrapper) before 0.3.0 allows attackers to execute arbitrary scripts.
Attacker Value
Unknown

CVE-2019-11831

Disclosure Date: May 09, 2019 (last updated November 08, 2023)
The PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 does not prevent directory traversal, which allows attackers to bypass a deserialization protection mechanism, as demonstrated by a phar:///path/bad.phar/../good.phar URL.
Attacker Value
Unknown

CVE-2019-11830

Disclosure Date: May 09, 2019 (last updated November 08, 2023)
PharMetaDataInterceptor in the PharStreamWrapper (aka phar-stream-wrapper) package 2.x before 2.1.1 and 3.x before 3.1.1 for TYPO3 mishandles Phar stub parsing, which allows attackers to bypass a deserialization protection mechanism.
0
Attacker Value
Unknown

CVE-2016-10671

Disclosure Date: June 04, 2018 (last updated November 26, 2024)
mystem-wrapper is a Yandex mystem app wrapper module. mystem-wrapper downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the network or positioned in between the user and the remote server.
0
Attacker Value
Unknown

CVE-2016-10628

Disclosure Date: June 01, 2018 (last updated November 26, 2024)
selenium-wrapper is a selenium server wrapper, including installation and chrome webdriver. selenium-wrapper downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.
0
Attacker Value
Unknown

CVE-2011-2486

Disclosure Date: November 19, 2012 (last updated October 05, 2023)
nspluginwrapper before 1.4.4 does not properly provide access to NPNVprivateModeBool variable settings, which could prevent Firefox plugins from determining if they should run in Private Browsing mode and allow remote attackers to bypass intended access restrictions, as demonstrated using Flash.
0
Attacker Value
Unknown

CVE-2007-4302

Disclosure Date: August 13, 2007 (last updated October 04, 2023)
Multiple race conditions in certain system call wrappers in Generic Software Wrappers Toolkit (GSWTK) allow local users to defeat system call interposition and possibly gain privileges or bypass auditing.
0