Show filters
129 Total Results
Displaying 11-20 of 129
Sort by:
Attacker Value
Unknown

CVE-2024-6135

Disclosure Date: September 13, 2024 (last updated September 19, 2024)
BT:Classic: Multiple missing buf length checks
Attacker Value
Unknown

CVE-2024-5931

Disclosure Date: September 13, 2024 (last updated September 19, 2024)
BT: Unchecked user input in bap_broadcast_assistant
Attacker Value
Unknown

CVE-2024-6258

Disclosure Date: September 13, 2024 (last updated September 19, 2024)
BT: Missing length checks of net_buf in rfcomm_handle_data
Attacker Value
Unknown

CVE-2024-5754

Disclosure Date: September 13, 2024 (last updated September 19, 2024)
BT: Encryption procedure host vulnerability
Attacker Value
Unknown

CVE-2024-43916

Disclosure Date: August 26, 2024 (last updated September 13, 2024)
Authorization Bypass Through User-Controlled Key vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.102.
Attacker Value
Unknown

CVE-2024-43915

Disclosure Date: August 26, 2024 (last updated August 29, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Dylan James Zephyr Project Manager allows Reflected XSS.This issue affects Zephyr Project Manager: from n/a through .3.102.
Attacker Value
Unknown

CVE-2024-4785

Disclosure Date: August 19, 2024 (last updated February 04, 2025)
BT: Missing Check in LL_CONNECTION_UPDATE_IND Packet Leads to Division by Zero
Attacker Value
Unknown

CVE-2024-43322

Disclosure Date: August 18, 2024 (last updated February 12, 2025)
Authorization Bypass Through User-Controlled Key vulnerability in Dylan James Zephyr Project Manager.This issue affects Zephyr Project Manager: from n/a through 3.3.100.
Attacker Value
Unknown

CVE-2024-7624

Disclosure Date: August 15, 2024 (last updated February 12, 2025)
The Zephyr Project Manager plugin for WordPress is vulnerable to limited privilege escalation in all versions up to, and including, 3.3.101. This is due to the plugin not properly checking a users capabilities before allowing them to enable access to the plugin's settings through the update_user_access() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to grant themselves full access to the plugin's settings.
0
Attacker Value
Unknown

CVE-2024-7356

Disclosure Date: August 03, 2024 (last updated February 12, 2025)
The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘filename’ parameter in all versions up to, and including, 3.3.100 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.