Show filters
40 Total Results
Displaying 11-20 of 40
Sort by:
Attacker Value
Unknown

CVE-2022-1820

Disclosure Date: June 13, 2022 (last updated October 07, 2023)
The Keep Backup Daily plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘t’ parameter in versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2022-23435

Disclosure Date: January 19, 2022 (last updated October 07, 2023)
decoding.c in android-gif-drawable before 1.2.24 does not limit the maximum length of a comment, leading to denial of service.
Attacker Value
Unknown

CVE-2021-24798

Disclosure Date: November 08, 2021 (last updated February 23, 2025)
The WP Header Images WordPress plugin before 2.0.1 does not sanitise and escape the t parameter before outputting it back in the plugin's settings page, leading to a Reflected Cross-Site Scripting issue
Attacker Value
Unknown

CVE-2020-8913

Disclosure Date: August 12, 2020 (last updated February 21, 2025)
A local, arbitrary code execution vulnerability exists in the SplitCompat.install endpoint in Android's Play Core Library versions prior to 1.7.2. A malicious attacker could create an apk which targets a specific application, and if a victim were to install this apk, the attacker could perform a directory traversal, execute code as the targeted application and access the targeted application's data on the Android device. We recommend all users update Play Core to version 1.7.2 or later.
Attacker Value
Unknown

CVE-2019-11932

Disclosure Date: October 03, 2019 (last updated November 27, 2024)
A double free vulnerability in the DDGifSlurp function in decoding.c in the android-gif-drawable library before version 1.2.18, as used in WhatsApp for Android before version 2.19.244 and many other Android applications, allows remote attackers to execute arbitrary code or cause a denial of service when the library is used to parse a specially crafted GIF image.
Attacker Value
Unknown

CVE-2016-10641

Disclosure Date: June 04, 2018 (last updated November 26, 2024)
node-bsdiff-android downloads resources over HTTP, which leaves it vulnerable to MITM attacks.
0
Attacker Value
Unknown

CVE-2017-1000498

Disclosure Date: January 03, 2018 (last updated November 26, 2024)
AndroidSVG version 1.2.2 is vulnerable to XXE attacks in the SVG parsing component resulting in denial of service and possibly remote code execution
Attacker Value
Unknown

CVE-2017-1002003

Disclosure Date: September 14, 2017 (last updated November 26, 2024)
Vulnerability in wordpress plugin wp2android-turn-wp-site-into-android-app v1.1.4, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com.
0
Attacker Value
Unknown

CVE-2014-7507

Disclosure Date: October 20, 2014 (last updated October 05, 2023)
The Hector Leal (aka ad.hector.leal.com) application 13/08/14 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown

CVE-2014-7476

Disclosure Date: October 19, 2014 (last updated October 05, 2023)
The Healthy Lunch Diet Recipes (aka com.best.lunchdietrecipes) application 3.6.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0