Show filters
29 Total Results
Displaying 11-20 of 29
Sort by:
Attacker Value
Unknown
CVE-2021-40418
Disclosure Date: December 22, 2021 (last updated October 07, 2023)
When parsing a file that is submitted to the DPDecoder service as a job, the R3D SDK will mistakenly skip over the assignment of a property containing an object referring to a UUID that was parsed from a frame within the video container. Upon destruction of the object that owns it, the uninitialized member will be dereferenced and then destroyed using the object’s virtual destructor. Due to the object property being uninitialized, this can result in dereferencing an arbitrary pointer for the object’s virtual method table, which can result in code execution under the context of the application.
0
Attacker Value
Unknown
CVE-2021-40417
Disclosure Date: December 22, 2021 (last updated October 07, 2023)
When parsing a file that is submitted to the DPDecoder service as a job, the service will use the combination of decoding parameters that were submitted with the job along with fields that were parsed for the submitted video by the R3D SDK to calculate the size of a heap buffer. Due to an integer overflow with regards to this calculation, this can result in an undersized heap buffer being allocated. When this heap buffer is written to, a heap-based buffer overflow will occur. This can result in code execution under the context of the application.
0
Attacker Value
Unknown
CVE-2021-42111
Disclosure Date: November 10, 2021 (last updated October 07, 2023)
An issue was discovered in the RCDevs OpenOTP app 1.4.13 and 1.4.14 for iOS. If it is installed on a jailbroken device, it is possible to retrieve the PIN code used to access the application. The IOS app version 1.4.1631262629 resolves this issue by storing a hash PIN code.
0
Attacker Value
Unknown
CVE-2021-24571
Disclosure Date: August 23, 2021 (last updated February 23, 2025)
The HD Quiz WordPress plugin before 1.8.4 does not escape some of its Answers before outputting them in attribute when generating the Quiz, which could lead to Stored Cross-Site Scripting issues
0
Attacker Value
Unknown
CVE-2019-15540
Disclosure Date: August 25, 2019 (last updated November 27, 2024)
filters/filter-cso/filter-stream.c in the CSO filter in libMirage 3.2.2 in CDemu does not validate the part size, triggering a heap-based buffer overflow that can lead to root access by a local Linux user.
0
Attacker Value
Unknown
CVE-2018-5370
Disclosure Date: January 16, 2018 (last updated November 26, 2024)
BizLogic xnami 1.0 has XSS via the comment parameter in an addComment action to the /media/ajax URI.
0
Attacker Value
Unknown
CVE-2013-5963
Disclosure Date: September 30, 2013 (last updated October 05, 2023)
Unrestricted file upload vulnerability in multi.php in Simple Dropbox Upload plugin before 1.8.8.1 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/uploads/wpdb/.
0
Attacker Value
Unknown
CVE-2009-2921
Disclosure Date: August 21, 2009 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in login.php in MOC Designs PHP News 1.1 allow remote attackers to execute arbitrary SQL commands via the (1) newsuser parameter (User field) and (2) newspassword parameter (Password field).
0
Attacker Value
Unknown
CVE-2008-6945
Disclosure Date: August 12, 2009 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Interchange 5.7 before 5.7.1, 5.6 before 5.6.1, and 5.4 before 5.4.3 allow remote attackers to inject arbitrary web script or HTML via (1) the mv_order_item CGI variable parameter in Core, (2) the country-select widget, or (3) possibly the value specifier when used in the UserTag feature.
0
Attacker Value
Unknown
CVE-2009-1039
Disclosure Date: March 20, 2009 (last updated October 04, 2023)
Buffer overflow in CDex 1.70b2 allows remote attackers to execute arbitrary code via a crafted Info header in an Ogg Vorbis (.ogg) file.
0