Show filters
15 Total Results
Displaying 11-15 of 15
Sort by:
Attacker Value
Unknown
CVE-2023-40580
Disclosure Date: August 25, 2023 (last updated February 25, 2025)
Freighter is a Stellar chrome extension. It may be possible for a malicious website to access the recovery mnemonic phrase when the Freighter wallet is unlocked. This vulnerability impacts access control to the mnemonic recovery phrase. This issue was patched in version 5.3.1.
0
Attacker Value
Unknown
CVE-2023-28371
Disclosure Date: March 15, 2023 (last updated February 24, 2025)
In Stellarium through 1.2, attackers can write to files that are typically unintended, such as ones with absolute pathnames or .. directory traversal.
0
Attacker Value
Unknown
CVE-2021-32738
Disclosure Date: July 02, 2021 (last updated February 22, 2025)
js-stellar-sdk is a Javascript library for communicating with a Stellar Horizon server. The `Utils.readChallengeTx` function used in SEP-10 Stellar Web Authentication states in its function documentation that it reads and validates the challenge transaction including verifying that the `serverAccountID` has signed the transaction. In js-stellar-sdk before version 8.2.3, the function does not verify that the server has signed the transaction. Applications that also used `Utils.verifyChallengeTxThreshold` or `Utils.verifyChallengeTxSigners` to verify the signatures including the server signature on the challenge transaction are unaffected as those functions verify the server signed the transaction. Applications calling `Utils.readChallengeTx` should update to version 8.2.3, the first version with a patch for this vulnerability, to ensure that the challenge transaction is completely valid and signed by the server creating the challenge transaction.
0
Attacker Value
Unknown
CVE-2019-15109
Disclosure Date: August 21, 2019 (last updated October 08, 2024)
The the-events-calendar plugin before 4.8.2 for WordPress has XSS via the tribe_paged URL parameter.
0
Attacker Value
Unknown
CVE-2002-0916
Disclosure Date: October 04, 2002 (last updated February 22, 2025)
Format string vulnerability in the allowuser code for the Stellar-X msntauth authentication module, as distributed in Squid 2.4.STABLE6 and earlier, allows remote attackers to execute arbitrary code via format strings in the user name, which are not properly handled in a syslog call.
0