Show filters
557 Total Results
Displaying 101-110 of 557
Sort by:
Attacker Value
Unknown

CVE-2019-13322

Disclosure Date: February 10, 2020 (last updated February 21, 2025)
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Xiaomi Browser Prior to 10.4.0. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the miui.share application. The issue results from the lack of proper validation of user-supplied data, which can result in an arbitrary application download. An attacker can leverage this vulnerability to execute code in the context of the user. Was ZDI-CAN-7483.
Attacker Value
Unknown

CVE-2019-13321

Disclosure Date: February 10, 2020 (last updated February 21, 2025)
This vulnerability allows network adjacent attackers to execute arbitrary code on affected installations of Xiaomi Browser Prior to 10.4.0. User interaction is required to exploit this vulnerability in that the target must connect to a malicious access point. The specific flaw exists within the handling of HTTP responses to the Captive Portal. A crafted HTML response can cause the Captive Portal to to open a browser to a specified location without user interaction. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-7467.
Attacker Value
Unknown

CVE-2019-0219

Disclosure Date: January 14, 2020 (last updated November 27, 2024)
A website running in the InAppBrowser webview on Android could execute arbitrary JavaScript in the main application's webview using a specially crafted gap-iab: URI.
Attacker Value
Unknown

CVE-2019-18893

Disclosure Date: January 13, 2020 (last updated February 21, 2025)
XSS in the Video Downloader component before 1.5 of Avast Secure Browser 77.1.1831.91 and AVG Secure Browser 77.0.1790.77 allows websites to execute their code in the context of this component. While Video Downloader is technically a browser extension, it is granted a very wide set of privileges and can for example access cookies and browsing history, spy on the user while they are surfing the web, and alter their surfing experience in almost arbitrary ways.
Attacker Value
Unknown

CVE-2012-2714

Disclosure Date: January 09, 2020 (last updated February 21, 2025)
The BrowserID (Mozilla Persona) module 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to hijack the authentication of arbitrary users via the audience identifier.
Attacker Value
Unknown

CVE-2019-19502

Disclosure Date: December 02, 2019 (last updated November 27, 2024)
Code injection in pluginconfig.php in Image Uploader and Browser for CKEditor before 4.1.9 allows remote authenticated users to execute arbitrary PHP code.
Attacker Value
Unknown

CVE-2019-16647

Disclosure Date: October 29, 2019 (last updated November 27, 2024)
Unquoted Search Path in Maxthon 5.1.0 to 5.2.7 Browser for Windows.
Attacker Value
Unknown

CVE-2016-10897

Disclosure Date: August 21, 2019 (last updated November 27, 2024)
The sermon-browser plugin before 0.45.16 for WordPress has multiple XSS issues.
0
Attacker Value
Unknown

CVE-2019-13075

Disclosure Date: June 30, 2019 (last updated November 27, 2024)
Tor Browser through 8.5.3 has an information exposure vulnerability. It allows remote attackers to detect the browser's language via vectors involving an IFRAME element, because text in that language is included in the title attribute of a LINK element for a non-HTML page. This is related to a behavior of Firefox before 68.
0
Attacker Value
Unknown

CVE-2019-12133

Disclosure Date: June 18, 2019 (last updated November 27, 2024)
Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory and its sub-folders. Moreover, the services associated with said products try to execute binaries such as sc.exe from the current directory upon system start. This will effectively allow non-privileged users to escalate privileges to NT AUTHORITY\SYSTEM. This affects Desktop Central 10.0.380, EventLog Analyzer 12.0.2, ServiceDesk Plus 10.0.0, SupportCenter Plus 8.1, O365 Manager Plus 4.0, Mobile Device Manager Plus 9.0.0, Patch Connect Plus 9.0.0, Vulnerability Manager Plus 9.0.0, Patch Manager Plus 9.0.0, OpManager 12.3, NetFlow Analyzer 11.0, OpUtils 11.0, Network Configuration Manager 11.0, FireWall 12.0, Key Manager Plus 5.6, Password Manager Pro 9.9, Analytics Plus 1.0, and Browser Security Plus.
0