Show filters
287 Total Results
Displaying 111-120 of 287
Sort by:
Attacker Value
Unknown
CVE-2021-44082
Disclosure Date: March 29, 2022 (last updated February 23, 2025)
textpattern 4.8.7 is vulnerable to Cross Site Scripting (XSS) via /textpattern/index.php,Body. A remote and unauthenticated attacker can use XSS to trigger remote code execution by uploading a webshell. To do so they must first steal the CSRF token before submitting a file upload request.
0
Attacker Value
Unknown
CVE-2022-21158
Disclosure Date: March 10, 2022 (last updated February 23, 2025)
A stored cross-site scripting vulnerability in marktext versions prior to v0.17.0 due to improper handling of the link (with javascript: scheme) inside the document may allow an attacker to execute an arbitrary script on the PC of the user using marktext.
0
Attacker Value
Unknown
CVE-2022-25069
Disclosure Date: March 05, 2022 (last updated February 23, 2025)
Mark Text v0.16.3 was discovered to contain a DOM-based cross-site scripting (XSS) vulnerability which allows attackers to perform remote code execution (RCE) via injecting a crafted payload into /lib/contentState/pasteCtrl.js.
0
Attacker Value
Unknown
CVE-2021-44331
Disclosure Date: February 28, 2022 (last updated February 23, 2025)
ARM astcenc 3.2.0 is vulnerable to Buffer Overflow in function encode_ise().
0
Attacker Value
Unknown
CVE-2021-43086
Disclosure Date: February 28, 2022 (last updated February 23, 2025)
ARM astcenc 3.2.0 is vulnerable to Buffer Overflow. When the compression function of the astc-encoder project with -cl option was used, a stack-buffer-overflow occurred in function encode_ise() in function compress_symbolic_block_for_partition_2planes() in "/Source/astcenc_compress_symbolic.cpp".
0
Attacker Value
Unknown
CVE-2022-23853
Disclosure Date: February 11, 2022 (last updated February 23, 2025)
The LSP (Language Server Protocol) plugin in KDE Kate before 21.12.2 and KTextEditor before 5.91.0 tries to execute the associated LSP server binary when opening a file of a given type. If this binary is absent from the PATH, it will try running the LSP server binary in the directory of the file that was just opened (due to a misunderstanding of the QProcess API, that was never intended). This can be an untrusted directory.
0
Attacker Value
Unknown
CVE-2022-24198
Disclosure Date: February 01, 2022 (last updated February 23, 2025)
iText v7.1.17 was discovered to contain an out-of-bounds exception via the component ARCFOUREncryption.encryptARCFOUR, which allows attackers to cause a Denial of Service (DoS) via a crafted PDF file. NOTE: Vendor does not view this as a vulnerability and has not found it to be exploitable.
0
Attacker Value
Unknown
CVE-2022-24197
Disclosure Date: February 01, 2022 (last updated February 23, 2025)
iText v7.1.17 was discovered to contain a stack-based buffer overflow via the component ByteBuffer.append, which allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.
0
Attacker Value
Unknown
CVE-2022-24196
Disclosure Date: February 01, 2022 (last updated February 23, 2025)
iText v7.1.17, up to (exluding)": 7.1.18 and 7.2.2 was discovered to contain an out-of-memory error via the component readStreamBytesRaw, which allows attackers to cause a Denial of Service (DoS) via a crafted PDF file.
0
Attacker Value
Unknown
CVE-2022-24123
Disclosure Date: January 29, 2022 (last updated February 23, 2025)
MarkText through 0.16.3 does not sanitize the input of a mermaid block before rendering. This could lead to Remote Code Execution via a .md file containing a mutation Cross-Site Scripting (XSS) payload.
0