Show filters
281 Total Results
Displaying 121-130 of 281
Sort by:
Attacker Value
Unknown

CVE-2021-32622

Disclosure Date: May 17, 2021 (last updated February 22, 2025)
Matrix-React-SDK is a react-based SDK for inserting a Matrix chat/voip client into a web page. Before version 3.21.0, when uploading a file, the local file preview can lead to execution of scripts embedded in the uploaded file. This can only occur after several user interactions to open the preview in a separate tab. This only impacts the local user while in the process of uploading. It cannot be exploited remotely or by other users. This vulnerability is patched in version 3.21.0.
Attacker Value
Unknown

CVE-2021-29453

Disclosure Date: April 19, 2021 (last updated February 22, 2025)
matrix-media-repo is an open-source multi-domain media repository for Matrix. Versions 1.2.6 and earlier of matrix-media-repo do not properly handle malicious images which are crafted to be small in file size, but large in complexity. A malicious user could upload a relatively small image in terms of file size, using particular image formats, which expands to have extremely large dimensions during the process of thumbnailing. The server can be exhausted of memory in the process of trying to load the whole image into memory for thumbnailing, leading to denial of service. Version 1.2.7 has a fix for the vulnerability.
Attacker Value
Unknown

CVE-2021-30000

Disclosure Date: April 02, 2021 (last updated February 22, 2025)
An issue was discovered in LATRIX 0.6.0. SQL injection in the txtaccesscode parameter of inandout.php leads to information disclosure and code execution.
Attacker Value
Unknown

CVE-2021-21623

Disclosure Date: March 18, 2021 (last updated February 22, 2025)
An incorrect permission check in Jenkins Matrix Authorization Strategy Plugin 2.6.5 and earlier allows attackers with Item/Read permission on nested items to access them, even if they lack Item/Read permission for parent folders.
Attacker Value
Unknown

CVE-2021-21320

Disclosure Date: March 02, 2021 (last updated February 22, 2025)
matrix-react-sdk is an npm package which is a Matrix SDK for React Javascript. In matrix-react-sdk before version 3.15.0, the user content sandbox can be abused to trick users into opening unexpected documents. The content is opened with a `blob` origin that cannot access Matrix user data, so messages and secrets are not at risk. This has been fixed in version 3.15.0.
Attacker Value
Unknown

CVE-2021-25906

Disclosure Date: January 26, 2021 (last updated November 28, 2024)
An issue was discovered in the basic_dsp_matrix crate before 0.9.2 for Rust. When a TransformContent panic occurs, a double drop can be performed.
Attacker Value
Unknown

CVE-2019-16747

Disclosure Date: December 30, 2020 (last updated February 22, 2025)
In MatrixSSL before 4.2.2 Open, the DTLS server can encounter an invalid pointer free (leading to memory corruption and a daemon crash) via a crafted incoming network message, a different vulnerability than CVE-2019-14431.
Attacker Value
Unknown

CVE-2020-28206

Disclosure Date: December 02, 2020 (last updated February 22, 2025)
An issue was discovered in Bitrix24 Bitrix Framework (1c site management) 20.0. An "User enumeration and Improper Restriction of Excessive Authentication Attempts" vulnerability exists in the admin login form, allowing a remote user to enumerate users in the administrator group. This also allows brute-force attacks on the passwords of users not in the administrator group.
Attacker Value
Unknown

CVE-2020-2225

Disclosure Date: July 15, 2020 (last updated February 21, 2025)
Jenkins Matrix Project Plugin 1.16 and earlier does not escape the axis names shown in tooltips on the overview page of builds with multiple axes, resulting in a stored cross-site scripting vulnerability.
Attacker Value
Unknown

CVE-2020-2224

Disclosure Date: July 15, 2020 (last updated February 21, 2025)
Jenkins Matrix Project Plugin 1.16 and earlier does not escape the node names shown in tooltips on the overview page of builds with a single axis, resulting in a stored cross-site scripting vulnerability.