Show filters
155 Total Results
Displaying 121-130 of 155
Sort by:
Attacker Value
Unknown

CVE-2019-12215

Disclosure Date: May 20, 2019 (last updated November 08, 2023)
A full path disclosure vulnerability was discovered in Matomo v3.9.1 where a user can trigger a particular error to discover the full path of Matomo on the disk, because lastError.file is used in plugins/CorePluginsAdmin/templates/safemode.twig. NOTE: the vendor disputes the significance of this issue, stating "avoid reporting path disclosures, as we don't consider them as security vulnerabilities.
0
Attacker Value
Unknown

CVE-2016-10620

Disclosure Date: June 01, 2018 (last updated November 26, 2024)
atom-node-module-installer installs node modules for atom-shell applications. atom-node-module-installer binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.
0
Attacker Value
Unknown

CVE-2018-1000006

Disclosure Date: January 24, 2018 (last updated November 08, 2023)
GitHub Electron versions 1.8.2-beta.3 and earlier, 1.7.10 and earlier, 1.6.15 and earlier has a vulnerability in the protocol handler, specifically Electron apps running on Windows 10, 7 or 2008 that register custom protocol handlers can be tricked in arbitrary command execution if the user clicks on a specially crafted URL. This has been fixed in versions 1.8.2-beta.4, 1.7.11, and 1.6.16.
0
Attacker Value
Unknown

CVE-2017-1000424

Disclosure Date: January 02, 2018 (last updated November 26, 2024)
Github Electron version 1.6.4 - 1.6.11 and 1.7.0 - 1.7.5 is vulnerable to a URL Spoofing problem when opening PDFs in PDFium resulting loading arbitrary PDFs that a hacker can control.
0
Attacker Value
Unknown

CVE-2016-6349

Disclosure Date: March 29, 2017 (last updated November 26, 2024)
The machinectl command in oci-register-machine allows local users to list running containers and possibly obtain sensitive information by running that command.
0
Attacker Value
Unknown

CVE-2017-5226

Disclosure Date: March 29, 2017 (last updated November 26, 2024)
When executing a program via the bubblewrap sandbox, the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to push characters into the terminal's input buffer, allowing an attacker to escape the sandbox.
0
Attacker Value
Unknown

CVE-2016-1202

Disclosure Date: April 25, 2016 (last updated November 25, 2024)
Untrusted search path vulnerability in Atom Electron before 0.33.5 allows local users to gain privileges via a Trojan horse Node.js module in a parent directory of a directory named on a require line.
0
Attacker Value
Unknown

CVE-2015-7816

Disclosure Date: November 16, 2015 (last updated October 05, 2023)
The DisplayTopKeywords function in plugins/Referrers/Controller.php in Piwik before 2.15.0 allows remote attackers to conduct PHP object injection attacks, conduct Server-Side Request Forgery (SSRF) attacks, and execute arbitrary PHP code via a crafted HTTP header.
0
Attacker Value
Unknown

CVE-2015-7815

Disclosure Date: November 16, 2015 (last updated October 05, 2023)
Directory traversal vulnerability in core/ViewDataTable/Factory.php in Piwik before 2.15.0 allows remote attackers to include and execute arbitrary local files via the viewDataTable parameter.
0
Attacker Value
Unknown

CVE-2014-7571

Disclosure Date: October 20, 2014 (last updated October 05, 2023)
The Grey's Anatomy Fan (aka nl.jborsje.android.tvfan.greysanatomy) application 3.7.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0