Show filters
155 Total Results
Displaying 121-130 of 155
Sort by:
Attacker Value
Unknown
CVE-2019-12215
Disclosure Date: May 20, 2019 (last updated November 08, 2023)
A full path disclosure vulnerability was discovered in Matomo v3.9.1 where a user can trigger a particular error to discover the full path of Matomo on the disk, because lastError.file is used in plugins/CorePluginsAdmin/templates/safemode.twig. NOTE: the vendor disputes the significance of this issue, stating "avoid reporting path disclosures, as we don't consider them as security vulnerabilities.
0
Attacker Value
Unknown
CVE-2016-10620
Disclosure Date: June 01, 2018 (last updated November 26, 2024)
atom-node-module-installer installs node modules for atom-shell applications. atom-node-module-installer binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.
0
Attacker Value
Unknown
CVE-2018-1000006
Disclosure Date: January 24, 2018 (last updated November 08, 2023)
GitHub Electron versions 1.8.2-beta.3 and earlier, 1.7.10 and earlier, 1.6.15 and earlier has a vulnerability in the protocol handler, specifically Electron apps running on Windows 10, 7 or 2008 that register custom protocol handlers can be tricked in arbitrary command execution if the user clicks on a specially crafted URL. This has been fixed in versions 1.8.2-beta.4, 1.7.11, and 1.6.16.
0
Attacker Value
Unknown
CVE-2017-1000424
Disclosure Date: January 02, 2018 (last updated November 26, 2024)
Github Electron version 1.6.4 - 1.6.11 and 1.7.0 - 1.7.5 is vulnerable to a URL Spoofing problem when opening PDFs in PDFium resulting loading arbitrary PDFs that a hacker can control.
0
Attacker Value
Unknown
CVE-2016-6349
Disclosure Date: March 29, 2017 (last updated November 26, 2024)
The machinectl command in oci-register-machine allows local users to list running containers and possibly obtain sensitive information by running that command.
0
Attacker Value
Unknown
CVE-2017-5226
Disclosure Date: March 29, 2017 (last updated November 26, 2024)
When executing a program via the bubblewrap sandbox, the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to push characters into the terminal's input buffer, allowing an attacker to escape the sandbox.
0
Attacker Value
Unknown
CVE-2016-1202
Disclosure Date: April 25, 2016 (last updated November 25, 2024)
Untrusted search path vulnerability in Atom Electron before 0.33.5 allows local users to gain privileges via a Trojan horse Node.js module in a parent directory of a directory named on a require line.
0
Attacker Value
Unknown
CVE-2015-7816
Disclosure Date: November 16, 2015 (last updated October 05, 2023)
The DisplayTopKeywords function in plugins/Referrers/Controller.php in Piwik before 2.15.0 allows remote attackers to conduct PHP object injection attacks, conduct Server-Side Request Forgery (SSRF) attacks, and execute arbitrary PHP code via a crafted HTTP header.
0
Attacker Value
Unknown
CVE-2015-7815
Disclosure Date: November 16, 2015 (last updated October 05, 2023)
Directory traversal vulnerability in core/ViewDataTable/Factory.php in Piwik before 2.15.0 allows remote attackers to include and execute arbitrary local files via the viewDataTable parameter.
0
Attacker Value
Unknown
CVE-2014-7571
Disclosure Date: October 20, 2014 (last updated October 05, 2023)
The Grey's Anatomy Fan (aka nl.jborsje.android.tvfan.greysanatomy) application 3.7.2 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0