Show filters
251 Total Results
Displaying 121-130 of 251
Sort by:
Attacker Value
Unknown

CVE-2018-15861

Disclosure Date: August 25, 2018 (last updated November 27, 2024)
Unchecked NULL pointer usage in ExprResolveLhs in xkbcomp/expr.c in xkbcommon before 0.8.2 could be used by local attackers to crash (NULL pointer dereference) the xkbcommon parser by supplying a crafted keymap file that triggers an xkb_intern_atom failure.
0
Attacker Value
Unknown

CVE-2018-15853

Disclosure Date: August 25, 2018 (last updated November 27, 2024)
Endless recursion exists in xkbcomp/expr.c in xkbcommon and libxkbcommon before 0.8.1, which could be used by local attackers to crash xkbcommon users by supplying a crafted keymap file that triggers boolean negation.
0
Attacker Value
Unknown

CVE-2018-13746

Disclosure Date: July 09, 2018 (last updated November 27, 2024)
The mintToken function of a smart contract implementation for kBit, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
0
Attacker Value
Unknown

CVE-2016-10537

Disclosure Date: May 31, 2018 (last updated November 26, 2024)
backbone is a module that adds in structure to a JavaScript heavy application through key-value pairs and custom events connecting to your RESTful API through JSON There exists a potential Cross Site Scripting vulnerability in the `Model#Escape` function of backbone 0.3.3 and earlier, if a user is able to supply input. This is due to the regex that's replacing things to miss the conversion of things such as `<` to `<`.
0
Attacker Value
Unknown

CVE-2017-18262

Disclosure Date: April 30, 2018 (last updated November 26, 2024)
Blackboard Learn (Since at least 17th of October 2017) has allowed Unvalidated Redirects on any signed-in user through its endpoints for handling Shibboleth logins, as demonstrated by a webapps/bb-auth-provider-shibboleth-BBLEARN/execute/shibbolethLogin?returnUrl= URI.
0
Attacker Value
Unknown

CVE-2018-13257

Disclosure Date: April 18, 2018 (last updated November 27, 2024)
The bb-auth-provider-cas authentication module within Blackboard Learn 2018-07-02 is susceptible to HTTP host header spoofing during Central Authentication Service (CAS) service ticket validation, enabling a phishing attack from the CAS server login page.
Attacker Value
Unknown

CVE-2017-17442

Disclosure Date: March 13, 2018 (last updated September 17, 2024)
In BlackBerry UEM Management Console version 12.7.1 and earlier, a reflected cross-site scripting vulnerability that could allow an attacker to execute script commands in the context of the affected UEM Management Console account by crafting a malicious link and then persuading a user with legitimate access to the Management Console to click on the malicious link.
0
Attacker Value
Unknown

CVE-2017-18011

Disclosure Date: January 01, 2018 (last updated November 26, 2024)
The MyCBGenie Affiliate Ads for Clickbank Products plugin through 1.6 for WordPress has XSS via the text_ads_ajax.php border_color parameter.
0
Attacker Value
Unknown

CVE-2017-3892

Disclosure Date: November 14, 2017 (last updated November 26, 2024)
In BlackBerry QNX Software Development Platform (SDP) 6.6.0, an information disclosure vulnerability in the default configuration of the QNX SDP could allow an attacker to gain information relating to memory layout that could be used in a blended attack by executing commands targeting procfs resources.
0
Attacker Value
Unknown

CVE-2017-9371

Disclosure Date: November 14, 2017 (last updated November 26, 2024)
In BlackBerry QNX Software Development Platform (SDP) 6.6.0 and 6.5.0 SP1 and earlier, a loss of integrity vulnerability in the default configuration of the QNX SDP could allow an attacker being able to reduce the entropy of the PRNG, making other blended attacks more practical by gaining control over environmental factors that influence seed generation.
0