Show filters
744 Total Results
Displaying 121-130 of 744
Sort by:
Attacker Value
Unknown
CVE-2024-22200
Disclosure Date: January 30, 2024 (last updated February 09, 2024)
vantage6-UI is the User Interface for vantage6. The docker image used to run the UI leaks the nginx version. To mitigate the vulnerability, users can run the UI as an angular application. This vulnerability was patched in 4.2.0.
0
Attacker Value
Unknown
CVE-2024-22193
Disclosure Date: January 30, 2024 (last updated February 09, 2024)
The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). There are no checks on whether the input is encrypted if a task is created in an encrypted collaboration. Therefore, a user may accidentally create a task with sensitive input data that will then be stored unencrypted in a database. Users should ensure they set the encryption setting correctly. This vulnerability is patched in 4.2.0.
0
Attacker Value
Unknown
CVE-2024-21671
Disclosure Date: January 30, 2024 (last updated February 09, 2024)
The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). It is possible to find out usernames from the response time of login requests. This could aid attackers in credential attacks. Version 4.2.0 patches this vulnerability.
0
Attacker Value
Unknown
CVE-2024-21653
Disclosure Date: January 30, 2024 (last updated February 09, 2024)
The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). Nodes and servers get a ssh config by default that permits root login with password authentication. In a proper deployment, the SSH service is not exposed so there is no risk, but not all deployments are ideal. The default should therefore be less permissive. The vulnerability can be mitigated by removing the ssh part from the docker file and rebuilding the docker image. Version 4.2.0 patches the vulnerability.
0
Attacker Value
Unknown
CVE-2024-21649
Disclosure Date: January 30, 2024 (last updated February 09, 2024)
The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). Prior to 4.2.0, authenticated users could inject code into algorithm environment variables, resulting in remote code execution. This vulnerability is patched in 4.2.0.
0
Attacker Value
Unknown
CVE-2024-0343
Disclosure Date: January 09, 2024 (last updated February 25, 2025)
A vulnerability classified as problematic was found in CodeAstro Simple House Rental System 5.6. Affected by this vulnerability is an unknown functionality of the component Login Panel. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250111.
0
Attacker Value
Unknown
CVE-2023-52208
Disclosure Date: January 08, 2024 (last updated February 25, 2025)
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Constant Contact Constant Contact Forms.This issue affects Constant Contact Forms: from n/a through 2.4.2.
0
Attacker Value
Unknown
CVE-2023-51535
Disclosure Date: January 05, 2024 (last updated February 25, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in СleanTalk - Anti-Spam Protection Spam protection, Anti-Spam, FireWall by CleanTalk.This issue affects Spam protection, Anti-Spam, FireWall by CleanTalk: from n/a through 6.20.
0
Attacker Value
Unknown
CVE-2023-49553
Disclosure Date: January 02, 2024 (last updated January 10, 2024)
An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_destroy function in the msj.c file.
0
Attacker Value
Unknown
CVE-2023-49552
Disclosure Date: January 02, 2024 (last updated February 25, 2025)
An Out of Bounds Write in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjs_op_json_stringify function in the msj.c file.
0