Show filters
381 Total Results
Displaying 141-150 of 381
Sort by:
Attacker Value
Unknown
CVE-2023-33023
Disclosure Date: April 01, 2024 (last updated January 12, 2025)
Memory corruption while processing finish_sign command to pass a rsp buffer.
0
Attacker Value
Unknown
CVE-2023-28547
Disclosure Date: April 01, 2024 (last updated January 12, 2025)
Memory corruption in SPS Application while requesting for public key in sorter TA.
0
Attacker Value
Unknown
CVE-2024-1023
Disclosure Date: March 27, 2024 (last updated October 22, 2024)
A vulnerability in the Eclipse Vert.x toolkit results in a memory leak due to using Netty FastThreadLocal data structures. Specifically, when the Vert.x HTTP client establishes connections to different hosts, triggering the memory leak. The leak can be accelerated with intimate runtime knowledge, allowing an attacker to exploit this vulnerability. For instance, a server accepting arbitrary internet addresses could serve as an attack vector by connecting to these addresses, thereby accelerating the memory leak.
0
Attacker Value
Unknown
CVE-2024-2599
Disclosure Date: March 18, 2024 (last updated January 05, 2025)
File upload restriction evasion vulnerability in AMSS++ version 4.31. This vulnerability could allow an authenticated user to potentially obtain RCE through webshell, compromising the entire infrastructure.
0
Attacker Value
Unknown
CVE-2024-2598
Disclosure Date: March 18, 2024 (last updated January 05, 2025)
Vulnerability in AMSS++ version 4.31, which does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /amssplus/modules/book/main/select_send_2.php, in multiple parameters. This vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and steal their session cookie credentials.
0
Attacker Value
Unknown
CVE-2024-2597
Disclosure Date: March 18, 2024 (last updated January 05, 2025)
Vulnerability in AMSS++ version 4.31, which does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /amssplus/modules/book/main/bookdetail_school_person.php, in the 'b_id' parameter. This vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and steal their session cookie credentials.
0
Attacker Value
Unknown
CVE-2024-2596
Disclosure Date: March 18, 2024 (last updated January 05, 2025)
Vulnerability in AMSS++ version 4.31, which does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /amssplus/modules/mail/main/select_send.php, in multiple parameters. This vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and steal their session cookie credentials.
0
Attacker Value
Unknown
CVE-2024-2595
Disclosure Date: March 18, 2024 (last updated January 05, 2025)
Vulnerability in AMSS++ version 4.31, which does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /amssplus/modules/book/main/bookdetail_khet_person.php, in the 'b_id' parameter. This vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and steal their session cookie credentials.
0
Attacker Value
Unknown
CVE-2024-2594
Disclosure Date: March 18, 2024 (last updated January 05, 2025)
Vulnerability in AMSS++ version 4.31, which does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /amssplus/admin/index.php, in multiple parameters. This vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and steal their session cookie credentials.
0
Attacker Value
Unknown
CVE-2024-2593
Disclosure Date: March 18, 2024 (last updated January 05, 2025)
Vulnerability in AMSS++ version 4.31, which does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /amssplus/modules/book/main/bookdetail_group.php, in the 'b_id' parameter. This vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and steal their session cookie credentials.
0