Show filters
381 Total Results
Displaying 141-150 of 381
Sort by:
Attacker Value
Unknown

CVE-2023-33023

Disclosure Date: April 01, 2024 (last updated January 12, 2025)
Memory corruption while processing finish_sign command to pass a rsp buffer.
Attacker Value
Unknown

CVE-2023-28547

Disclosure Date: April 01, 2024 (last updated January 12, 2025)
Memory corruption in SPS Application while requesting for public key in sorter TA.
Attacker Value
Unknown

CVE-2024-1023

Disclosure Date: March 27, 2024 (last updated October 22, 2024)
A vulnerability in the Eclipse Vert.x toolkit results in a memory leak due to using Netty FastThreadLocal data structures. Specifically, when the Vert.x HTTP client establishes connections to different hosts, triggering the memory leak. The leak can be accelerated with intimate runtime knowledge, allowing an attacker to exploit this vulnerability. For instance, a server accepting arbitrary internet addresses could serve as an attack vector by connecting to these addresses, thereby accelerating the memory leak.
0
Attacker Value
Unknown

CVE-2024-2599

Disclosure Date: March 18, 2024 (last updated January 05, 2025)
File upload restriction evasion vulnerability in AMSS++ version 4.31. This vulnerability could allow an authenticated user to potentially obtain RCE through webshell, compromising the entire infrastructure.
0
Attacker Value
Unknown

CVE-2024-2598

Disclosure Date: March 18, 2024 (last updated January 05, 2025)
Vulnerability in AMSS++ version 4.31, which does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /amssplus/modules/book/main/select_send_2.php, in multiple parameters. This vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and steal their session cookie credentials.
0
Attacker Value
Unknown

CVE-2024-2597

Disclosure Date: March 18, 2024 (last updated January 05, 2025)
Vulnerability in AMSS++ version 4.31, which does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /amssplus/modules/book/main/bookdetail_school_person.php, in the 'b_id' parameter. This vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and steal their session cookie credentials.
0
Attacker Value
Unknown

CVE-2024-2596

Disclosure Date: March 18, 2024 (last updated January 05, 2025)
Vulnerability in AMSS++ version 4.31, which does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /amssplus/modules/mail/main/select_send.php, in multiple parameters. This vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and steal their session cookie credentials.
0
Attacker Value
Unknown

CVE-2024-2595

Disclosure Date: March 18, 2024 (last updated January 05, 2025)
Vulnerability in AMSS++ version 4.31, which does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /amssplus/modules/book/main/bookdetail_khet_person.php, in the 'b_id' parameter. This vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and steal their session cookie credentials.
0
Attacker Value
Unknown

CVE-2024-2594

Disclosure Date: March 18, 2024 (last updated January 05, 2025)
Vulnerability in AMSS++ version 4.31, which does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /amssplus/admin/index.php, in multiple parameters. This vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and steal their session cookie credentials.
0
Attacker Value
Unknown

CVE-2024-2593

Disclosure Date: March 18, 2024 (last updated January 05, 2025)
Vulnerability in AMSS++ version 4.31, which does not sufficiently encode user-controlled input, resulting in a Cross-Site Scripting (XSS) vulnerability through /amssplus/modules/book/main/bookdetail_group.php, in the 'b_id' parameter. This vulnerability could allow a remote attacker to send a specially crafted URL to an authenticated user and steal their session cookie credentials.
0