Show filters
2,224 Total Results
Displaying 141-150 of 2,224
Sort by:
Attacker Value
Unknown

CVE-2022-4542

Disclosure Date: January 23, 2023 (last updated October 08, 2023)
The Compact WP Audio Player WordPress plugin before 1.9.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
Attacker Value
Unknown

CVE-2022-46449

Disclosure Date: January 10, 2023 (last updated February 24, 2025)
An issue in MPD (Music Player Daemon) v0.23.10 allows attackers to cause a Denial of Service (DoS) via a crafted input.
Attacker Value
Unknown

CVE-2019-25086

Disclosure Date: December 27, 2022 (last updated February 24, 2025)
A vulnerability was found in IET-OU Open Media Player up to 1.5.0. It has been declared as problematic. This vulnerability affects the function webvtt of the file application/controllers/timedtext.php. The manipulation of the argument ttml_url leads to cross site scripting. The attack can be initiated remotely. Upgrading to version 1.5.1 is able to address this issue. The name of the patch is 3f39f2d68d11895929c04f7b49b97a734ae7cd1f. It is recommended to upgrade the affected component. VDB-216862 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2022-3985

Disclosure Date: December 19, 2022 (last updated October 08, 2023)
The Videojs HTML5 Player WordPress plugin before 1.1.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks
Attacker Value
Unknown

CVE-2022-3984

Disclosure Date: December 19, 2022 (last updated October 08, 2023)
The Flowplayer Video Player WordPress plugin before 1.0.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks
Attacker Value
Unknown

CVE-2022-3937

Disclosure Date: December 19, 2022 (last updated October 08, 2023)
The Easy Video Player WordPress plugin before 1.2.2.3 does not sanitize and escapes some parameters, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks.
Attacker Value
Unknown

CVE-2022-2951

Disclosure Date: December 13, 2022 (last updated February 24, 2025)
Altair HyperView Player versions 2021.1.0.27 and prior are vulnerable to improper validation of array index vulnerability during processing of H3D files. A DWORD value from a PoC file is extracted and used as an index to write to a buffer, leading to memory corruption.
Attacker Value
Unknown

CVE-2022-2950

Disclosure Date: December 13, 2022 (last updated February 24, 2025)
Altair HyperView Player versions 2021.1.0.27 and prior are vulnerable to the use of uninitialized memory vulnerability during parsing of H3D files. A DWORD is extracted from an uninitialized buffer and, after sign extension, is used as an index into a stack variable to increment a counter leading to memory corruption.
Attacker Value
Unknown

CVE-2022-2949

Disclosure Date: December 13, 2022 (last updated February 24, 2025)
Altair HyperView Player versions 2021.1.0.27 and prior are vulnerable to the use of uninitialized memory vulnerability during parsing of H3D files. A DWORD is extracted from an uninitialized buffer and, after sign extension, is used as an index into a stack variable to increment a counter leading to memory corruption.
Attacker Value
Unknown

CVE-2022-2947

Disclosure Date: December 13, 2022 (last updated February 24, 2025)
Altair HyperView Player versions 2021.1.0.27 and prior perform operations on a memory buffer but can read from or write to a memory location outside of the intended boundary of the buffer. This hits initially as a read access violation, leading to a memory corruption situation.