Show filters
1,462 Total Results
Displaying 151-160 of 1,462
Sort by:
Attacker Value
Unknown

CVE-2024-36289

Disclosure Date: June 17, 2024 (last updated February 26, 2025)
Reusing a nonce, key pair in encryption issue exists in "FreeFrom - the nostr client" App versions prior to 1.3.5 for Android and iOS. If this vulnerability is exploited, the content of direct messages (DMs) between users may be manipulated by a man-in-the-middle attack.
0
Attacker Value
Unknown

CVE-2024-36279

Disclosure Date: June 17, 2024 (last updated February 26, 2025)
Reliance on obfuscation or encryption of security-relevant inputs without integrity checking issue exists in "FreeFrom - the nostr client" App versions prior to 1.3.5 for Android and iOS. If this vulnerability is exploited, the content of direct messages (DMs) between users may be manipulated by a man-in-the-middle attack.
0
Attacker Value
Unknown

CVE-2024-36277

Disclosure Date: June 17, 2024 (last updated February 26, 2025)
Improper verification of cryptographic signature issue exists in "FreeFrom - the nostr client" App versions prior to 1.3.5 for Android and iOS. The affected app cannot detect event data with invalid signatures.
0
Attacker Value
Unknown

CVE-2024-3467

Disclosure Date: June 12, 2024 (last updated February 26, 2025)
There is a vulnerability in AVEVA PI Asset Framework Client that could allow malicious code to execute on the PI System Explorer environment under the privileges of an interactive user that was socially engineered to import XML supplied by an attacker.
Attacker Value
Unknown

CVE-2024-5739

Disclosure Date: June 12, 2024 (last updated June 12, 2024)
The in-app browser of LINE client for iOS versions below 14.9.0 contains a Universal XSS (UXSS) vulnerability. This vulnerability allows for cross-site scripting (XSS) where arbitrary JavaScript can be executed in the top frame from an embedded iframe on any displayed web site within the in-app browser. The in-app browser is usually opened by tapping on URLs contained in chat messages, and for the attack to be successful, the victim must trigger a click event on a malicious iframe. If an iframe embedded in any website can be controlled by an attacker, this vulnerability could be exploited to capture or alter content displayed in the top frame, as well as user session information. This vulnerability affects LINE client for iOS versions below 14.9.0 and does not affect other LINE clients such as LINE client for Android. Please update LINE client for iOS to version 14.9.0 or higher.
0
Attacker Value
Unknown

CVE-2024-37296

Disclosure Date: June 11, 2024 (last updated February 26, 2025)
The Aimeos HTML client provides Aimeos HTML components for e-commerce projects. Starting in version 2020.04.1 and prior to versions 2020.10.27, 2021.10.21, 2022.10.12, 2023.10.14, and 2024.04.5, digital downloads sold in online shops can be downloaded without valid payment, e.g. if the payment didn't succeed. Versions 2020.10.27, 2021.10.21, 2022.10.12, 2023.10.14, and 2024.04.5 fix this issue.
0
Attacker Value
Unknown

CVE-2024-34686

Disclosure Date: June 11, 2024 (last updated February 26, 2025)
Due to insufficient input validation, SAP CRM WebClient UI allows an unauthenticated attacker to craft a URL link which embeds a malicious script. When a victim clicks on this link, the script will be executed in the victim's browser giving the attacker the ability to access and/or modify information with no effect on availability of the application.
Attacker Value
Unknown

CVE-2023-38042

Disclosure Date: May 31, 2024 (last updated February 26, 2025)
A local privilege escalation vulnerability in Ivanti Secure Access Client for Windows allows a low privileged user to execute code as SYSTEM.
0
Attacker Value
Unknown

CVE-2024-2451

Disclosure Date: May 28, 2024 (last updated February 26, 2025)
Improper fingerprint validation in the TeamViewer Client (Full & Host) prior Version 15.54 for Windows and macOS allows an attacker with administrative user rights to further elevate privileges via executable sideloading.
0
Attacker Value
Unknown

CVE-2024-22429

Disclosure Date: May 17, 2024 (last updated February 26, 2025)
Dell BIOS contains an Improper Input Validation vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to arbitrary code execution.