Show filters
1,338 Total Results
Displaying 161-170 of 1,338
Sort by:
Attacker Value
Unknown

CVE-2021-42863

Disclosure Date: May 12, 2022 (last updated February 23, 2025)
A buffer overflow in ecma_builtin_typedarray_prototype_filter() in JerryScript version fe3a5c0 allows an attacker to construct a fake object or a fake arraybuffer with unlimited size.
Attacker Value
Unknown

CVE-2022-1682

Disclosure Date: May 12, 2022 (last updated February 23, 2025)
Reflected Xss using url based payload in GitHub repository neorazorx/facturascripts prior to 2022.07. Xss can use to steal user's cookies which lead to Account takeover or do any malicious activity in victim's browser
Attacker Value
Unknown

CVE-2022-30286

Disclosure Date: May 09, 2022 (last updated October 07, 2023)
pyscriptjs (aka PyScript Demonstrator) in PyScript through 2022-05-04 allows a remote user to read Python source code.
Attacker Value
Unknown

CVE-2022-1571

Disclosure Date: May 04, 2022 (last updated February 23, 2025)
Cross-site scripting - Reflected in Create Subaccount in GitHub repository neorazorx/facturascripts prior to 2022.07. This vulnerability can be arbitrarily executed javascript code to steal user'cookie, perform HTTP request, get content of `same origin` page, etc ...
Attacker Value
Unknown

CVE-2021-41959

Disclosure Date: May 03, 2022 (last updated February 23, 2025)
JerryScript Git version 14ff5bf does not sufficiently track and release allocated memory via jerry-core/ecma/operations/ecma-regexp-object.c after RegExp, which causes a memory leak.
Attacker Value
Unknown

CVE-2022-1514

Disclosure Date: April 28, 2022 (last updated February 23, 2025)
Stored XSS via upload plugin functionality in zip format in GitHub repository neorazorx/facturascripts prior to 2022.06. Cross-site scripting attacks can have devastating consequences. Code injected into a vulnerable application can exfiltrate data or install malware on the user's machine. Attackers can masquerade as authorized users via session cookies, allowing them to perform any action allowed by the user account.
Attacker Value
Unknown

CVE-2022-1457

Disclosure Date: April 25, 2022 (last updated February 23, 2025)
Store XSS in title parameter executing at EditUser Page & EditProducto page in GitHub repository neorazorx/facturascripts prior to 2022.04. Cross-site scripting attacks can have devastating consequences. Code injected into a vulnerable application can exfiltrate data or install malware on the user's machine. Attackers can masquerade as authorized users via session cookies, allowing them to perform any action allowed by the user account.
Attacker Value
Unknown

CVE-2021-43453

Disclosure Date: April 07, 2022 (last updated February 23, 2025)
A Heap-based Buffer Overflow vulnerability exists in JerryScript 2.4.0 and prior versions via an out-of-bounds read in parser_parse_for_statement_start in the js-parser-statm.c file. This issue is similar to CVE-2020-29657.
Attacker Value
Unknown

CVE-2021-41752

Disclosure Date: April 05, 2022 (last updated February 23, 2025)
Stack overflow vulnerability in Jerryscript before commit e1ce7dd7271288be8c0c8136eea9107df73a8ce2 on Oct 20, 2021 due to an unbounded recursive call to the new opt() function.
Attacker Value
Unknown

CVE-2021-41751

Disclosure Date: April 05, 2022 (last updated February 23, 2025)
Buffer overflow vulnerability in file ecma-builtin-array-prototype.c:909 in function ecma_builtin_array_prototype_object_slice in Jerryscript before commit e1ce7dd7271288be8c0c8136eea9107df73a8ce2 on Oct 20, 2021.