Show filters
203 Total Results
Displaying 171-180 of 203
Sort by:
Attacker Value
Unknown
CVE-2019-19133
Disclosure Date: August 07, 2019 (last updated November 27, 2024)
The CSS Hero plugin through 4.0.3 for WordPress is prone to reflected XSS via the URI in a csshero_action=edit_page request because it fails to sufficiently sanitize user-supplied input. An attacker may leverage this issue to execute arbitrary JavaScript in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookies or launch other attacks.
0
Attacker Value
Unknown
CVE-2019-1010218
Disclosure Date: July 22, 2019 (last updated November 27, 2024)
Cherokee Webserver Latest Cherokee Web server Upto Version 1.2.103 (Current stable) is affected by: Buffer Overflow - CWE-120. The impact is: Crash. The component is: Main cherokee command. The attack vector is: Overwrite argv[0] to an insane length with execl. The fixed version is: There's no fix yet.
0
Attacker Value
Unknown
CVE-2018-11789
Disclosure Date: March 21, 2019 (last updated November 08, 2023)
When accessing the heron-ui webpage, people can modify the file paths outside of the current container to access any file on the host. Example woule be modifying the parameter path= to go to the directory you would like to view. i.e. ..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd.
0
Attacker Value
Unknown
CVE-2018-17987
Disclosure Date: December 26, 2018 (last updated November 27, 2024)
The determineWinner function of a smart contract implementation for HashHeroes Tiles, an Ethereum game, uses a certain blockhash value in an attempt to generate a random number for the case where NUM_TILES equals the number of people who purchased a tile, which allows an attacker to control the awarding of the prize by being the last person to purchase a tile.
0
Attacker Value
Unknown
CVE-2018-15183
Disclosure Date: August 09, 2018 (last updated November 27, 2024)
PHP Scripts Mall Myperfectresume / JobHero / Resume Clone Script 2.0.6 has Stored XSS via the Full Name and Title fields.
0
Attacker Value
Unknown
CVE-2017-5711
Disclosure Date: November 21, 2017 (last updated November 26, 2024)
Multiple buffer overflows in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allow attacker with local access to the system to execute arbitrary code with AMT execution privilege.
0
Attacker Value
Unknown
CVE-2017-5712
Disclosure Date: November 21, 2017 (last updated November 26, 2024)
Buffer overflow in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allows attacker with remote Admin access to the system to execute arbitrary code with AMT execution privilege.
0
Attacker Value
Unknown
CVE-2016-1000137
Disclosure Date: October 10, 2016 (last updated November 25, 2024)
Reflected XSS in wordpress plugin hero-maps-pro v2.1.0
0
Attacker Value
Unknown
CVE-2014-7070
Disclosure Date: October 19, 2014 (last updated October 05, 2023)
The Air War Hero (aka com.dev.airwar) application 3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0
Attacker Value
Unknown
CVE-2014-6434
Disclosure Date: October 07, 2014 (last updated October 05, 2023)
gpExec in GoPro HERO 3+ allows remote attackers to execute arbitrary commands via a the (1) a1 or (2) a2 parameter in a restart action.
0