Show filters
809 Total Results
Displaying 171-180 of 809
Sort by:
Attacker Value
Unknown
CVE-2023-20046
Disclosure Date: May 09, 2023 (last updated February 24, 2025)
A vulnerability in the key-based SSH authentication feature of Cisco StarOS Software could allow an authenticated, remote attacker to elevate privileges on an affected device.
This vulnerability is due to insufficient validation of user-supplied credentials. An attacker could exploit this vulnerability by sending a valid low-privileged SSH key to an affected device from a host that has an IP address that is configured as the source for a high-privileged user account. A successful exploit could allow the attacker to log in to the affected device through SSH as a high-privileged user.
There are workarounds that address this vulnerability.
0
Attacker Value
Unknown
CVE-2023-31287
Disclosure Date: April 27, 2023 (last updated February 24, 2025)
An issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. Password reset links are sent by email. A link contains a token that is used to reset the password. This token remains valid even after the password reset and can be used a second time to change the password of the corresponding user. The token expires only 3 hours after issuance and is sent as a query parameter when resetting. An attacker with access to the browser history can thus use the token again to change the password in order to take over the account.
0
Attacker Value
Unknown
CVE-2023-31286
Disclosure Date: April 27, 2023 (last updated February 24, 2025)
An issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. When a password reset request occurs, the server response leaks the existence of users. If one tries to reset a password of a non-existent user, an error message indicates that this user does not exist.
0
Attacker Value
Unknown
CVE-2023-31285
Disclosure Date: April 27, 2023 (last updated February 24, 2025)
An XSS issue was discovered in Serenity Serene (and StartSharp) before 6.7.0. When users upload temporary files, some specific file endings are not allowed, but it is possible to upload .html or .htm files containing an XSS payload. The resulting link can be sent to an administrator user.
0
Attacker Value
Unknown
CVE-2023-30798
Disclosure Date: April 21, 2023 (last updated February 24, 2025)
There MultipartParser usage in Encode's Starlette python framework before versions 0.25.0 allows an unauthenticated and remote attacker to specify any number of form fields or files which can cause excessive memory usage resulting in denial of service of the HTTP service.
0
Attacker Value
Unknown
CVE-2021-43819
Disclosure Date: April 19, 2023 (last updated February 24, 2025)
Stargate-Bukkit is a mod for the minecraft video game which adds a portal focused environment. In affected versions Minecarts with chests will drop their items when teleporting through a portal; when they reappear, they will still have their items impacting the integrity of the game world. The teleport code has since been rewritten and is available in release `0.11.5.1`. Users are advised to upgrade. There are no known workarounds for this issue.
0
Attacker Value
Unknown
CVE-2023-22660
Disclosure Date: April 05, 2023 (last updated February 24, 2025)
A heap-based buffer overflow vulnerability exists in the way Ichitaro version 2022 1.0.1.57600 processes certain LayoutBox stream record types. A specially crafted document can cause a buffer overflow, leading to memory corruption, which can result in arbitrary code execution.To trigger this vulnerability, the victim would need to open a malicious, attacker-created document.
0
Attacker Value
Unknown
CVE-2023-22291
Disclosure Date: April 05, 2023 (last updated February 24, 2025)
An invalid free vulnerability exists in the Frame stream parser functionality of Ichitaro 2022 1.0.1.57600. A specially crafted document can lead to an attempt to free a stack pointer, which causes memory corruption. An attacker can provide a malicious file to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2022-45115
Disclosure Date: April 05, 2023 (last updated February 24, 2025)
A buffer overflow vulnerability exists in the Attribute Arena functionality of Ichitaro 2022 1.0.1.57600. A specially crafted document can lead to memory corruption. An attacker can provide a malicious file to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2022-43664
Disclosure Date: April 05, 2023 (last updated February 24, 2025)
A use-after-free vulnerability exists within the way Ichitaro Word Processor 2022, version 1.0.1.57600, processes protected documents. A specially crafted document can trigger reuse of freed memory, which can lead to further memory corruption and potentially result in arbitrary code execution. An attacker can provide a malicious document to trigger this vulnerability.
0