Show filters
398 Total Results
Displaying 181-190 of 398
Sort by:
Attacker Value
Unknown
CVE-2021-27807
Disclosure Date: March 19, 2021 (last updated February 22, 2025)
A carefully crafted PDF file can trigger an infinite loop while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.
0
Attacker Value
Unknown
CVE-2021-27906
Disclosure Date: March 19, 2021 (last updated February 22, 2025)
A carefully crafted PDF file can trigger an OutOfMemory-Exception while loading the file. This issue affects Apache PDFBox version 2.0.22 and prior 2.0.x versions.
0
Attacker Value
Unknown
CVE-2019-25025
Disclosure Date: March 05, 2021 (last updated February 22, 2025)
The activerecord-session_store (aka Active Record Session Store) component through 1.1.3 for Ruby on Rails does not use a constant-time approach when delivering information about whether a guessed session ID is valid. Consequently, remote attackers can leverage timing discrepancies to achieve a correct guess in a relatively short amount of time. This is a related issue to CVE-2019-16782.
0
Attacker Value
Unknown
CVE-2020-4856
Disclosure Date: February 26, 2021 (last updated February 22, 2025)
IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190459.
0
Attacker Value
Unknown
CVE-2020-4975
Disclosure Date: February 26, 2021 (last updated February 22, 2025)
IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 192435.
0
Attacker Value
Unknown
CVE-2021-20350
Disclosure Date: February 26, 2021 (last updated February 22, 2025)
IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194707.
0
Attacker Value
Unknown
CVE-2020-4866
Disclosure Date: February 26, 2021 (last updated February 22, 2025)
IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190742.
0
Attacker Value
Unknown
CVE-2021-20351
Disclosure Date: February 26, 2021 (last updated February 22, 2025)
IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 194708.
0
Attacker Value
Unknown
CVE-2020-4863
Disclosure Date: February 26, 2021 (last updated February 22, 2025)
IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190566.
0
Attacker Value
Unknown
CVE-2020-4857
Disclosure Date: February 26, 2021 (last updated February 22, 2025)
IBM Engineering products are vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 190460.
0