Show filters
819 Total Results
Displaying 191-200 of 819
Sort by:
Attacker Value
Unknown

CVE-2023-27371

Disclosure Date: February 28, 2023 (last updated February 24, 2025)
GNU libmicrohttpd before 0.9.76 allows remote DoS (Denial of Service) due to improper parsing of a multipart/form-data boundary in the postprocessor.c MHD_create_post_processor() method. This allows an attacker to remotely send a malicious HTTP POST packet that includes one or more '\0' bytes in a multipart/form-data boundary field, which - assuming a specific heap layout - will result in an out-of-bounds read and a crash in the find_boundary() function.
Attacker Value
Unknown

CVE-2023-1081

Disclosure Date: February 28, 2023 (last updated February 24, 2025)
Cross-site Scripting (XSS) - Stored in GitHub repository microweber/microweber prior to 1.3.3.
Attacker Value
Unknown

CVE-2023-0755

Disclosure Date: February 23, 2023 (last updated February 24, 2025)
The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code.
Attacker Value
Unknown

CVE-2023-0754

Disclosure Date: February 23, 2023 (last updated February 24, 2025)
The affected products are vulnerable to an integer overflow or wraparound, which could  allow an attacker to crash the server and remotely execute arbitrary code.
Attacker Value
Unknown

CVE-2021-32856

Disclosure Date: February 21, 2023 (last updated February 24, 2025)
Microweber is a drag and drop website builder and content management system. Versions 1.2.12 and prior are vulnerable to copy-paste cross-site scripting (XSS). For this particular type of XSS, the victim needs to be fooled into copying a malicious payload into the text editor. A fix was attempted in versions 1.2.9 and 1.2.12, but it is incomplete.
Attacker Value
Unknown

CVE-2022-43779

Disclosure Date: February 12, 2023 (last updated February 24, 2025)
A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in certain HP PC products using AMI UEFI Firmware (system BIOS) which might allow arbitrary code execution, denial of service, and information disclosure. AMI has released updates to mitigate the potential vulnerability.
Attacker Value
Unknown

CVE-2022-27538

Disclosure Date: February 01, 2023 (last updated February 24, 2025)
A potential Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in the BIOS for certain HP PC products which may allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability.
Attacker Value
Unknown

CVE-2022-27537

Disclosure Date: February 01, 2023 (last updated October 08, 2023)
Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate these potential vulnerabilities.
Attacker Value
Unknown

CVE-2021-3809

Disclosure Date: February 01, 2023 (last updated October 08, 2023)
Potential security vulnerabilities have been identified in the BIOS (UEFI Firmware) for certain HP PC products, which might allow arbitrary code execution. HP is releasing firmware updates to mitigate these potential vulnerabilities.
Attacker Value
Unknown

CVE-2021-3808

Disclosure Date: February 01, 2023 (last updated October 08, 2023)
Potential security vulnerabilities have been identified in the BIOS (UEFI Firmware) for certain HP PC products, which might allow arbitrary code execution. HP is releasing firmware updates to mitigate these potential vulnerabilities.