Show filters
698 Total Results
Displaying 191-200 of 698
Sort by:
Attacker Value
Unknown

CVE-2022-2057

Disclosure Date: June 30, 2022 (last updated February 24, 2025)
Divide By Zero error in tiffcrop in libtiff 4.4.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f3a5e010.
Attacker Value
Unknown

CVE-2022-2056

Disclosure Date: June 30, 2022 (last updated February 24, 2025)
Divide By Zero error in tiffcrop in libtiff 4.4.0 allows attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit f3a5e010.
Attacker Value
Unknown

CVE-2022-33910

Disclosure Date: June 24, 2022 (last updated February 24, 2025)
An XSS vulnerability in MantisBT before 2.25.5 allows remote attackers to attach crafted SVG documents to issue reports or bugnotes. When a user or an admin clicks on the attachment, file_download.php opens the SVG document in a browser tab instead of downloading it as a file, causing the JavaScript code to execute.
Attacker Value
Unknown

CVE-2021-36609

Disclosure Date: June 16, 2022 (last updated February 23, 2025)
Cross Site Scripting (XSS) vulnerability in webTareas 2.2p1 via the Name field to /linkedcontent/editfolder.php.
Attacker Value
Unknown

CVE-2021-36608

Disclosure Date: June 16, 2022 (last updated February 23, 2025)
Cross Site Scripting (XSS) vulnerability in webTareas 2.2p1 via the Name field to /projects/editproject.php.
Attacker Value
Unknown

CVE-2022-0745

Disclosure Date: June 13, 2022 (last updated February 23, 2025)
The Like Button Rating WordPress plugin before 2.6.45 allows any logged-in user, such as subscriber, to send arbitrary e-mails to any recipient, with any subject and body
Attacker Value
Unknown

CVE-2022-1294

Disclosure Date: May 30, 2022 (last updated February 23, 2025)
The IMDB info box WordPress plugin through 2.0 does not sanitize and escape some of its settings, which could allow high-privileged users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
Attacker Value
Unknown

CVE-2022-1393

Disclosure Date: May 16, 2022 (last updated February 23, 2025)
The WP Subtitle WordPress plugin before 3.4.1 adds a subtitle field and provides a shortcode to display it via [wp_subtitle]. The subtitle is stored as a custom post meta with the key: "wps_subtitle", which is sanitized upon post save/update, however is not sanitized when updating it directly from the post meta update button (via AJAX) - and this makes the XSS exploitable by authenticated users with a role as low as contributor.
Attacker Value
Unknown

CVE-2022-1622

Disclosure Date: May 11, 2022 (last updated February 23, 2025)
LibTIFF master branch has an out-of-bounds read in LZWDecode in libtiff/tif_lzw.c:619, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit b4e79bfa.
Attacker Value
Unknown

CVE-2022-1623

Disclosure Date: May 11, 2022 (last updated February 23, 2025)
LibTIFF master branch has an out-of-bounds read in LZWDecode in libtiff/tif_lzw.c:624, allowing attackers to cause a denial-of-service via a crafted tiff file. For users that compile libtiff from sources, the fix is available with commit b4e79bfa.