Show filters
1,868 Total Results
Displaying 21-30 of 1,868
Sort by:
Attacker Value
Unknown
CVE-2014-2817
Disclosure Date: August 12, 2014 (last updated June 29, 2024)
Microsoft Internet Explorer 6 through 11 allows remote attackers to gain privileges via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."
1
Attacker Value
Unknown
CVE-2019-6447
Disclosure Date: January 16, 2019 (last updated November 27, 2024)
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary files or execute applications via TCP port 59777 requests on the local Wi-Fi network. This TCP port remains open after the ES application has been launched once, and responds to unauthenticated application/json data over HTTP.
0
Attacker Value
Unknown
Microsoft Internet Explorer CCaret Use-After-Free
Disclosure Date: September 11, 2013 (last updated October 05, 2023)
Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
0
Attacker Value
Unknown
Microsoft Internet Explorer EnsureRecalcNotify Use-After-Free
Disclosure Date: August 14, 2013 (last updated October 05, 2023)
Microsoft Internet Explorer 7 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."
0
Attacker Value
Unknown
Microsoft Internet Explorer CGenericElement Use-After-Free
Disclosure Date: May 05, 2013 (last updated July 17, 2024)
Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly allocated or (2) is deleted, as exploited in the wild in May 2013.
0
Attacker Value
Unknown
MS12-037 Microsoft Internet Explorer Same ID Property Deleted Object Handling M…
Disclosure Date: June 12, 2012 (last updated October 04, 2023)
Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "Same ID Property Remote Code Execution Vulnerability."
0
Attacker Value
Unknown
CVE-2011-1252
Disclosure Date: June 16, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the SafeHTML function in the toStaticHTML API in Microsoft Internet Explorer 7 and 8, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP1, Groove Server 2010 Gold and SP1, Windows SharePoint Services 3.0 SP2, and SharePoint Foundation 2010 Gold and SP1 allows remote attackers to inject arbitrary web script or HTML via unspecified strings, aka "toStaticHTML Information Disclosure Vulnerability" or "HTML Sanitization Vulnerability."
1
Attacker Value
Unknown
CVE-2024-52503
Disclosure Date: December 02, 2024 (last updated December 21, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tailored Web Services Tailored Tools allows Stored XSS.This issue affects Tailored Tools: from n/a through 1.8.4.
0
Attacker Value
Unknown
CVE-2023-5816
Disclosure Date: October 30, 2024 (last updated November 07, 2024)
The Code Explorer plugin for WordPress is vulnerable to arbitrary external file reading in all versions up to, and including, 1.4.5. This is due to the fact that the plugin does not restrict accessing files to those outside of the WordPress instance, though the intention of the plugin is to only access WordPress related files. This makes it possible for authenticated attackers, with administrator-level access, to read files outside of the WordPress instance.
0
Attacker Value
Unknown
CVE-2024-35291
Disclosure Date: May 27, 2024 (last updated May 27, 2024)
Cross-site scripting vulnerability exists in Splunk Config Explorer versions prior to 1.7.16. If this vulnerability is exploited, an arbitrary script may be executed on the web browser of the user who is using the product.
0