Show filters
123 Total Results
Displaying 21-30 of 123
Sort by:
Attacker Value
Unknown
CVE-2021-45465
Disclosure Date: January 04, 2024 (last updated January 11, 2024)
A vulnerability has been identified in syngo fastView (All versions). The affected application lacks proper validation of user-supplied data when parsing BMP files. This could result in a write-what-where condition and an attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-15696)
0
Attacker Value
Unknown
CVE-2021-42028
Disclosure Date: January 04, 2024 (last updated January 11, 2024)
A vulnerability has been identified in syngo fastView (All versions). The affected application lacks proper validation of user-supplied data when parsing BMP files. This could result in an out-of-bounds write past the end of an allocated structure. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-14860)
0
Attacker Value
Unknown
CVE-2021-40367
Disclosure Date: January 04, 2024 (last updated January 11, 2024)
A vulnerability has been identified in syngo fastView (All versions). The affected application lacks proper validation of user-supplied data when parsing DICOM files. This could result in an out-of-bounds write past the end of an allocated structure. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-15097)
0
Attacker Value
Unknown
CVE-2023-0967
Disclosure Date: April 05, 2023 (last updated October 08, 2023)
Bhima version 1.27.0 allows an attacker authenticated with normal user permissions to view sensitive data of other application users and data that should only be viewed by the administrator. This is possible because the application is vulnerable to IDOR, it does not properly validate user permissions with respect to certain actions the user can perform.
0
Attacker Value
Unknown
CVE-2023-0959
Disclosure Date: April 05, 2023 (last updated October 08, 2023)
Bhima version 1.27.0 allows a remote attacker to update the privileges of any account registered in the application via a malicious link sent to an administrator. This is possible because the application is vulnerable to CSRF.
0
Attacker Value
Unknown
CVE-2023-0944
Disclosure Date: April 05, 2023 (last updated October 08, 2023)
Bhima version 1.27.0 allows an authenticated attacker with regular user permissions to update arbitrary user session data such as username, email and password. This is possible because the application is vulnerable to IDOR, it does not correctly validate user permissions with respect to certain actions that can be performed by the user.
0
Attacker Value
Unknown
CVE-2023-1254
Disclosure Date: March 07, 2023 (last updated October 08, 2023)
A vulnerability has been found in SourceCodester Health Center Patient Record Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file birthing_print.php. The manipulation of the argument birth_id leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-222484.
0
Attacker Value
Unknown
CVE-2023-1253
Disclosure Date: March 07, 2023 (last updated October 08, 2023)
A vulnerability, which was classified as critical, was found in SourceCodester Health Center Patient Record Management System 1.0. This affects an unknown part of the file login.php. The manipulation of the argument username leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-222483.
0
Attacker Value
Unknown
CVE-2023-1180
Disclosure Date: March 05, 2023 (last updated October 08, 2023)
A vulnerability has been found in SourceCodester Health Center Patient Record Management System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file hematology_print.php. The manipulation of the argument hem_id leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-222331.
0
Attacker Value
Unknown
CVE-2023-1156
Disclosure Date: March 02, 2023 (last updated October 08, 2023)
A vulnerability classified as problematic was found in SourceCodester Health Center Patient Record Management System 1.0. This vulnerability affects unknown code of the file admin/fecalysis_form.php. The manipulation of the argument itr_no leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-222220.
0