Show filters
563 Total Results
Displaying 231-240 of 563
Sort by:
Attacker Value
Unknown
CVE-2021-41033
Disclosure Date: September 13, 2021 (last updated February 23, 2025)
In all released versions of Eclipse Equinox, at least until version 4.21 (September 2021), installation can be vulnerable to man-in-the-middle attack if using p2 repos that are HTTP; that can then be exploited to serve incorrect p2 metadata and entirely alter the local installation, particularly by installing plug-ins that may then run malicious code.
0
Attacker Value
Unknown
CVE-2021-32834
Disclosure Date: September 09, 2021 (last updated February 23, 2025)
Eclipse Keti is a service that was designed to protect RESTfuls API using Attribute Based Access Control (ABAC). In Keti a user able to create Policy Sets can run arbitrary code by sending malicious Groovy scripts which will escape the configured Groovy sandbox. This vulnerability is known to exist in the latest commit at the time of writing this CVE (commit a1c8dbe). For more details see the referenced GHSL-2021-063.
0
Attacker Value
Unknown
CVE-2021-32835
Disclosure Date: September 09, 2021 (last updated February 23, 2025)
Eclipse Keti is a service that was designed to protect RESTfuls API using Attribute Based Access Control (ABAC). In Keti a sandbox escape vulnerability may lead to post-authentication Remote Code execution. This vulnerability is known to exist in the latest commit at the time of writing this CVE (commit a1c8dbe). For more details see the referenced GHSL-2021-063.
0
Attacker Value
Unknown
CVE-2021-38707
Disclosure Date: September 07, 2021 (last updated February 23, 2025)
Persistent cross-site scripting (XSS) vulnerabilities in ClinicCases 7.3.3 allow low-privileged attackers to introduce arbitrary JavaScript to account parameters. The XSS payloads will execute in the browser of any user who views the relevant content. This can result in account takeover via session token theft.
0
Attacker Value
Unknown
CVE-2021-38704
Disclosure Date: September 07, 2021 (last updated February 23, 2025)
Multiple reflected cross-site scripting (XSS) vulnerabilities in ClinicCases 7.3.3 allow unauthenticated attackers to introduce arbitrary JavaScript by crafting a malicious URL. This can result in account takeover via session token theft.
0
Attacker Value
Unknown
CVE-2021-38705
Disclosure Date: September 07, 2021 (last updated February 23, 2025)
ClinicCases 7.3.3 is affected by Cross-Site Request Forgery (CSRF). A successful attack would consist of an authenticated user following a malicious link, resulting in arbitrary actions being carried out with the privilege level of the targeted user. This can be exploited to create a secondary administrator account for the attacker.
0
Attacker Value
Unknown
CVE-2021-38706
Disclosure Date: September 07, 2021 (last updated February 23, 2025)
messages_load.php in ClinicCases 7.3.3 suffers from a blind SQL injection vulnerability, which allows low-privileged attackers to execute arbitrary SQL commands through a vulnerable parameter.
0
Attacker Value
Unknown
CVE-2021-34436
Disclosure Date: September 02, 2021 (last updated February 23, 2025)
In Eclipse Theia 0.1.1 to 0.2.0, it is possible to exploit the default build to obtain remote code execution (and XXE) via the theia-xml-extension. This extension uses lsp4xml (recently renamed to LemMinX) in order to provide language support for XML. This is installed by default.
0
Attacker Value
Unknown
CVE-2021-34435
Disclosure Date: September 01, 2021 (last updated February 23, 2025)
In Eclipse Theia 0.3.9 to 1.8.1, the "mini-browser" extension allows a user to preview HTML files in an iframe inside the IDE. But with the way it is made it is possible for a previewed HTML file to trigger an RCE. This exploit only happens if a user previews a malicious file..
0
Attacker Value
Unknown
CVE-2021-34434
Disclosure Date: August 30, 2021 (last updated February 23, 2025)
In Eclipse Mosquitto versions 2.0 to 2.0.11, when using the dynamic security plugin, if the ability for a client to make subscriptions on a topic is revoked when a durable client is offline, then existing subscriptions for that client are not revoked.
0