Show filters
818 Total Results
Displaying 241-250 of 818
Sort by:
Attacker Value
Unknown

CVE-2022-35906

Disclosure Date: July 15, 2022 (last updated February 24, 2025)
An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x. Using an affected version of MicroStation or MicroStation-based application to open a DGN file containing crafted data can force an out-of-bounds read. Exploitation of these vulnerabilities within the parsing of DGN files could enable an attacker to read information in the context of the current process.
Attacker Value
Unknown

CVE-2022-35905

Disclosure Date: July 15, 2022 (last updated February 24, 2025)
An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x. Using an affected version of MicroStation or MicroStation-based application to open an FBX file containing crafted data can force an out-of-bounds read. Exploitation of these vulnerabilities within the parsing of FBX files could enable an attacker to read information in the context of the current process.
Attacker Value
Unknown

CVE-2022-35904

Disclosure Date: July 15, 2022 (last updated February 24, 2025)
An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x. Using an affected version of MicroStation or MicroStation-based application to open an IFC file containing crafted data can force an out-of-bounds read. Exploitation of these vulnerabilities within the parsing of IFC files could enable an attacker to read information in the context of the current process.
Attacker Value
Unknown

CVE-2022-35903

Disclosure Date: July 15, 2022 (last updated February 24, 2025)
An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x. Using an affected version of MicroStation or MicroStation-based application to open a 3DS file containing crafted data can force an out-of-bounds read. Exploitation of these vulnerabilities within the parsing of 3DS files could enable an attacker to read information in the context of the current process.
Attacker Value
Unknown

CVE-2022-35902

Disclosure Date: July 15, 2022 (last updated February 24, 2025)
An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x. Using an affected version of MicroStation or MicroStation-based application to open an OBJ file containing crafted data can force an out-of-bounds read. Exploitation of these vulnerabilities within the parsing of OBJ files could enable an attacker to read information in the context of the current process.
Attacker Value
Unknown

CVE-2022-35901

Disclosure Date: July 15, 2022 (last updated February 24, 2025)
An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x. Using an affected version of MicroStation or MicroStation-based application to open a J2K file containing crafted data can force an out-of-bounds read. Exploitation of these vulnerabilities within the parsing of J2K files could enable an attacker to read information in the context of the current process.
Attacker Value
Unknown

CVE-2022-35900

Disclosure Date: July 15, 2022 (last updated February 24, 2025)
An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x. Using an affected version of MicroStation or MicroStation-based application to open a JP2 file containing crafted data can force an out-of-bounds read. Exploitation of these vulnerabilities within the parsing of JP2 files could enable an attacker to read information in the context of the current process.
Attacker Value
Unknown

CVE-2021-36461

Disclosure Date: July 15, 2022 (last updated February 24, 2025)
An Arbitrary File Upload vulnerability exists in Microweber 1.1.3 that allows attackers to getshell via the Settings Upload Picture section by uploading pictures with malicious code, user.ini.
Attacker Value
Unknown

CVE-2022-2368

Disclosure Date: July 11, 2022 (last updated February 24, 2025)
Authentication Bypass by Spoofing in GitHub repository microweber/microweber prior to 1.2.20.
Attacker Value
Unknown

CVE-2022-2353

Disclosure Date: July 09, 2022 (last updated February 24, 2025)
Prior to microweber/microweber v1.2.20, due to improper neutralization of input, an attacker can steal tokens to perform cross-site request forgery, fetch contents from same-site and redirect a user.