Show filters
107 Total Results
Displaying 31-40 of 107
Sort by:
Attacker Value
Unknown
CVE-2024-2863
Disclosure Date: March 25, 2024 (last updated January 05, 2025)
This vulnerability allows remote attackers to traverse paths via file upload on the affected LG LED Assistant.
0
Attacker Value
Unknown
CVE-2024-2862
Disclosure Date: March 25, 2024 (last updated January 05, 2025)
This vulnerability allows remote attackers to reset the password of anonymous users without authorization on the affected LG LED Assistant.
0
Attacker Value
Unknown
CVE-2024-28171
Disclosure Date: March 21, 2024 (last updated January 05, 2025)
It is possible to perform a path traversal attack and write outside of the intended directory. If a file name is specified that already exists on the file system, then the original file will be overwritten.
0
Attacker Value
Unknown
CVE-2024-28045
Disclosure Date: March 21, 2024 (last updated January 05, 2025)
Improper neutralization of input within the affected product could lead to cross-site scripting.
0
Attacker Value
Unknown
CVE-2024-28040
Disclosure Date: March 21, 2024 (last updated January 05, 2025)
SQL injection vulnerability exists in GetDIAE_astListParameters.
0
Attacker Value
Unknown
CVE-2024-25567
Disclosure Date: March 21, 2024 (last updated January 05, 2025)
Path traversal attack is possible and write outside of the intended directory and may access sensitive information. If a file name is specified that already exists on the file system, then the original file will be overwritten.
0
Attacker Value
Unknown
CVE-2024-23975
Disclosure Date: March 21, 2024 (last updated January 05, 2025)
SQL injection vulnerability exists in GetDIAE_slogListParameters.
0
Attacker Value
Unknown
CVE-2024-23494
Disclosure Date: March 21, 2024 (last updated January 05, 2025)
SQL injection vulnerability exists in GetDIAE_unListParameters.
0
Attacker Value
Unknown
CVE-2024-28891
Disclosure Date: March 21, 2024 (last updated January 05, 2025)
SQL injection vulnerability exists in the script Handler_CFG.ashx.
0
Attacker Value
Unknown
CVE-2024-27303
Disclosure Date: March 06, 2024 (last updated March 07, 2024)
electron-builder is a solution to package and build a ready for distribution Electron, Proton Native app for macOS, Windows and Linux. A vulnerability that only affects eletron-builder prior to 24.13.2 in Windows, the NSIS installer makes a system call to open cmd.exe via NSExec in the `.nsh` installer script. NSExec by default searches the current directory of where the installer is located before searching `PATH`. This means that if an attacker can place a malicious executable file named cmd.exe in the same folder as the installer, the installer will run the malicious file. Version 24.13.2 fixes this issue. No known workaround exists. The code executes at the installer-level before the app is present on the system, so there's no way to check if it exists in a current installer.
0