Show filters
59 Total Results
Displaying 31-40 of 59
Sort by:
Attacker Value
Unknown

CVE-2019-9650

Disclosure Date: March 11, 2019 (last updated November 27, 2024)
An XSS issue was discovered in upcoming_events.php in the Upcoming Events plugin before 1.33 for MyBB via a crafted name for an event.
0
Attacker Value
Unknown

CVE-2018-1000827

Disclosure Date: December 20, 2018 (last updated November 27, 2024)
Ubilling version <= 0.9.2 contains a Other/Unknown vulnerability in user-controlled parameter that can result in Disclosure of confidential data, denial of service, SSRF, remote code execution.
0
Attacker Value
Unknown

CVE-2018-16460

Disclosure Date: September 07, 2018 (last updated November 27, 2024)
A command Injection in ps package versions <1.0.0 for Node.js allowed arbitrary commands to be executed when attacker controls the PID.
0
Attacker Value
Unknown

CVE-2018-10769

Disclosure Date: August 10, 2018 (last updated November 08, 2023)
The transferProxy and approveProxy functions of a smart contract implementation for SmartMesh (SMT), an Ethereum ERC20 token, allow attackers to accomplish an unauthorized transfer of digital assets because replay attacks can occur with the same-named functions (with the same signatures) in other tokens: First (FST), GG Token (GG), M2C Mesh Network (MTC), M2C Mesh Network (mesh), and UG Token (UGT).
0
Attacker Value
Unknown

CVE-2018-3751

Disclosure Date: July 03, 2018 (last updated November 27, 2024)
The utilities function in all versions <= 0.3.0 of the merge-recursive node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects.
0
Attacker Value
Unknown

CVE-2018-6651

Disclosure Date: February 05, 2018 (last updated November 26, 2024)
In the uncurl_ws_accept function in uncurl.c in uncurl before 0.07, as used in Parsec before 140-3, insufficient Origin header validation (accepting an arbitrary substring match) for WebSocket API requests allows remote attackers to bypass intended access restrictions. In Parsec, this means full control over the victim's computer.
0
Attacker Value
Unknown

CVE-2016-2224

Disclosure Date: March 24, 2017 (last updated November 26, 2024)
The __decode_dotted function in libc/inet/resolv.c in uClibc-ng before 1.0.12 allows remote DNS servers to cause a denial of service (infinite loop) via vectors involving compressed items in a reply.
0
Attacker Value
Unknown

CVE-2016-2225

Disclosure Date: March 24, 2017 (last updated November 26, 2024)
The __read_etc_hosts_r function in libc/inet/resolv.c in uClibc-ng before 1.0.12 allows remote DNS servers to cause a denial of service (infinite loop) via a crafted packet.
0
Attacker Value
Unknown

CVE-2016-6264

Disclosure Date: January 27, 2017 (last updated November 25, 2024)
Integer signedness error in libc/string/arm/memset.S in uClibc and uClibc-ng before 1.0.16 allows context-dependent attackers to cause a denial of service (crash) via a negative length value to the memset function.
Attacker Value
Unknown

CVE-2015-4608

Disclosure Date: June 16, 2015 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the BE User Log (beko_beuserlog) extension 1.1.1 and earlier for TYPO3 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
0