Show filters
85 Total Results
Displaying 31-40 of 85
Sort by:
Attacker Value
Unknown

CVE-2020-12135

Disclosure Date: April 24, 2020 (last updated February 21, 2025)
bson before 0.8 incorrectly uses int rather than size_t for many variables, parameters, and return values. In particular, the bson_ensure_space() parameter bytesNeeded could have an integer overflow via properly constructed bson input.
Attacker Value
Unknown

CVE-2020-8859

Disclosure Date: March 23, 2020 (last updated February 21, 2025)
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of ELOG Electronic Logbook 3.1.4-283534d. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of HTTP parameters. A crafted request can trigger the dereference of a null pointer. An attacker can leverage this vulnerability to create a denial-of-service condition. Was ZDI-CAN-10115.
Attacker Value
Unknown

CVE-2015-5215

Disclosure Date: February 17, 2020 (last updated February 21, 2025)
The default configuration of the Jinja templating engine used in the Identity Provider (IdP) server in Ipsilon 0.1.0 before 1.0.1 does not enable auto-escaping, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via template variables. NOTE: This may be a duplicate of CVE-2015-5216. Moreover, the Jinja development team does not enable auto-escape by default for performance issues as explained in https://jinja.palletsprojects.com/en/master/faq/#why-is-autoescaping-not-the-default.
Attacker Value
Unknown

CVE-2015-5216

Disclosure Date: February 17, 2020 (last updated February 21, 2025)
The Identity Provider (IdP) server in Ipsilon 0.1.0 before 1.0.1 does not properly escape certain characters in a Python exception-message template, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via an HTTP response.
Attacker Value
Unknown

CVE-2012-0945

Disclosure Date: January 15, 2020 (last updated February 21, 2025)
whoopsie-daisy before 0.1.26: Root user can remove arbitrary files
Attacker Value
Unknown

CVE-2019-20376

Disclosure Date: January 10, 2020 (last updated February 21, 2025)
A cross-site scripting (XSS) vulnerability in Electronic Logbook (ELOG) 3.1.4 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG document to elogd.c.
Attacker Value
Unknown

CVE-2019-20375

Disclosure Date: January 10, 2020 (last updated February 21, 2025)
A cross-site scripting (XSS) vulnerability in Electronic Logbook (ELOG) 3.1.4 allows remote attackers to inject arbitrary web script or HTML via the value parameter in a localization (loc) command to elogd.c.
Attacker Value
Unknown

CVE-2019-11484

Disclosure Date: October 29, 2019 (last updated February 21, 2025)
Kevin Backhouse discovered an integer overflow in bson_ensure_space, as used in whoopsie.
Attacker Value
Unknown

CVE-2019-6528

Disclosure Date: March 05, 2019 (last updated November 27, 2024)
PSI GridConnect GmbH Telecontrol Gateway and Smart Telecontrol Unit family, IEC104 Security Proxy versions Telecontrol Gateway 3G Versions 4.2.21, 5.0.27, 5.1.19, 6.0.16 and prior, and Telecontrol Gateway XS-MU Versions 4.2.21, 5.0.27, 5.1.19, 6.0.16 and prior, and Telecontrol Gateway VM Versions 4.2.21, 5.0.27, 5.1.19, 6.0.16 and prior, and Smart Telecontrol Unit TCG Versions 5.0.27, 5.1.19, 6.0.16 and prior, and IEC104 Security Proxy Version 2.2.10 and prior The web application browser interprets input as active HTML, JavaScript, or VBScript, which could allow an attacker to execute arbitrary code.
Attacker Value
Unknown

CVE-2016-10711

Disclosure Date: January 29, 2018 (last updated November 26, 2024)
Apsis Pound before 2.8a allows request smuggling via crafted headers, a different vulnerability than CVE-2005-3751.
0