Show filters
85 Total Results
Displaying 31-40 of 85
Sort by:
Attacker Value
Unknown
CVE-2020-12135
Disclosure Date: April 24, 2020 (last updated February 21, 2025)
bson before 0.8 incorrectly uses int rather than size_t for many variables, parameters, and return values. In particular, the bson_ensure_space() parameter bytesNeeded could have an integer overflow via properly constructed bson input.
0
Attacker Value
Unknown
CVE-2020-8859
Disclosure Date: March 23, 2020 (last updated February 21, 2025)
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of ELOG Electronic Logbook 3.1.4-283534d. Authentication is not required to exploit this vulnerability. The specific flaw exists within the processing of HTTP parameters. A crafted request can trigger the dereference of a null pointer. An attacker can leverage this vulnerability to create a denial-of-service condition. Was ZDI-CAN-10115.
0
Attacker Value
Unknown
CVE-2015-5215
Disclosure Date: February 17, 2020 (last updated February 21, 2025)
The default configuration of the Jinja templating engine used in the Identity Provider (IdP) server in Ipsilon 0.1.0 before 1.0.1 does not enable auto-escaping, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via template variables. NOTE: This may be a duplicate of CVE-2015-5216. Moreover, the Jinja development team does not enable auto-escape by default for performance issues as explained in https://jinja.palletsprojects.com/en/master/faq/#why-is-autoescaping-not-the-default.
0
Attacker Value
Unknown
CVE-2015-5216
Disclosure Date: February 17, 2020 (last updated February 21, 2025)
The Identity Provider (IdP) server in Ipsilon 0.1.0 before 1.0.1 does not properly escape certain characters in a Python exception-message template, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via an HTTP response.
0
Attacker Value
Unknown
CVE-2012-0945
Disclosure Date: January 15, 2020 (last updated February 21, 2025)
whoopsie-daisy before 0.1.26: Root user can remove arbitrary files
0
Attacker Value
Unknown
CVE-2019-20376
Disclosure Date: January 10, 2020 (last updated February 21, 2025)
A cross-site scripting (XSS) vulnerability in Electronic Logbook (ELOG) 3.1.4 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG document to elogd.c.
0
Attacker Value
Unknown
CVE-2019-20375
Disclosure Date: January 10, 2020 (last updated February 21, 2025)
A cross-site scripting (XSS) vulnerability in Electronic Logbook (ELOG) 3.1.4 allows remote attackers to inject arbitrary web script or HTML via the value parameter in a localization (loc) command to elogd.c.
0
Attacker Value
Unknown
CVE-2019-11484
Disclosure Date: October 29, 2019 (last updated February 21, 2025)
Kevin Backhouse discovered an integer overflow in bson_ensure_space, as used in whoopsie.
0
Attacker Value
Unknown
CVE-2019-6528
Disclosure Date: March 05, 2019 (last updated November 27, 2024)
PSI GridConnect GmbH Telecontrol Gateway and Smart Telecontrol Unit family, IEC104 Security Proxy versions Telecontrol Gateway 3G Versions 4.2.21, 5.0.27, 5.1.19, 6.0.16 and prior, and Telecontrol Gateway XS-MU Versions 4.2.21, 5.0.27, 5.1.19, 6.0.16 and prior, and Telecontrol Gateway VM Versions 4.2.21, 5.0.27, 5.1.19, 6.0.16 and prior, and Smart Telecontrol Unit TCG Versions 5.0.27, 5.1.19, 6.0.16 and prior, and IEC104 Security Proxy Version 2.2.10 and prior The web application browser interprets input as active HTML, JavaScript, or VBScript, which could allow an attacker to execute arbitrary code.
0
Attacker Value
Unknown
CVE-2016-10711
Disclosure Date: January 29, 2018 (last updated November 26, 2024)
Apsis Pound before 2.8a allows request smuggling via crafted headers, a different vulnerability than CVE-2005-3751.
0