Show filters
1,840 Total Results
Displaying 301-310 of 1,840
Sort by:
Attacker Value
Unknown
CVE-2023-35372
Disclosure Date: August 08, 2023 (last updated February 25, 2025)
Microsoft Office Visio Remote Code Execution Vulnerability
0
Attacker Value
Unknown
CVE-2023-35371
Disclosure Date: August 08, 2023 (last updated February 25, 2025)
Microsoft Office Remote Code Execution Vulnerability
0
Attacker Value
Unknown
CVE-2023-4166
Disclosure Date: August 05, 2023 (last updated February 25, 2025)
A vulnerability has been found in Tongda OA and classified as critical. This vulnerability affects unknown code of the file general/system/seal_manage/dianju/delete_log.php. The manipulation of the argument DELETE_STR leads to sql injection. The exploit has been disclosed to the public and may be used. Upgrading to version 11.10 is able to address this issue. It is recommended to upgrade the affected component. VDB-236182 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2023-4165
Disclosure Date: August 05, 2023 (last updated February 25, 2025)
A vulnerability, which was classified as critical, was found in Tongda OA. This affects an unknown part of the file general/system/seal_manage/iweboffice/delete_seal.php. The manipulation of the argument DELETE_STR leads to sql injection. The exploit has been disclosed to the public and may be used. Upgrading to version 11.10 is able to address this issue. It is recommended to upgrade the affected component. The identifier VDB-236181 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2023-26442
Disclosure Date: August 02, 2023 (last updated February 25, 2025)
In case Cacheservice was configured to use a sproxyd object-storage backend, it would follow HTTP redirects issued by that backend. An attacker with access to a local or restricted network with the capability to intercept and replay HTTP requests to sproxyd (or who is in control of the sproxyd service) could perform a server-side request-forgery attack and make Cacheservice connect to unexpected resources. We have disabled the ability to follow HTTP redirects when connecting to sproxyd resources. No publicly available exploits are known.
0
Attacker Value
Unknown
CVE-2023-26441
Disclosure Date: August 02, 2023 (last updated February 25, 2025)
Cacheservice did not correctly check if relative cache object were pointing to the defined absolute location when accessing resources. An attacker with access to the database and a local or restricted network would be able to read arbitrary local file system resources that are accessible by the services system user account. We have improved path validation and make sure that any access is contained to the defined root directory. No publicly available exploits are known.
0
Attacker Value
Unknown
CVE-2023-26440
Disclosure Date: August 02, 2023 (last updated February 25, 2025)
The cacheservice API could be abused to indirectly inject parameters with SQL syntax which was insufficiently sanitized and would later be executed when creating new cache groups. Attackers with access to a local or restricted network could perform arbitrary SQL queries. We have improved the input check for API calls and filter for potentially malicious content. No publicly available exploits are known.
0
Attacker Value
Unknown
CVE-2023-26439
Disclosure Date: August 02, 2023 (last updated February 25, 2025)
The cacheservice API could be abused to inject parameters with SQL syntax which was insufficiently sanitized before getting executed as SQL statement. Attackers with access to a local or restricted network were able to perform arbitrary SQL queries, discovering other users cached data. We have improved the input check for API calls and filter for potentially malicious content. No publicly available exploits are known.
0
Attacker Value
Unknown
CVE-2023-34798
Disclosure Date: July 25, 2023 (last updated February 25, 2025)
An arbitrary file upload vulnerability in eoffice before v9.5 allows attackers to execute arbitrary code via uploading a crafted file.
0
Attacker Value
Unknown
CVE-2023-38617
Disclosure Date: July 20, 2023 (last updated February 25, 2025)
Office Suite Premium Version v10.9.1.42602 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the filter parameter at /api?path=files.
0