Show filters
699 Total Results
Displaying 301-310 of 699
Sort by:
Attacker Value
Unknown
CVE-2019-15092
Disclosure Date: August 23, 2019 (last updated November 27, 2024)
The webtoffee "WordPress Users & WooCommerce Customers Import Export" plugin 1.3.0 for WordPress allows CSV injection in the user_url, display_name, first_name, and last_name columns in an exported CSV file created by the WF_CustomerImpExpCsv_Exporter class.
0
Attacker Value
Unknown
CVE-2019-15074
Disclosure Date: August 21, 2019 (last updated November 27, 2024)
The Timeline feature in my_view_page.php in MantisBT through 2.21.1 has a stored cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code (if CSP settings permit it) after uploading an attachment with a crafted filename. The code is executed for any user having visibility to the issue, whenever My View Page is displayed.
0
Attacker Value
Unknown
CVE-2019-14973
Disclosure Date: August 14, 2019 (last updated November 08, 2023)
_TIFFCheckMalloc and _TIFFCheckRealloc in tif_aux.c in LibTIFF through 4.0.10 mishandle Integer Overflow checks because they rely on compiler behavior that is undefined by the applicable C standards. This can, for example, lead to an application crash.
0
Attacker Value
Unknown
CVE-2018-16514
Disclosure Date: June 20, 2019 (last updated November 27, 2024)
A cross-site scripting (XSS) vulnerability in the View Filters page (view_filters_page.php) and Edit Filter page (manage_filter_edit_page.php) in MantisBT 2.1.0 through 2.17.0 allows remote attackers to inject arbitrary code (if CSP settings permit it) through a crafted PATH_INFO. NOTE: this vulnerability exists because of an incomplete fix for CVE-2018-13055.
0
Attacker Value
Unknown
CVE-2018-9839
Disclosure Date: June 06, 2019 (last updated November 27, 2024)
An issue was discovered in MantisBT through 1.3.14, and 2.0.0. Using a crafted request on bug_report_page.php (modifying the 'm_id' parameter), any user with REPORTER access or above is able to view any private issue's details (summary, description, steps to reproduce, additional information) when cloning it. By checking the 'Copy issue notes' and 'Copy attachments' checkboxes and completing the clone operation, this data also becomes public (except private notes).
0
Attacker Value
Unknown
CVE-2018-15208
Disclosure Date: April 30, 2019 (last updated November 27, 2024)
BPC SmartVista 2 has Session Fixation via the JSESSIONID parameter.
0
Attacker Value
Unknown
CVE-2018-15207
Disclosure Date: April 30, 2019 (last updated November 27, 2024)
BPC SmartVista 2 has Improper Access Control in the SVFE module, where it fails to appropriately restrict access: a normal user is able to access the SVFE2/pages/finadmin/currconvrate/currconvrate.jsf functionality that should be only accessible to an admin.
0
Attacker Value
Unknown
CVE-2018-15206
Disclosure Date: April 30, 2019 (last updated November 27, 2024)
BPC SmartVista 2 has CSRF via SVFE2/pages/admpages/roles/createrole.jsf.
0
Attacker Value
Unknown
CVE-2017-16232
Disclosure Date: March 21, 2019 (last updated November 08, 2023)
LibTIFF 4.0.8 has multiple memory leak vulnerabilities, which allow attackers to cause a denial of service (memory consumption), as demonstrated by tif_open.c, tif_lzw.c, and tif_aux.c. NOTE: Third parties were unable to reproduce the issue
0
Attacker Value
Unknown
CVE-2019-7663
Disclosure Date: February 09, 2019 (last updated November 27, 2024)
An Invalid Address dereference was discovered in TIFFWriteDirectoryTagTransferfunction in libtiff/tif_dirwrite.c in LibTIFF 4.0.10, affecting the cpSeparateBufToContigBuf function in tiffcp.c. Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted tiff file. This is different from CVE-2018-12900.
0