Show filters
557 Total Results
Displaying 41-50 of 557
Sort by:
Attacker Value
Unknown

CVE-2023-31290

Disclosure Date: April 27, 2023 (last updated October 08, 2023)
Trust Wallet Core before 3.1.1, as used in the Trust Wallet browser extension before 0.0.183, allows theft of funds because the entropy is 32 bits, as exploited in the wild in December 2022 and March 2023. This occurs because the mt19937 Mersenne Twister takes a single 32-bit value as an input seed, resulting in only four billion possible mnemonics. The affected versions of the browser extension are 0.0.172 through 0.0.182. To steal funds efficiently, an attacker can identify all Ethereum addresses created since the 0.0.172 release, and check whether they are Ethereum addresses that could have been created by this extension. To respond to the risk, affected users need to upgrade the product version and also move funds to a new wallet address.
Attacker Value
Unknown

CVE-2021-33975

Disclosure Date: April 19, 2023 (last updated October 08, 2023)
Buffer Overflow vulnerability in Qihoo 360 Total Security v10.8.0.1060 and v10.8.0.1213 allows attacker to escalate privileges.
Attacker Value
Unknown

CVE-2021-33972

Disclosure Date: April 19, 2023 (last updated October 08, 2023)
Buffer Overflow vulnerability in Qihoo 360 Safe Browser v13.0.2170.0 allows attacker to escalate priveleges.
Attacker Value
Unknown

CVE-2016-15021

Disclosure Date: January 17, 2023 (last updated October 20, 2023)
A vulnerability was found in nickzren alsdb. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to sql injection. Upgrading to version v2 is able to address this issue. The identifier of the patch is cbc79a68145e845f951113d184b4de207c341599. It is recommended to upgrade the affected component. The identifier VDB-218429 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2015-10058

Disclosure Date: January 17, 2023 (last updated October 20, 2023)
A vulnerability, which was classified as problematic, was found in Wikisource Category Browser. This affects an unknown part of the file index.php. The manipulation of the argument lang leads to cross site scripting. It is possible to initiate the attack remotely. The patch is named 764f4e8ce3f9242637df77530c70ae8a2ec4b6a1. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-218415.
Attacker Value
Unknown

CVE-2022-45299

Disclosure Date: January 13, 2023 (last updated October 08, 2023)
An issue in the IpFile argument of rust-lang webbrowser-rs v0.8.2 allows attackers to access arbitrary files via supplying a crafted URL.
Attacker Value
Unknown

CVE-2022-41706

Disclosure Date: November 25, 2022 (last updated October 08, 2023)
Browsershot version 3.57.2 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate the URL protocol passed to the Browsershot::url method.
Attacker Value
Unknown

CVE-2022-43984

Disclosure Date: November 25, 2022 (last updated October 08, 2023)
Browsershot version 3.57.3 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate that the JS content imported from an external source passed to the Browsershot::html method does not contain URLs that use the file:// protocol.
Attacker Value
Unknown

CVE-2022-43983

Disclosure Date: November 25, 2022 (last updated October 08, 2023)
Browsershot version 3.57.2 allows an external attacker to remotely obtain arbitrary local files. This is possible because the application does not validate that the HTML content passed to the Browsershot::html method does not contain URL's that use the file:// protocol.
Attacker Value
Unknown

CVE-2022-37623

Disclosure Date: October 31, 2022 (last updated December 22, 2024)
Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the shimPath variable in resolve-shims.js.