Show filters
334,846 Total Results
Displaying 41-50 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown

CVE-2018-9472

Disclosure Date: November 20, 2024 (last updated November 21, 2024)
In xmlMemStrdupLoc of xmlmemory.c, there is a possible out-of-bounds write due to an integer overflow. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is needed for exploitation.
0
Attacker Value
Unknown

CVE-2018-9471

Disclosure Date: November 20, 2024 (last updated November 21, 2024)
In the deserialization constructor of NanoAppFilter.java, there is a possible loss of data due to type confusion. This could lead to local escalation of privilege in the system server with no additional execution privileges needed. User interaction is not needed for exploitation.
0
Attacker Value
Unknown

CVE-2018-9470

Disclosure Date: November 20, 2024 (last updated November 21, 2024)
In bff_Scanner_addOutPos of Scanner.c, there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to remote escalation of privilege in an unprivileged app with no additional execution privileges needed. User interaction is needed for exploitation.
0
Attacker Value
Unknown

CVE-2024-52796

Disclosure Date: November 20, 2024 (last updated November 21, 2024)
Password Pusher, an open source application to communicate sensitive information over the web, comes with a configurable rate limiter. In versions prior to v1.49.0, the rate limiter could be bypassed by forging proxy headers allowing bad actors to send unlimited traffic to the site potentially causing a denial of service. In v1.49.0, a fix was implemented to only authorize proxies on local IPs which resolves this issue. As a workaround, one may add rules to one's proxy and/or firewall to not accept external proxy headers such as `X-Forwarded-*` from clients.
0
Attacker Value
Unknown

CVE-2024-52771

Disclosure Date: November 20, 2024 (last updated November 21, 2024)
DedeBIZ v6.3.0 was discovered to contain an arbitrary file deletion vulnerability via the component /admin/file_manage_view.
0
Attacker Value
Unknown

CVE-2024-52770

Disclosure Date: November 20, 2024 (last updated November 21, 2024)
An arbitrary file upload vulnerability in the component /admin/file_manage_control of DedeBIZ v6.3.0 allows attackers to execute arbitrary code via uploading a crafted file.
0
Attacker Value
Unknown

CVE-2024-52769

Disclosure Date: November 20, 2024 (last updated November 21, 2024)
An arbitrary file upload vulnerability in the component /admin/friendlink_edit of DedeBIZ v6.3.0 allows attackers to execute arbitrary code via uploading a crafted file.
0
Attacker Value
Unknown

CVE-2024-52725

Disclosure Date: November 20, 2024 (last updated November 21, 2024)
SemCms v4.8 was discovered to contain a SQL injection vulnerability. This allows an attacker to execute arbitrary code via the ldgid parameter in the SEMCMS_SeoAndTag.php component.
0
Attacker Value
Unknown

CVE-2024-51163

Disclosure Date: November 20, 2024 (last updated November 22, 2024)
A Local File Inclusion vulnerability in Vegam Solutions Vegam 4i versions 6.3.47.0 and earlier allows a remote attacker to obtain sensitive information through the print label function. Specifically, the filePathList parameter is susceptible to LFI, enabling a malicious user to include files from the web server, such as web.config or /etc/host, leading to the disclosure of sensitive information.
0
Attacker Value
Unknown

CVE-2024-51162

Disclosure Date: November 20, 2024 (last updated November 22, 2024)
An issue in Audimex EE versions 15.1.20 and earlier allowing a remote attacker to escalate privileges. Analyzing the offline client code, it was identified that it is possible for any user (with any privilege) of Audimex to dump the whole Audimex database. This gives visibility upon password hashes of any user, ongoing audit data and more.
0