Show filters
557 Total Results
Displaying 51-60 of 557
Sort by:
Attacker Value
Unknown

CVE-2022-37621

Disclosure Date: October 28, 2022 (last updated December 22, 2024)
Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the fullPath variable in resolve-shims.js.
Attacker Value
Unknown

CVE-2022-37617

Disclosure Date: October 11, 2022 (last updated October 08, 2023)
Prototype pollution vulnerability in function resolveShims in resolve-shims.js in thlorenz browserify-shim 3.8.15 via the k variable in resolve-shims.js.
Attacker Value
Unknown

CVE-2022-36220

Disclosure Date: August 19, 2022 (last updated October 08, 2023)
Kiosk breakout (without quit password) in Safe Exam Browser (Windows) <3.4.0, which allows an attacker to achieve code execution via the browsers' print dialog.
Attacker Value
Unknown

CVE-2022-36835

Disclosure Date: August 05, 2022 (last updated November 29, 2024)
Implicit Intent hijacking vulnerability in Samsung Internet Browser prior to version 17.0.7.34 allows attackers to access arbitrary files.
Attacker Value
Unknown

CVE-2022-2443

Disclosure Date: July 18, 2022 (last updated October 07, 2023)
The FreeMind WP Browser plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including 1.2. This is due to missing nonce protection on the FreemindOptions() function found in the ~/freemind-wp-browser.php file. This makes it possible for unauthenticated attackers to inject malicious web scripts into the page, granted they can trick a site's administrator into performing an action such as clicking on a link.
Attacker Value
Unknown

CVE-2022-28226

Disclosure Date: June 15, 2022 (last updated October 07, 2023)
Local privilege vulnerability in Yandex Browser for Windows prior to 22.3.3.801 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating temporary files in directory with insecure permissions during Yandex Browser update process.
Attacker Value
Unknown

CVE-2022-28225

Disclosure Date: June 15, 2022 (last updated October 07, 2023)
Local privilege vulnerability in Yandex Browser for Windows prior to 22.3.3.684 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating symlinks to installation file during Yandex Browser update process.
Attacker Value
Unknown

CVE-2021-25261

Disclosure Date: June 15, 2022 (last updated October 07, 2023)
Local privilege vulnerability in Yandex Browser for Windows prior to 22.5.0.862 allows a local, low privileged, attacker to execute arbitary code with the SYSTEM privileges through manipulating symlinks to installation file during Yandex Browser update process.
Attacker Value
Unknown

CVE-2022-32550

Disclosure Date: June 15, 2022 (last updated March 26, 2024)
An issue was discovered in AgileBits 1Password, involving the method various 1Password apps and integrations used to create connections to the 1Password service. In specific circumstances, this issue allowed a malicious server to convince a 1Password app or integration it is communicating with the 1Password service.
Attacker Value
Unknown

CVE-2022-27176

Disclosure Date: June 14, 2022 (last updated October 07, 2023)
Incomplete filtering of special elements vulnerability exists in RevoWorks SCVX using 'File Sanitization Library' 1.043 and prior versions, RevoWorks Browser 2.2.67 and prior versions (when using 'File Sanitization Option'), and RevoWorks Desktop 2.1.84 and prior versions (when using 'File Sanitization Option'), which may allow an attacker to execute a malicious macro by having a user to download, import, and open a specially crafted file in the local environment.