Show filters
87 Total Results
Displaying 51-60 of 87
Sort by:
Attacker Value
Unknown

CVE-2020-0560

Disclosure Date: February 13, 2020 (last updated February 21, 2025)
Improper permissions in the installer for the Intel(R) Renesas Electronics(R) USB 3.0 Driver, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.
Attacker Value
Unknown

CVE-2011-3582

Disclosure Date: January 22, 2020 (last updated February 21, 2025)
A Cross-site Request Forgery (CSRF) vulnerability exists in Advanced Electron Forums (AEF) through 1.0.9 due to inadequate confirmation for sensitive transactions in the administrator functions.
Attacker Value
Unknown

CVE-2019-20376

Disclosure Date: January 10, 2020 (last updated February 21, 2025)
A cross-site scripting (XSS) vulnerability in Electronic Logbook (ELOG) 3.1.4 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG document to elogd.c.
Attacker Value
Unknown

CVE-2019-20375

Disclosure Date: January 10, 2020 (last updated February 21, 2025)
A cross-site scripting (XSS) vulnerability in Electronic Logbook (ELOG) 3.1.4 allows remote attackers to inject arbitrary web script or HTML via the value parameter in a localization (loc) command to elogd.c.
Attacker Value
Unknown

CVE-2019-13028

Disclosure Date: June 28, 2019 (last updated November 27, 2024)
An incorrect implementation of a local web server in eID client (Windows version before 3.1.2, Linux version before 3.0.3) allows remote attackers to execute arbitrary code (.cgi, .pl, or .php) or delete arbitrary files via a crafted HTML page. This is a product from the Ministry of Interior of the Slovak Republic.
0
Attacker Value
Unknown

CVE-2019-5958

Disclosure Date: May 17, 2019 (last updated November 27, 2024)
Untrusted search path vulnerability in Electronic reception and examination of application for radio licenses Offline 1.0.9.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
0
Attacker Value
Unknown

CVE-2019-5957

Disclosure Date: May 17, 2019 (last updated November 27, 2024)
Untrusted search path vulnerability in Installer of Electronic reception and examination of application for radio licenses Online 1.0.9.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
0
Attacker Value
Unknown

CVE-2019-9632

Disclosure Date: March 08, 2019 (last updated November 27, 2024)
ESAFENET CDG V3 and V5 has an arbitrary file download vulnerability via the fileName parameter in download.jsp because the InstallationPack parameter is mishandled in a /CDGServer3/ClientAjax request.
0
Attacker Value
Unknown

CVE-2018-15685

Disclosure Date: August 23, 2018 (last updated November 27, 2024)
GitHub Electron 1.7.15, 1.8.7, 2.0.7, and 3.0.0-beta.6, in certain scenarios involving IFRAME elements and "nativeWindowOpen: true" or "sandbox: true" options, is affected by a WebPreferences vulnerability that can be leveraged to perform remote code execution.
0
Attacker Value
Unknown

CVE-2018-13000

Disclosure Date: June 29, 2018 (last updated November 26, 2024)
An XSS issue was discovered in Advanced Electron Forum (AEF) v1.0.9. A persistent XSS vulnerability is located in the `FTP Link` element of the `Private Message` module. The editor of the private message module allows inserting links without sanitizing the content. This allows remote attackers to inject malicious script code payloads as a private message (aka pmbody). The injection point is the editor ftp link element and the execution point occurs in the message body context on arrival. The request method to inject is POST with restricted user privileges.
0