Show filters
290 Total Results
Displaying 51-60 of 290
Sort by:
Attacker Value
Unknown

CVE-2021-45707

Disclosure Date: December 27, 2021 (last updated February 23, 2025)
An issue was discovered in the nix crate 0.16.0 and later before 0.20.2, 0.21.x before 0.21.2, and 0.22.x before 0.22.2 for Rust. unistd::getgrouplist has an out-of-bounds write if a user is in more than 16 /etc/groups groups.
Attacker Value
Unknown

CVE-2021-24816

Disclosure Date: November 08, 2021 (last updated February 23, 2025)
The Phoenix Media Rename WordPress plugin before 3.4.4 does not have capability checks in its phoenix_media_rename AJAX action, which could allow users with Author roles to rename any uploaded media files, including ones they do not own.
Attacker Value
Unknown

CVE-2020-12058

Disclosure Date: September 03, 2020 (last updated February 22, 2025)
Several XSS vulnerabilities in osCommerce CE Phoenix before 1.0.6.0 allow an attacker to inject and execute arbitrary JavaScript code. The malicious code can be injected as follows: the page parameter to catalog/admin/order_status.php, catalog/admin/tax_rates.php, catalog/admin/languages.php, catalog/admin/countries.php, catalog/admin/tax_classes.php, catalog/admin/reviews.php, or catalog/admin/zones.php; or the zpage or spage parameter to catalog/admin/geo_zones.php.
Attacker Value
Unknown

CVE-2020-12048

Disclosure Date: June 29, 2020 (last updated February 21, 2025)
Phoenix Hemodialysis Delivery System SW 3.36 and 3.40, The Phoenix Hemodialysis device does not support data-in-transit encryption (e.g., TLS/SSL) when transmitting treatment and prescription data on the network between the Phoenix system and the Exalis dialysis data management tool. An attacker with access to the network could observe sensitive treatment and prescription data sent between the Phoenix system and the Exalis tool.
Attacker Value
Unknown

CVE-2020-10057

Disclosure Date: March 04, 2020 (last updated February 21, 2025)
GeniXCMS 1.1.7 is vulnerable to user privilege escalation due to broken access control. This issue exists because of an incomplete fix for CVE-2015-2680, in which "token" is used as a CSRF protection mechanism, but without validation that "token" is associated with an administrative user.
Attacker Value
Unknown

CVE-2011-1145

Disclosure Date: November 14, 2019 (last updated November 27, 2024)
The SQLDriverConnect() function in unixODBC before 2.2.14p2 have a possible buffer overflow condition when specifying a large value for SAVEFILE parameter in the connection string.
Attacker Value
Unknown

CVE-2019-17365

Disclosure Date: October 09, 2019 (last updated January 16, 2025)
Nix through 2.3 allows local users to gain access to an arbitrary user's account because the parent directory of the user-profile directories is world writable.
Attacker Value
Unknown

CVE-2017-14740

Disclosure Date: April 26, 2018 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in GeniXCMS 1.1.0 allows remote authenticated users to inject arbitrary web script or HTML via the Menu ID when adding a menu.
0
Attacker Value
Unknown

CVE-2018-14476

Disclosure Date: April 04, 2018 (last updated November 27, 2024)
GeniXCMS 1.1.5 has XSS via the dbuser or dbhost parameter during step 1 of installation.
Attacker Value
Unknown

CVE-2018-7485

Disclosure Date: February 26, 2018 (last updated November 26, 2024)
The SQLWriteFileDSN function in odbcinst/SQLWriteFileDSN.c in unixODBC 2.3.5 has strncpy arguments in the wrong order, which allows attackers to cause a denial of service or possibly have unspecified other impact.
0