Show filters
290 Total Results
Displaying 51-60 of 290
Sort by:
Attacker Value
Unknown
CVE-2021-45707
Disclosure Date: December 27, 2021 (last updated February 23, 2025)
An issue was discovered in the nix crate 0.16.0 and later before 0.20.2, 0.21.x before 0.21.2, and 0.22.x before 0.22.2 for Rust. unistd::getgrouplist has an out-of-bounds write if a user is in more than 16 /etc/groups groups.
0
Attacker Value
Unknown
CVE-2021-24816
Disclosure Date: November 08, 2021 (last updated February 23, 2025)
The Phoenix Media Rename WordPress plugin before 3.4.4 does not have capability checks in its phoenix_media_rename AJAX action, which could allow users with Author roles to rename any uploaded media files, including ones they do not own.
0
Attacker Value
Unknown
CVE-2020-12058
Disclosure Date: September 03, 2020 (last updated February 22, 2025)
Several XSS vulnerabilities in osCommerce CE Phoenix before 1.0.6.0 allow an attacker to inject and execute arbitrary JavaScript code. The malicious code can be injected as follows: the page parameter to catalog/admin/order_status.php, catalog/admin/tax_rates.php, catalog/admin/languages.php, catalog/admin/countries.php, catalog/admin/tax_classes.php, catalog/admin/reviews.php, or catalog/admin/zones.php; or the zpage or spage parameter to catalog/admin/geo_zones.php.
0
Attacker Value
Unknown
CVE-2020-12048
Disclosure Date: June 29, 2020 (last updated February 21, 2025)
Phoenix Hemodialysis Delivery System SW 3.36 and 3.40, The Phoenix Hemodialysis device does not support data-in-transit encryption (e.g., TLS/SSL) when transmitting treatment and prescription data on the network between the Phoenix system and the Exalis dialysis data management tool. An attacker with access to the network could observe sensitive treatment and prescription data sent between the Phoenix system and the Exalis tool.
0
Attacker Value
Unknown
CVE-2020-10057
Disclosure Date: March 04, 2020 (last updated February 21, 2025)
GeniXCMS 1.1.7 is vulnerable to user privilege escalation due to broken access control. This issue exists because of an incomplete fix for CVE-2015-2680, in which "token" is used as a CSRF protection mechanism, but without validation that "token" is associated with an administrative user.
0
Attacker Value
Unknown
CVE-2011-1145
Disclosure Date: November 14, 2019 (last updated November 27, 2024)
The SQLDriverConnect() function in unixODBC before 2.2.14p2 have a possible buffer overflow condition when specifying a large value for SAVEFILE parameter in the connection string.
0
Attacker Value
Unknown
CVE-2019-17365
Disclosure Date: October 09, 2019 (last updated January 16, 2025)
Nix through 2.3 allows local users to gain access to an arbitrary user's account because the parent directory of the user-profile directories is world writable.
0
Attacker Value
Unknown
CVE-2017-14740
Disclosure Date: April 26, 2018 (last updated November 26, 2024)
Cross-site scripting (XSS) vulnerability in GeniXCMS 1.1.0 allows remote authenticated users to inject arbitrary web script or HTML via the Menu ID when adding a menu.
0
Attacker Value
Unknown
CVE-2018-14476
Disclosure Date: April 04, 2018 (last updated November 27, 2024)
GeniXCMS 1.1.5 has XSS via the dbuser or dbhost parameter during step 1 of installation.
0
Attacker Value
Unknown
CVE-2018-7485
Disclosure Date: February 26, 2018 (last updated November 26, 2024)
The SQLWriteFileDSN function in odbcinst/SQLWriteFileDSN.c in unixODBC 2.3.5 has strncpy arguments in the wrong order, which allows attackers to cause a denial of service or possibly have unspecified other impact.
0