Show filters
318 Total Results
Displaying 51-60 of 318
Sort by:
Attacker Value
Unknown

CVE-2023-37530

Disclosure Date: February 29, 2024 (last updated February 26, 2025)
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a webpage trying to retrieve cookie stored information.
Attacker Value
Unknown

CVE-2023-37529

Disclosure Date: February 29, 2024 (last updated February 26, 2025)
A cross-site scripting (XSS) vulnerability in the Web Reports component of HCL BigFix Platform can possibly allow an attacker to execute malicious javascript code into a webpage trying to retrieve cookie stored information. This is not the same vulnerability as identified in CVE-2023-37530.
Attacker Value
Unknown

CVE-2023-28018

Disclosure Date: February 12, 2024 (last updated October 17, 2024)
HCL Connections is vulnerable to a denial of service, caused by improper validation on certain requests. Using a specially-crafted request an attacker could exploit this vulnerability to cause denial of service for affected users.
Attacker Value
Unknown

CVE-2023-45698

Disclosure Date: February 10, 2024 (last updated February 26, 2025)
Sametime is impacted by lack of clickjacking protection in Outlook add-in. The application is not implementing appropriate protections in order to protect users from clickjacking attacks.
Attacker Value
Unknown

CVE-2023-45696

Disclosure Date: February 10, 2024 (last updated September 06, 2024)
Sametime is impacted by sensitive fields with autocomplete enabled in the Legacy web chat client. By default, this allows user entered data to be stored by the browser.
Attacker Value
Unknown

CVE-2023-45718

Disclosure Date: February 09, 2024 (last updated February 26, 2025)
Sametime is impacted by a failure to invalidate sessions. The application is setting sensitive cookie values in a persistent manner in Sametime Web clients. When this happens, cookie values can remain valid even after a user has closed out their session.  
Attacker Value
Unknown

CVE-2023-45716

Disclosure Date: February 09, 2024 (last updated February 26, 2025)
Sametime is impacted by sensitive information passed in URL.
Attacker Value
Unknown

CVE-2023-50349

Disclosure Date: February 09, 2024 (last updated February 26, 2025)
Sametime is impacted by a Cross Site Request Forgery (CSRF) vulnerability. Some REST APIs in the Sametime Proxy application can allow an attacker to perform malicious actions on the application.
Attacker Value
Unknown

CVE-2023-46360

Disclosure Date: February 06, 2024 (last updated February 26, 2025)
Hardy Barth cPH2 eCharge Ladestation v1.87.0 and earlier is vulnerable to Execution with Unnecessary Privileges.
Attacker Value
Unknown

CVE-2023-46359

Disclosure Date: February 06, 2024 (last updated February 26, 2025)
An OS command injection vulnerability in Hardy Barth cPH2 eCharge Ladestation v1.87.0 and earlier, may allow an unauthenticated remote attacker to execute arbitrary commands on the system via a specifically crafted arguments passed to the connectivity check feature.