Show filters
266 Total Results
Displaying 61-70 of 266
Sort by:
Attacker Value
Unknown
CVE-2023-39955
Disclosure Date: August 10, 2023 (last updated October 08, 2023)
Notes is a note-taking app for Nextcloud, an open-source cloud platform. Starting in version 4.4.0 and prior to version 4.8.0, when creating a note file with HTML, the content is rendered in the preview instead of the file being offered to download. Nextcloud Notes app version 4.8.0 contains a patch for the issue. No known workarounds are available.
0
Attacker Value
Unknown
CVE-2023-28423
Disclosure Date: June 22, 2023 (last updated October 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Prism Tech Studios Modern Footnotes plugin <= 1.4.15 versions.
0
Attacker Value
Unknown
CVE-2023-33188
Disclosure Date: May 27, 2023 (last updated October 08, 2023)
Omni-notes is an open source note-taking application for Android. The Omni-notes Android app had an insufficient path validation vulnerability when displaying the details of a note received through an externally-provided intent. The paths of the note's attachments were not properly validated, allowing malicious or compromised applications in the same device to force Omni-notes to copy files from its internal storage to its external storage directory, where they would have become accessible to any component with permission to read the external storage. Updating to the newest version (6.2.7) of Omni-notes Android fixes this vulnerability.
0
Attacker Value
Unknown
CVE-2022-44755
Disclosure Date: December 19, 2022 (last updated November 08, 2023)
HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the vulnerability described in CVE-2022-44751. This vulnerability applies to software previously licensed by IBM.
0
Attacker Value
Unknown
CVE-2022-44753
Disclosure Date: December 19, 2022 (last updated November 08, 2023)
HCL Notes is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted WordPerfect file. This vulnerability applies to software previously licensed by IBM.
0
Attacker Value
Unknown
CVE-2022-44751
Disclosure Date: December 19, 2022 (last updated November 08, 2023)
HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the vulnerability described in CVE-2022-44755. This vulnerability applies to software previously licensed by IBM.
0
Attacker Value
Unknown
CVE-2022-27558
Disclosure Date: August 24, 2022 (last updated October 08, 2023)
HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability. Custom password policies are not enforced on certain iNotes forms which could allow users to set weak passwords, leading to easier cracking.
0
Attacker Value
Unknown
CVE-2022-27546
Disclosure Date: August 24, 2022 (last updated October 08, 2023)
HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-supplied input supplied with a form POST request. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's web browser within the security context of the hosting web site and/or steal the victim's cookie-based authentication credentials.
0
Attacker Value
Unknown
CVE-2022-27547
Disclosure Date: August 24, 2022 (last updated October 08, 2023)
HCL iNotes is susceptible to a link to non-existent domain vulnerability. An attacker could use this vulnerability to trick a user into supplying sensitive information such as username, password, credit card number, etc.
0
Attacker Value
Unknown
CVE-2022-36831
Disclosure Date: August 05, 2022 (last updated November 29, 2024)
Path traversal vulnerability in UriFileUtils of Samsung Notes prior to version 4.3.14.39 allows attacker to access some file as Samsung Notes permission.
0