Show filters
266 Total Results
Displaying 61-70 of 266
Sort by:
Attacker Value
Unknown

CVE-2023-39955

Disclosure Date: August 10, 2023 (last updated October 08, 2023)
Notes is a note-taking app for Nextcloud, an open-source cloud platform. Starting in version 4.4.0 and prior to version 4.8.0, when creating a note file with HTML, the content is rendered in the preview instead of the file being offered to download. Nextcloud Notes app version 4.8.0 contains a patch for the issue. No known workarounds are available.
Attacker Value
Unknown

CVE-2023-28423

Disclosure Date: June 22, 2023 (last updated October 08, 2023)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Prism Tech Studios Modern Footnotes plugin <= 1.4.15 versions.
Attacker Value
Unknown

CVE-2023-33188

Disclosure Date: May 27, 2023 (last updated October 08, 2023)
Omni-notes is an open source note-taking application for Android. The Omni-notes Android app had an insufficient path validation vulnerability when displaying the details of a note received through an externally-provided intent. The paths of the note's attachments were not properly validated, allowing malicious or compromised applications in the same device to force Omni-notes to copy files from its internal storage to its external storage directory, where they would have become accessible to any component with permission to read the external storage. Updating to the newest version (6.2.7) of Omni-notes Android fixes this vulnerability.
Attacker Value
Unknown

CVE-2022-44755

Disclosure Date: December 19, 2022 (last updated November 08, 2023)
HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the vulnerability described in CVE-2022-44751.  This vulnerability applies to software previously licensed by IBM.
Attacker Value
Unknown

CVE-2022-44753

Disclosure Date: December 19, 2022 (last updated November 08, 2023)
HCL Notes is susceptible to a stack based buffer overflow vulnerability in wp6sr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted WordPerfect file.  This vulnerability applies to software previously licensed by IBM.
Attacker Value
Unknown

CVE-2022-44751

Disclosure Date: December 19, 2022 (last updated November 08, 2023)
HCL Notes is susceptible to a stack based buffer overflow vulnerability in lasr.dll in Micro Focus KeyView. This could allow a remote unauthenticated attacker to crash the application or execute arbitrary code via a crafted Lotus Ami Pro file. This is different from the vulnerability described in CVE-2022-44755.  This vulnerability applies to software previously licensed by IBM.
Attacker Value
Unknown

CVE-2022-27558

Disclosure Date: August 24, 2022 (last updated October 08, 2023)
HCL iNotes is susceptible to a Broken Password Strength Checks vulnerability. Custom password policies are not enforced on certain iNotes forms which could allow users to set weak passwords, leading to easier cracking.
Attacker Value
Unknown

CVE-2022-27546

Disclosure Date: August 24, 2022 (last updated October 08, 2023)
HCL iNotes is susceptible to a Reflected Cross-site Scripting (XSS) vulnerability caused by improper validation of user-supplied input supplied with a form POST request. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in a victim's web browser within the security context of the hosting web site and/or steal the victim's cookie-based authentication credentials.
Attacker Value
Unknown

CVE-2022-27547

Disclosure Date: August 24, 2022 (last updated October 08, 2023)
HCL iNotes is susceptible to a link to non-existent domain vulnerability. An attacker could use this vulnerability to trick a user into supplying sensitive information such as username, password, credit card number, etc.
Attacker Value
Unknown

CVE-2022-36831

Disclosure Date: August 05, 2022 (last updated November 29, 2024)
Path traversal vulnerability in UriFileUtils of Samsung Notes prior to version 4.3.14.39 allows attacker to access some file as Samsung Notes permission.