Show filters
3,830 Total Results
Displaying 61-70 of 3,830
Sort by:
Attacker Value
Unknown
CVE-2024-52283
Disclosure Date: November 28, 2024 (last updated December 21, 2024)
Missing sanitation of inputs allowed arbitrary users to conduct a stored XSS attack that triggers for users that view a certain project
0
Attacker Value
Unknown
CVE-2024-49503
Disclosure Date: November 28, 2024 (last updated December 21, 2024)
A Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in SUSE manager allows attackers to execute Javascript code in the organization credentials sub page.
This issue affects Container suse/manager/5.0/x86_64/server:5.0.2.7.8.1: before 5.0.15-150600.3.10.2; SUSE Manager Server Module 4.3: before 4.3.42-150400.3.52.1.
0
Attacker Value
Unknown
CVE-2024-49502
Disclosure Date: November 28, 2024 (last updated December 21, 2024)
A Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in the Setup Wizard, HTTP Proxy credentials pane in spacewalk-web allows attackers to attack users by providing specially crafted URLs to click.
This issue affects Container suse/manager/5.0/x86_64/server:5.0.2.7.8.1: before 5.0.15-150600.3.10.2; SUSE Manager Server Module 4.3: before 4.3.42-150400.3.52.1.
0
Attacker Value
Unknown
CVE-2024-22038
Disclosure Date: November 28, 2024 (last updated December 21, 2024)
Various problems in obs-scm-bridge allows attackers that create specially crafted git repositories to leak information of cause denial of service.
0
Attacker Value
Unknown
CVE-2024-22037
Disclosure Date: November 28, 2024 (last updated December 21, 2024)
The uyuni-server-attestation systemd service needs a database_password environment variable. This file has 640 permission, and cannot be shown users, but the environment is still exposed by systemd to non-privileged users.
0
Attacker Value
Unknown
CVE-2024-49506
Disclosure Date: November 13, 2024 (last updated November 14, 2024)
Insecure creation of temporary files allows local users on systems with non-default configurations to cause denial of service or set the encryption key for a filesystem
0
Attacker Value
Unknown
CVE-2024-49505
Disclosure Date: November 13, 2024 (last updated November 15, 2024)
A Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in openSUSE Tumbleweed MirrorCache allows the execution of arbitrary JS via reflected XSS in the REGEX and P parameters.
This issue affects MirrorCache before 1.083.
0
Attacker Value
Unknown
CVE-2024-49504
Disclosure Date: November 13, 2024 (last updated November 14, 2024)
grub2 allowed attackers with access to the grub shell to access files on the encrypted disks.
0
Attacker Value
Unknown
CVE-2022-45157
Disclosure Date: November 13, 2024 (last updated November 14, 2024)
A vulnerability has been identified in the way that Rancher stores vSphere's CPI (Cloud Provider Interface) and CSI (Container Storage Interface) credentials used to deploy clusters through the vSphere cloud provider. This issue leads to the vSphere CPI and CSI passwords being stored in a plaintext object inside Rancher. This vulnerability is only applicable to users that deploy clusters in vSphere environments.
0
Attacker Value
Unknown
CVE-2024-46956
Disclosure Date: November 10, 2024 (last updated November 15, 2024)
An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code execution.
0