Show filters
255 Total Results
Displaying 71-80 of 255
Sort by:
Attacker Value
Unknown

CVE-2024-0232

Disclosure Date: January 16, 2024 (last updated April 25, 2024)
A heap use-after-free issue has been identified in SQLite in the jsonParseAddNodeArray() function in sqlite3.c. This flaw allows a local attacker to leverage a victim to pass specially crafted malicious input to the application, potentially causing a crash and leading to a denial of service.
Attacker Value
Unknown

CVE-2023-46623

Disclosure Date: December 29, 2023 (last updated January 05, 2024)
Improper Control of Generation of Code ('Code Injection') vulnerability in TienCOP WP EXtra.This issue affects WP EXtra: from n/a through 6.2.
Attacker Value
Unknown

CVE-2023-51766

Disclosure Date: December 24, 2023 (last updated February 02, 2024)
Exim before 4.97.1 allows SMTP smuggling in certain PIPELINING/CHUNKING configurations. Remote attackers can use a published exploitation technique to inject e-mail messages with a spoofed MAIL FROM address, allowing bypass of an SPF protection mechanism. This occurs because Exim supports <LF>.<CR><LF> but some other popular e-mail servers do not.
Attacker Value
Unknown

CVE-2023-4256

Disclosure Date: December 21, 2023 (last updated January 03, 2024)
Within tcpreplay's tcprewrite, a double free vulnerability has been identified in the tcpedit_dlt_cleanup() function within plugins/dlt_plugins.c. This vulnerability can be exploited by supplying a specifically crafted file to the tcprewrite binary. This flaw enables a local attacker to initiate a Denial of Service (DoS) attack.
Attacker Value
Unknown

CVE-2023-4255

Disclosure Date: December 21, 2023 (last updated January 03, 2024)
An out-of-bounds write issue has been discovered in the backspace handling of the checkType() function in etc.c within the W3M application. This vulnerability is triggered by supplying a specially crafted HTML file to the w3m binary. Exploitation of this flaw could lead to application crashes, resulting in a denial of service condition.
Attacker Value
Unknown

CVE-2023-49164

Disclosure Date: December 19, 2023 (last updated December 22, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in OceanWP Ocean Extra.This issue affects Ocean Extra: from n/a through 2.2.2.
Attacker Value
Unknown

CVE-2023-46212

Disclosure Date: December 19, 2023 (last updated December 23, 2023)
Missing Authorization, Cross-Site Request Forgery (CSRF) vulnerability in TienCOP WP EXtra allows Accessing Functionality Not Properly Constrained by ACLs, Cross Site Request Forgery.This issue affects WP EXtra: from n/a through 6.2.
Attacker Value
Unknown

CVE-2023-49347

Disclosure Date: December 14, 2023 (last updated December 21, 2023)
Temporary data passed between application components by Budgie Extras Windows Previews could potentially be viewed or manipulated. The data is stored in a location that is accessible to any user who has local access to the system. Attackers may read private information from windows, present false information to users, or deny access to the application.
Attacker Value
Unknown

CVE-2023-49346

Disclosure Date: December 14, 2023 (last updated December 21, 2023)
Temporary data passed between application components by Budgie Extras WeatherShow applet could potentially be viewed or manipulated. The data is stored in a location that is accessible to any user who has local access to the system. Attackers may pre-create and control this file to present false information to users or deny access to the application and panel.
Attacker Value
Unknown

CVE-2023-49345

Disclosure Date: December 14, 2023 (last updated December 21, 2023)
Temporary data passed between application components by Budgie Extras Takeabreak applet could potentially be viewed or manipulated. The data is stored in a location that is accessible to any user who has local access to the system. Attackers may pre-create and control this file to present false information to users or deny access to the application and panel.