Show filters
863 Total Results
Displaying 71-80 of 863
Sort by:
Attacker Value
Unknown

CVE-2023-7066

Disclosure Date: August 12, 2024 (last updated August 13, 2024)
The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PDF files. This could allow an attacker to execute code in the context of the current process.
0
Attacker Value
Unknown

CVE-2024-43114

Disclosure Date: August 06, 2024 (last updated September 12, 2024)
In JetBrains TeamCity before 2024.07.1 possible privilege escalation due to incorrect directory permissions
Attacker Value
Unknown

CVE-2024-41829

Disclosure Date: July 22, 2024 (last updated August 15, 2024)
In JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space Application connection
Attacker Value
Unknown

CVE-2024-41828

Disclosure Date: July 22, 2024 (last updated August 08, 2024)
In JetBrains TeamCity before 2024.07 comparison of authorization tokens took non-constant time
Attacker Value
Unknown

CVE-2024-41827

Disclosure Date: July 22, 2024 (last updated August 08, 2024)
In JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expiration
Attacker Value
Unknown

CVE-2024-41826

Disclosure Date: July 22, 2024 (last updated August 08, 2024)
In JetBrains TeamCity before 2024.07 stored XSS was possible on Show Connection page
Attacker Value
Unknown

CVE-2024-41825

Disclosure Date: July 22, 2024 (last updated August 08, 2024)
In JetBrains TeamCity before 2024.07 stored XSS was possible on the Code Inspection tab
Attacker Value
Unknown

CVE-2024-41824

Disclosure Date: July 22, 2024 (last updated August 08, 2024)
In JetBrains TeamCity before 2024.07 parameters of the "password" type could leak into the build log in some specific cases
Attacker Value
Unknown

CVE-2024-38670

Disclosure Date: July 20, 2024 (last updated July 20, 2024)
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Team Members allows Stored XSS.This issue affects Team Members: from n/a through 5.3.3.
0
Attacker Value
Unknown

CVE-2024-20396

Disclosure Date: July 17, 2024 (last updated July 18, 2024)
A vulnerability in the protocol handlers of Cisco Webex App could allow an unauthenticated, remote attacker to gain access to sensitive information. This vulnerability exists because the affected application does not safely handle file protocol handlers. An attacker could exploit this vulnerability by persuading a user to follow a link that is designed to cause the application to send requests. If the attacker can observe transmitted traffic in a privileged network position, a successful exploit could allow the attacker to capture sensitive information, including credential information, from the requests.
0