Show filters
155 Total Results
Displaying 71-80 of 155
Sort by:
Attacker Value
Unknown

CVE-2023-47217

Disclosure Date: November 20, 2023 (last updated September 10, 2024)
in OpenHarmony v3.2.2 and prior versions allow a local attacker cause DOS through buffer overflow.
Attacker Value
Unknown

CVE-2023-46705

Disclosure Date: November 20, 2023 (last updated September 10, 2024)
in OpenHarmony v3.2.2 and prior versions allow a local attacker causes system information leak through type confusion.
Attacker Value
Unknown

CVE-2023-46100

Disclosure Date: November 20, 2023 (last updated September 10, 2024)
in OpenHarmony v3.2.2 and prior versions allow a local attacker get sensitive buffer information through use of uninitialized resource.
Attacker Value
Unknown

CVE-2023-43612

Disclosure Date: November 20, 2023 (last updated September 10, 2024)
in OpenHarmony v3.2.2 and prior versions allow a local attacker arbitrary file read and write through improper preservation of permissions.
Attacker Value
Unknown

CVE-2023-42774

Disclosure Date: November 20, 2023 (last updated September 10, 2024)
in OpenHarmony v3.2.2 and prior versions allow a local attacker get confidential information through incorrect default permissions.
Attacker Value
Unknown

CVE-2023-3116

Disclosure Date: November 20, 2023 (last updated September 10, 2024)
in OpenHarmony v3.2.2 and prior versions allow a local attacker get confidential information or rewrite sensitive file through incorrect default permissions.
Attacker Value
Unknown

CVE-2023-5601

Disclosure Date: November 06, 2023 (last updated November 15, 2023)
The WooCommerce Ninja Forms Product Add-ons WordPress plugin before 1.7.1 does not validate the file to be uploaded, allowing any unauthenticated users to upload arbitrary files to the server, leading to RCE.
Attacker Value
Unknown

CVE-2023-4753

Disclosure Date: September 21, 2023 (last updated September 10, 2024)
OpenHarmony v3.2.1 and prior version has a system call function usage error. Local attackers can crash kernel by the error input.
Attacker Value
Unknown

CVE-2023-36351

Disclosure Date: August 01, 2023 (last updated October 08, 2023)
An issue in Viatom Health ViHealth for Android v.2.74.58 and before allows a remote attacker to execute arbitrary code via the com.viatom.baselib.mvvm.webWebViewActivity component.
Attacker Value
Unknown

CVE-2023-33211

Disclosure Date: May 28, 2023 (last updated February 25, 2025)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in André Bräkling WP-Matomo Integration (WP-Piwik) plugin <= 1.0.27 versions.