Show filters
698 Total Results
Displaying 71-80 of 698
Sort by:
Attacker Value
Unknown
CVE-2023-6228
Disclosure Date: December 18, 2023 (last updated October 12, 2024)
An issue was found in the tiffcp utility distributed by the libtiff package where a crafted TIFF file on processing may cause a heap-based buffer overflow leads to an application crash.
0
Attacker Value
Unknown
CVE-2023-50469
Disclosure Date: December 15, 2023 (last updated December 20, 2023)
Shenzhen Libituo Technology Co., Ltd LBT-T300-T310 v2.2.2.6 was discovered to contain a buffer overflow via the ApCliEncrypType parameter at /apply.cgi.
0
Attacker Value
Unknown
CVE-2023-40627
Disclosure Date: December 14, 2023 (last updated December 19, 2023)
A reflected XSS vulnerability was discovered in the LivingWord component for Joomla.
0
Attacker Value
Unknown
CVE-2023-49802
Disclosure Date: December 11, 2023 (last updated December 15, 2023)
The LinkedCustomFields plugin for MantisBT allows users to link values between two custom fields, creating linked drop-downs. Prior to version 2.0.1, cross-site scripting in the MantisBT LinkedCustomFields plugin allows Javascript execution, when a crafted Custom Field is linked via the plugin and displayed when reporting a new Issue or editing an existing one. This issue is fixed in version 2.0.1. As a workaround, one may utilize MantisBT's default Content Security Policy, which blocks script execution.
0
Attacker Value
Unknown
CVE-2023-47307
Disclosure Date: November 30, 2023 (last updated December 07, 2023)
Buffer Overflow vulnerability in /apply.cgi in Shenzhen Libituo Technology Co., Ltd LBT-T300-T310 v2.2.2.6 allows attackers to cause a denial of service via the ApCliAuthMode parameter.
0
Attacker Value
Unknown
CVE-2023-48284
Disclosure Date: November 30, 2023 (last updated December 05, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in WebToffee Decorator – WooCommerce Email Customizer allows Cross Site Request Forgery.This issue affects Decorator – WooCommerce Email Customizer: from n/a through 1.2.7.
0
Attacker Value
Unknown
CVE-2023-5738
Disclosure Date: November 27, 2023 (last updated December 02, 2023)
The WordPress Backup & Migration WordPress plugin before 1.4.4 does not sanitise and escape some parameters, which could allow users with a role as low as Subscriber to perform Cross-Site Scripting attacks.
0
Attacker Value
Unknown
CVE-2023-5737
Disclosure Date: November 27, 2023 (last updated December 02, 2023)
The WordPress Backup & Migration WordPress plugin before 1.4.4 does not authorize some AJAX requests, allowing users with a role as low as Subscriber to update some plugin settings.
0
Attacker Value
Unknown
CVE-2023-6277
Disclosure Date: November 24, 2023 (last updated April 25, 2024)
An out-of-memory flaw was found in libtiff. Passing a crafted tiff file to TIFFOpen() API may allow a remote attacker to cause a denial of service via a craft input with size smaller than 379 KB.
0
Attacker Value
Unknown
CVE-2023-31089
Disclosure Date: November 18, 2023 (last updated November 30, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Tradebooster Video XML Sitemap Generator.This issue affects Video XML Sitemap Generator: from n/a through 1.0.0.
0