Show filters
112 Total Results
Displaying 81-90 of 112
Sort by:
Attacker Value
Unknown
CVE-2019-10646
Disclosure Date: March 30, 2019 (last updated November 27, 2024)
Wolf CMS v0.8.3.1 is affected by cross site scripting (XSS) in the module Add Snippet (/?/admin/snippet/add). This allows an attacker to insert arbitrary JavaScript as user input, which will be executed whenever the affected snippet is loaded.
0
Attacker Value
Unknown
CVE-2019-6439
Disclosure Date: January 16, 2019 (last updated November 27, 2024)
examples/benchmark/tls_bench.c in a benchmark tool in wolfSSL through 3.15.7 has a heap-based buffer overflow.
0
Attacker Value
Unknown
CVE-2018-16870
Disclosure Date: January 03, 2019 (last updated November 27, 2024)
It was found that wolfssl before 3.15.7 is vulnerable to a new variant of the Bleichenbacher attack to perform downgrade attacks against TLS. This may lead to leakage of sensible data.
0
Attacker Value
Unknown
CVE-2018-15842
Disclosure Date: August 25, 2018 (last updated November 27, 2024)
WolfCMS 0.8.3.1 has XSS via the /?/admin/page/add slug parameter.
0
Attacker Value
Unknown
CVE-2018-14837
Disclosure Date: August 10, 2018 (last updated November 27, 2024)
Wolf CMS 0.8.3.1 has XSS in the Snippets tab, as demonstrated by a ?/admin/snippet/edit/1 URI.
0
Attacker Value
Unknown
CVE-2018-14012
Disclosure Date: July 12, 2018 (last updated November 27, 2024)
WolfSight CMS 3.2 allows SQL injection via the PATH_INFO to the default URI.
0
Attacker Value
Unknown
CVE-2018-12436
Disclosure Date: June 15, 2018 (last updated November 26, 2024)
wolfcrypt/src/ecc.c in wolfSSL before 3.15.1.patch allows a memory-cache side-channel attack on ECDSA signatures, aka the Return Of the Hidden Number Problem or ROHNP. To discover an ECDSA key, the attacker needs access to either the local machine or a different virtual machine on the same physical host.
0
Attacker Value
Unknown
CVE-2018-11505
Disclosure Date: May 26, 2018 (last updated November 26, 2024)
The Werewolf Online application 0.8.8 for Android allows attackers to discover the Firebase token by reading logcat output.
0
Attacker Value
Unknown
CVE-2018-8813
Disclosure Date: April 04, 2018 (last updated November 26, 2024)
Open redirect vulnerability in the login[redirect] parameter login functionality in WolfCMS 0.8.3.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a malformed URL.
0
Attacker Value
Unknown
CVE-2018-8814
Disclosure Date: April 04, 2018 (last updated November 26, 2024)
Cross-site request forgery (CSRF) vulnerability in WolfCMS 0.8.3.1 allows remote attackers to hijack the authentication of users for requests that modify plugin/[pluginname]/settings by crafting a malicious request.
0