Show filters
3,615 Total Results
Displaying 81-90 of 3,615
Sort by:
Attacker Value
Unknown

CVE-2021-37962

Disclosure Date: October 08, 2021 (last updated February 23, 2025)
Use after free in Performance Manager in Google Chrome prior to 94.0.4606.54 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page.
Attacker Value
Unknown

CVE-2021-37973

Disclosure Date: October 08, 2021 (last updated February 23, 2025)
Use after free in Portals in Google Chrome prior to 94.0.4606.61 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Attacker Value
Unknown

CVE-2021-30858

Disclosure Date: August 24, 2021 (last updated February 23, 2025)
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 14.8 and iPadOS 14.8, macOS Big Sur 11.6. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
Attacker Value
High

CVE-2020-11100

Disclosure Date: April 02, 2020 (last updated February 21, 2025)
In hpack_dht_insert in hpack-tbl.c in the HPACK decoder in HAProxy 1.8 through 2.x before 2.1.4, a remote attacker can write arbitrary bytes around a certain location on the heap via a crafted HTTP/2 request, possibly causing remote code execution.
Attacker Value
Unknown

CVE-2023-0950

Disclosure Date: May 25, 2023 (last updated October 08, 2023)
Improper Validation of Array Index vulnerability in the spreadsheet component of The Document Foundation LibreOffice allows an attacker to craft a spreadsheet document that will cause an array index underflow when loaded. In the affected versions of LibreOffice certain malformed spreadsheet formulas, such as AGGREGATE, could be created with less parameters passed to the formula interpreter than it expected, leading to an array index underflow, in which case there is a risk that arbitrary code could be executed. This issue affects: The Document Foundation LibreOffice 7.4 versions prior to 7.4.6; 7.5 versions prior to 7.5.1.
Attacker Value
Unknown

CVE-2022-37452

Disclosure Date: August 07, 2022 (last updated February 24, 2025)
Exim before 4.95 has a heap-based buffer overflow for the alias list in host_name_lookup in host.c when sender_host_name is set.
Attacker Value
Unknown

CVE-2023-43770

Disclosure Date: September 22, 2023 (last updated October 08, 2023)
Roundcube before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3 allows XSS via text/plain e-mail messages with crafted links because of program/lib/Roundcube/rcube_string_replacer.php behavior.
Attacker Value
Unknown

CVE-2020-21365

Disclosure Date: August 15, 2022 (last updated February 24, 2025)
Directory traversal vulnerability in wkhtmltopdf through 0.12.5 allows remote attackers to read local files and disclose sensitive information via a crafted html file running with the default configurations.
Attacker Value
Unknown

CVE-2022-31676

Disclosure Date: August 23, 2022 (last updated February 24, 2025)
VMware Tools (12.0.0, 11.x.y and 10.x.y) contains a local privilege escalation vulnerability. A malicious actor with local non-administrative access to the Guest OS can escalate privileges as a root user in the virtual machine.
Attacker Value
Unknown

CVE-2023-27522

Disclosure Date: March 07, 2023 (last updated February 14, 2025)
HTTP Response Smuggling vulnerability in Apache HTTP Server via mod_proxy_uwsgi. This issue affects Apache HTTP Server: from 2.4.30 through 2.4.55. Special characters in the origin response header can truncate/split the response forwarded to the client.