Show filters
998 Total Results
Displaying 81-90 of 998
Sort by:
Attacker Value
Unknown
CVE-2023-21994
Disclosure Date: July 18, 2023 (last updated October 08, 2023)
Vulnerability in the Oracle Mobile Security Suite product of Oracle Fusion Middleware (component: Android Mobile Authenticator App). Supported versions that are affected are Prior to 11.1.2.3.1. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Mobile Security Suite executes to compromise Oracle Mobile Security Suite. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Mobile Security Suite accessible data. CVSS 3.1 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
0
Attacker Value
Unknown
CVE-2023-29301
Disclosure Date: July 12, 2023 (last updated October 08, 2023)
Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by an Improper Restriction of Excessive Authentication Attempts vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to impact the confidentiality of the user. Exploitation of this issue does not require user interaction.
0
Attacker Value
Unknown
CVE-2022-47376
Disclosure Date: June 13, 2023 (last updated October 08, 2023)
The Alaris Infusion Central software, versions 1.1 to 1.3.2, may contain a recoverable password after the installation. No patient health data is stored in the database, although some site installations may choose to store personal data.
0
Attacker Value
Unknown
CVE-2023-25439
Disclosure Date: May 25, 2023 (last updated October 08, 2023)
Stored Cross Site Scripting (XSS) vulnerability in Square Pig FusionInvoice 2023-1.0, allows attackers to execute arbitrary code via the description or content fields to the expenses, tasks, and customer details.
0
Attacker Value
Unknown
CVE-2023-20870
Disclosure Date: April 25, 2023 (last updated October 08, 2023)
VMware Workstation and Fusion contain an out-of-bounds read vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine.
0
Attacker Value
Unknown
CVE-2023-20869
Disclosure Date: April 25, 2023 (last updated October 08, 2023)
VMware Workstation (17.x) and VMware Fusion (13.x) contain a stack-based buffer-overflow vulnerability that exists in the functionality for sharing host Bluetooth devices with the virtual machine.
0
Attacker Value
Unknown
CVE-2023-20872
Disclosure Date: April 25, 2023 (last updated October 08, 2023)
VMware Workstation and Fusion contain an out-of-bounds read/write vulnerability in SCSI CD/DVD device emulation.
0
Attacker Value
Unknown
CVE-2023-20871
Disclosure Date: April 25, 2023 (last updated October 08, 2023)
VMware Fusion contains a local privilege escalation vulnerability. A malicious actor with read/write access to the host operating system can elevate privileges to gain root access to the host operating system.
0
Attacker Value
Unknown
CVE-2023-26559
Disclosure Date: April 14, 2023 (last updated October 08, 2023)
A directory traversal vulnerability in Oxygen XML Web Author before 25.0.0.3 build 2023021715 and Oxygen Content Fusion before 5.0.3 build 2023022015 allows an attacker to read files from a WEB-INF directory via a crafted HTTP request. (XML Web Author 24.1.0.3 build 2023021714 and 23.1.1.4 build 2023021715 are also fixed versions.)
0
Attacker Value
Unknown
CVE-2023-26361
Disclosure Date: March 14, 2023 (last updated October 08, 2023)
Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in Arbitrary file system read. Exploitation of this issue does not require user interaction, but does require administrator privileges.
0