Show filters
400 Total Results
Displaying 81-90 of 400
Sort by:
Attacker Value
Unknown

CVE-2020-19188

Disclosure Date: August 22, 2023 (last updated February 25, 2025)
Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1116 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.
Attacker Value
Unknown

CVE-2020-19187

Disclosure Date: August 22, 2023 (last updated February 25, 2025)
Buffer Overflow vulnerability in fmt_entry function in progs/dump_entry.c:1100 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.
Attacker Value
Unknown

CVE-2020-19186

Disclosure Date: August 22, 2023 (last updated February 25, 2025)
Buffer Overflow vulnerability in _nc_find_entry function in tinfo/comp_hash.c:66 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.
Attacker Value
Unknown

CVE-2020-19185

Disclosure Date: August 22, 2023 (last updated February 25, 2025)
Buffer Overflow vulnerability in one_one_mapping function in progs/dump_entry.c:1373 in ncurses 6.1 allows remote attackers to cause a denial of service via crafted command.
Attacker Value
Unknown

CVE-2023-39532

Disclosure Date: August 08, 2023 (last updated February 25, 2025)
SES is a JavaScript environment that allows safe execution of arbitrary programs in Compartments. In version 0.18.0 prior to 0.18.7, 0.17.0 prior to 0.17.1, 0.16.0 prior to 0.16.1, 0.15.0 prior to 0.15.24, 0.14.0 prior to 0.14.5, an 0.13.0 prior to 0.13.5, there is a hole in the confinement of guest applications under SES that may manifest as either the ability to exfiltrate information or execute arbitrary code depending on the configuration and implementation of the surrounding host. Guest program running inside a Compartment with as few as no endowments can gain access to the surrounding host’s dynamic import by using dynamic import after the spread operator, like `{...import(arbitraryModuleSpecifier)}`. On the web or in web extensions, a Content-Security-Policy following ordinary best practices likely mitigates both the risk of exfiltration and execution of arbitrary code, at least limiting the modules that the attacker can import to those that are already part of the applicatio…
Attacker Value
Unknown

CVE-2023-37873

Disclosure Date: August 05, 2023 (last updated February 25, 2025)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WooCommerce Shipping Multiple Addresses plugin <= 3.8.5 versions.
Attacker Value
Unknown

CVE-2023-4167

Disclosure Date: August 05, 2023 (last updated February 25, 2025)
A vulnerability was found in Media Browser Emby Server 4.7.13.0 and classified as problematic. This issue affects some unknown processing of the file /web/. The manipulation leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-236183.
Attacker Value
Unknown

CVE-2023-32226

Disclosure Date: July 30, 2023 (last updated February 25, 2025)
Sysaid - CWE-552: Files or Directories Accessible to External Parties -  Authenticated users may exfiltrate files from the server via an unspecified method.
Attacker Value
Unknown

CVE-2023-32225

Disclosure Date: July 30, 2023 (last updated February 25, 2025)
Sysaid - CWE-434: Unrestricted Upload of File with Dangerous Type -  A malicious user with administrative privileges may be able to upload a dangerous filetype via an unspecified method.
Attacker Value
Unknown

CVE-2023-37976

Disclosure Date: July 27, 2023 (last updated February 25, 2025)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Radio Forge Muses Player with Skins plugin <= 2.5 versions.