Show filters
461 Total Results
Displaying 81-90 of 461
Sort by:
Attacker Value
Unknown

CVE-2023-23327

Disclosure Date: March 10, 2023 (last updated February 24, 2025)
An Information Disclosure vulnerability exists in AvantFAX 3.3.7. Backups of the AvantFAX sent/received faxes, and database backups are stored using the current date as the filename and hosted on the web server without access controls.
Attacker Value
Unknown

CVE-2023-23326

Disclosure Date: March 10, 2023 (last updated February 24, 2025)
A Stored Cross-Site Scripting (XSS) vulnerability exists in AvantFAX 3.3.7. An authenticated low privilege user can inject arbitrary Javascript into their e-mail address which is executed when an administrator logs into AvantFAX to view the admin dashboard. This may result in stealing an administrator's session cookie and hijacking their session.
Attacker Value
Unknown

CVE-2014-125087

Disclosure Date: February 19, 2023 (last updated February 24, 2025)
A vulnerability was found in java-xmlbuilder up to 1.1. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to xml external entity reference. Upgrading to version 1.2 is able to address this issue. The name of the patch is e6fddca201790abab4f2c274341c0bb8835c3e73. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-221480.
Attacker Value
Unknown

CVE-2022-40037

Disclosure Date: January 26, 2023 (last updated February 24, 2025)
An issue discovered in Rawchen blog-ssm v1.0 allows remote attacker to escalate privileges and execute arbitrary commands via the component /upFile.
Attacker Value
Unknown

CVE-2022-40034

Disclosure Date: January 23, 2023 (last updated February 24, 2025)
Cross-Site Scripting (XSS) vulnerability found in Rawchen blog-ssm v1.0 allows attackers to execute arbitrary code via the 'notifyInfo' parameter.
Attacker Value
Unknown

CVE-2022-24913

Disclosure Date: January 12, 2023 (last updated February 24, 2025)
Versions of the package com.fasterxml.util:java-merge-sort before 1.1.0 are vulnerable to Insecure Temporary File in the StdTempFileProvider() function in StdTempFileProvider.java, which uses the permissive File.createTempFile() function, exposing temporary file contents.
Attacker Value
Unknown

CVE-2022-4294

Disclosure Date: January 10, 2023 (last updated February 24, 2025)
Norton, Avira, Avast and AVG Antivirus for Windows may be susceptible to a Privilege Escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.
Attacker Value
Unknown

CVE-2022-45688

Disclosure Date: December 13, 2022 (last updated February 24, 2025)
A stack overflow in the XML.toJSONObject component of hutool-json v5.8.10 allows attackers to cause a Denial of Service (DoS) via crafted JSON or XML data.
Attacker Value
Unknown

CVE-2022-4291

Disclosure Date: December 08, 2022 (last updated February 24, 2025)
The aswjsflt.dll library from Avast Antivirus windows contained a potentially exploitable heap corruption vulnerability that could enable an attacker to bypass the sandbox of the application it was loaded into, if applicable. This issue was fixed in version 18.0.1478 of the Script Shield Component.
Attacker Value
Unknown

CVE-2022-4173

Disclosure Date: December 06, 2022 (last updated February 24, 2025)
A vulnerability within the malware removal functionality of Avast and AVG Antivirus allowed an attacker with write access to the filesystem, to escalate his privileges in certain scenarios. The issue was fixed with Avast and AVG Antivirus version 22.10.