Show filters
71,563 Total Results
Displaying 841-850 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown
CVE-2021-23180
Disclosure Date: March 02, 2022 (last updated October 07, 2023)
A flaw was found in htmldoc in v1.9.12 and before. Null pointer dereference in file_extension(),in file.c may lead to execute arbitrary code and denial of service.
1
Attacker Value
Unknown
CVE-2021-4102
Disclosure Date: February 11, 2022 (last updated October 07, 2023)
Use after free in V8 in Google Chrome prior to 96.0.4664.110 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
1
Attacker Value
Very Low
CVE-2020-13668
Disclosure Date: February 11, 2022 (last updated October 07, 2023)
Access Bypass vulnerability in Drupal Core allows for an attacker to leverage the way that HTML is rendered for affected forms in order to exploit the vulnerability. This issue affects: Drupal Core 8.8.x versions prior to 8.8.10; 8.9.x versions prior to 8.9.6; 9.0.x versions prior to 9.0.6.
0
Attacker Value
Unknown
CVE-2022-23806
Disclosure Date: February 11, 2022 (last updated November 29, 2024)
Curve.IsOnCurve in crypto/elliptic in Go before 1.16.14 and 1.17.x before 1.17.7 can incorrectly return true in situations with a big.Int value that is not a valid field element.
1
Attacker Value
Unknown
CVE-2022-20700
Disclosure Date: February 03, 2022 (last updated October 07, 2023)
Multiple vulnerabilities in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code Elevate privileges Execute arbitrary commands Bypass authentication and authorization protections Fetch and run unsigned software Cause denial of service (DoS) For more information about these vulnerabilities, see the Details section of this advisory.
1
Attacker Value
Unknown
CVE-2021-4079
Disclosure Date: December 23, 2021 (last updated October 07, 2023)
Out of bounds write in WebRTC in Google Chrome prior to 96.0.4664.93 allowed a remote attacker to potentially exploit heap corruption via crafted WebRTC packets.
1
Attacker Value
Unknown
CVE-2021-44790
Disclosure Date: December 20, 2021 (last updated November 08, 2023)
A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might be possible to craft one. This issue affects Apache HTTP Server 2.4.51 and earlier.
1
Attacker Value
Unknown
CVE-2021-38003
Disclosure Date: November 23, 2021 (last updated October 07, 2023)
Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
1
Attacker Value
Unknown
CVE-2021-38000
Disclosure Date: November 23, 2021 (last updated October 07, 2023)
Insufficient validation of untrusted input in Intents in Google Chrome on Android prior to 95.0.4638.69 allowed a remote attacker to arbitrarily browser to a malicious URL via a crafted HTML page.
1
Attacker Value
Moderate
CVE-2020-16152
Disclosure Date: November 14, 2021 (last updated October 07, 2023)
The NetConfig UI administrative interface in Extreme Networks ExtremeWireless Aerohive HiveOS and IQ Engine through 10.0r8a allows attackers to execute PHP code as the root user via remote HTTP requests that insert this code into a log file and then traverse to that file.
0