Show filters
774 Total Results
Displaying 91-100 of 774
Sort by:
Attacker Value
Unknown
CVE-2024-22259
Disclosure Date: March 16, 2024 (last updated February 14, 2025)
Applications that use UriComponentsBuilder in Spring Framework to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html attack or to a SSRF attack if the URL is used after passing validation checks.
This is the same as CVE-2024-22243 https://spring.io/security/cve-2024-22243 , but with different input.
0
Attacker Value
Unknown
CVE-2023-39254
Disclosure Date: March 01, 2024 (last updated February 01, 2025)
Dell Update Package (DUP), Versions prior to 4.9.10 contain an Uncontrolled Search Path vulnerability. A malicious user with local access to the system could potentially exploit this vulnerability to run arbitrary code as admin.
0
Attacker Value
Unknown
CVE-2024-22243
Disclosure Date: February 23, 2024 (last updated February 14, 2025)
Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html attack or to a SSRF attack if the URL is used after passing validation checks.
0
Attacker Value
Unknown
CVE-2024-1309
Disclosure Date: February 13, 2024 (last updated January 04, 2025)
Uncontrolled Resource Consumption vulnerability in Honeywell Niagara Framework on Windows, Linux, QNX allows Content Spoofing.This issue affects Niagara Framework: before Niagara AX 3.8.1, before Niagara 4.1.
0
Attacker Value
Unknown
CVE-2024-24880
Disclosure Date: February 08, 2024 (last updated October 16, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apollo13Themes Apollo13 Framework Extensions allows Stored XSS.This issue affects Apollo13 Framework Extensions: from n/a through 1.9.2.
0
Attacker Value
Unknown
CVE-2023-32454
Disclosure Date: February 06, 2024 (last updated February 14, 2024)
DUP framework version 4.9.4.36 and prior contains insecure operation on Windows junction/Mount point vulnerability. A local malicious standard user could exploit the vulnerability to create arbitrary files, leading to denial of service
0
Attacker Value
Unknown
CVE-2023-48714
Disclosure Date: January 23, 2024 (last updated February 02, 2024)
Silverstripe Framework is the framework that forms the base of the Silverstripe content management system. Prior to versions 4.13.39 and 5.1.11, if a user should not be able to see a record, but that record can be added to a `GridField` using the `GridFieldAddExistingAutocompleter` component, the record's title can be accessed by that user. Versions 4.13.39 and 5.1.11 contain a fix for this issue.
0
Attacker Value
Unknown
CVE-2024-22233
Disclosure Date: January 22, 2024 (last updated February 14, 2025)
In Spring Framework versions 6.0.15 and 6.1.2, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition.
Specifically, an application is vulnerable when all of the following are true:
* the application uses Spring MVC
* Spring Security 6.1.6+ or 6.2.1+ is on the classpath
Typically, Spring Boot applications need the org.springframework.boot:spring-boot-starter-web and org.springframework.boot:spring-boot-starter-security dependencies to meet all conditions.
0
Attacker Value
Unknown
CVE-2024-21640
Disclosure Date: January 13, 2024 (last updated January 23, 2024)
Chromium Embedded Framework (CEF) is a simple framework for embedding Chromium-based browsers in other applications.`CefVideoConsumerOSR::OnFrameCaptured` does not check `pixel_format` properly, which leads to out-of-bounds read out of the sandbox. This vulnerability was patched in commit 1f55d2e.
0
Attacker Value
Unknown
CVE-2024-21639
Disclosure Date: January 12, 2024 (last updated January 23, 2024)
CEF (Chromium Embedded Framework ) is a simple framework for embedding Chromium-based browsers in other applications. `CefLayeredWindowUpdaterOSR::OnAllocatedSharedMemory` does not check the size of the shared memory, which leads to out-of-bounds read outside the sandbox. This vulnerability was patched in commit 1f55d2e.
0