Show filters
1,086 Total Results
Displaying 91-100 of 1,086
Sort by:
Attacker Value
Unknown
CVE-2024-44117
Disclosure Date: September 10, 2024 (last updated February 26, 2025)
The RFC enabled function module allows a low privileged user to perform various actions, such as modifying the URLs of any user's favourite nodes and workbook ID. There is low impact on integrity and availability of the application.
0
Attacker Value
Unknown
CVE-2024-44116
Disclosure Date: September 10, 2024 (last updated February 26, 2025)
The RFC enabled function module allows a low privileged user to add any workbook to any user's workplace favourites. This vulnerability could be utilized to identify usernames and access information about targeted user's workplaces. There is low impact on integrity of the application.
0
Attacker Value
Unknown
CVE-2024-44115
Disclosure Date: September 10, 2024 (last updated February 26, 2025)
The RFC enabled function module allows a low privileged user to add URLs to any user's workplace favourites. This vulnerability could be utilized to identify usernames and access information about targeted user's workplaces, and nodes. There is low impact on integrity of the application
0
Attacker Value
Unknown
CVE-2024-42380
Disclosure Date: September 10, 2024 (last updated February 26, 2025)
The RFC enabled function module allows a low privileged user to read any user's workplace favourites and user menu along with all the specific data of each node. Usernames can be enumerated by exploiting vulnerability. There is low impact on confidentiality of the application.
0
Attacker Value
Unknown
CVE-2024-42371
Disclosure Date: September 10, 2024 (last updated February 26, 2025)
The RFC enabled function module allows a low privileged user to delete the workplace favourites of any user. This vulnerability could be utilized to identify usernames and access information about targeted user's workplaces and nodes. There is low impact on integrity and availability of the application.
0
Attacker Value
Unknown
CVE-2024-6789
Disclosure Date: August 27, 2024 (last updated February 26, 2025)
A path traversal issue in API endpoint in M-Files Server before version 24.8.13981.0 and LTS 24.2.13421.15 SR2 and LTS 23.8.12892.0 SR6 allows authenticated user to read files
0
Attacker Value
Unknown
CVE-2024-5849
Disclosure Date: August 13, 2024 (last updated February 26, 2025)
An unauthenticated remote attacker may use a reflected XSS vulnerability to obtain information from a user or reboot the affected device once.
0
Attacker Value
Unknown
CVE-2024-38502
Disclosure Date: August 13, 2024 (last updated February 26, 2025)
An unauthenticated remote attacker may use stored XSS vulnerability to obtain information from a user or reboot the affected device once.
0
Attacker Value
Unknown
CVE-2024-38501
Disclosure Date: August 13, 2024 (last updated February 26, 2025)
An unauthenticated remote attacker may use a HTML injection vulnerability with limited length to inject malicious HTML code and gain low-privileged access on the affected device.
0
Attacker Value
Unknown
CVE-2024-7006
Disclosure Date: August 12, 2024 (last updated February 26, 2025)
A null pointer dereference flaw was found in Libtiff via `tif_dirinfo.c`. This issue may allow an attacker to trigger memory allocation failures through certain means, such as restricting the heap space size or injecting faults, causing a segmentation fault. This can cause an application crash, eventually leading to a denial of service.
0