Show filters
1,086 Total Results
Displaying 91-100 of 1,086
Sort by:
Attacker Value
Unknown

CVE-2024-44117

Disclosure Date: September 10, 2024 (last updated February 26, 2025)
The RFC enabled function module allows a low privileged user to perform various actions, such as modifying the URLs of any user's favourite nodes and workbook ID. There is low impact on integrity and availability of the application.
0
Attacker Value
Unknown

CVE-2024-44116

Disclosure Date: September 10, 2024 (last updated February 26, 2025)
The RFC enabled function module allows a low privileged user to add any workbook to any user's workplace favourites. This vulnerability could be utilized to identify usernames and access information about targeted user's workplaces. There is low impact on integrity of the application.
0
Attacker Value
Unknown

CVE-2024-44115

Disclosure Date: September 10, 2024 (last updated February 26, 2025)
The RFC enabled function module allows a low privileged user to add URLs to any user's workplace favourites. This vulnerability could be utilized to identify usernames and access information about targeted user's workplaces, and nodes. There is low impact on integrity of the application
0
Attacker Value
Unknown

CVE-2024-42380

Disclosure Date: September 10, 2024 (last updated February 26, 2025)
The RFC enabled function module allows a low privileged user to read any user's workplace favourites and user menu along with all the specific data of each node. Usernames can be enumerated by exploiting vulnerability. There is low impact on confidentiality of the application.
0
Attacker Value
Unknown

CVE-2024-42371

Disclosure Date: September 10, 2024 (last updated February 26, 2025)
The RFC enabled function module allows a low privileged user to delete the workplace favourites of any user. This vulnerability could be utilized to identify usernames and access information about targeted user's workplaces and nodes. There is low impact on integrity and availability of the application.
0
Attacker Value
Unknown

CVE-2024-6789

Disclosure Date: August 27, 2024 (last updated February 26, 2025)
A path traversal issue in API endpoint in M-Files Server before version 24.8.13981.0 and LTS 24.2.13421.15 SR2 and LTS 23.8.12892.0 SR6 allows authenticated user to read files
Attacker Value
Unknown

CVE-2024-5849

Disclosure Date: August 13, 2024 (last updated February 26, 2025)
An unauthenticated remote attacker may use a reflected XSS vulnerability to obtain information from a user or reboot the affected device once.
Attacker Value
Unknown

CVE-2024-38502

Disclosure Date: August 13, 2024 (last updated February 26, 2025)
An unauthenticated remote attacker may use stored XSS vulnerability to obtain information from a user or reboot the affected device once.
Attacker Value
Unknown

CVE-2024-38501

Disclosure Date: August 13, 2024 (last updated February 26, 2025)
An unauthenticated remote attacker may use a HTML injection vulnerability with limited length to inject malicious HTML code and gain low-privileged access on the affected device.
Attacker Value
Unknown

CVE-2024-7006

Disclosure Date: August 12, 2024 (last updated February 26, 2025)
A null pointer dereference flaw was found in Libtiff via `tif_dirinfo.c`. This issue may allow an attacker to trigger memory allocation failures through certain means, such as restricting the heap space size or injecting faults, causing a segmentation fault. This can cause an application crash, eventually leading to a denial of service.