Show filters
5,933 Total Results
Displaying 91-100 of 5,933
Sort by:
Attacker Value
Unknown

CVE-2024-53966

Disclosure Date: February 05, 2025 (last updated February 12, 2025)
Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Attacker Value
Unknown

CVE-2024-53965

Disclosure Date: February 05, 2025 (last updated February 12, 2025)
Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker to execute arbitrary code in the context of the victim's browser session. By manipulating a DOM element through a crafted URL or user input, the attacker can inject malicious scripts that run when the page is rendered. This type of attack requires user interaction, as the victim would need to access a manipulated link or input data into a vulnerable page.
Attacker Value
Unknown

CVE-2024-53964

Disclosure Date: February 05, 2025 (last updated February 12, 2025)
Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Attacker Value
Unknown

CVE-2024-53963

Disclosure Date: February 05, 2025 (last updated February 12, 2025)
Adobe Experience Manager versions 6.5.21 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability that could be exploited by a low privileged attacker to execute arbitrary code in the context of the victim's browser session. By manipulating a DOM element through a crafted URL or user input, the attacker can inject malicious scripts that run when the page is rendered. This type of attack requires user interaction, as the victim would need to access a manipulated link or input data into a vulnerable page.
Attacker Value
Unknown

CVE-2024-53962

Disclosure Date: February 05, 2025 (last updated February 12, 2025)
Adobe Experience Manager versions 6.5.21 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field.
Attacker Value
Unknown

CVE-2024-49840

Disclosure Date: February 03, 2025 (last updated February 06, 2025)
Memory corruption while Invoking IOCTL calls from user-space to validate FIPS encryption or decryption functionality.
Attacker Value
Unknown

CVE-2024-49838

Disclosure Date: February 03, 2025 (last updated February 06, 2025)
Information disclosure while parsing the OCI IE with invalid length.
Attacker Value
Unknown

CVE-2024-45573

Disclosure Date: February 03, 2025 (last updated February 06, 2025)
Memory corruption may occour while generating test pattern due to negative indexing of display ID.
Attacker Value
Unknown

CVE-2024-45561

Disclosure Date: February 03, 2025 (last updated February 06, 2025)
Memory corruption while handling IOCTL call from user-space to set latency level.
Attacker Value
Unknown

CVE-2024-45560

Disclosure Date: February 03, 2025 (last updated February 06, 2025)
Memory corruption while taking a snapshot with hardware encoder due to unvalidated userspace buffer.