Show filters
698 Total Results
Displaying 91-100 of 698
Sort by:
Attacker Value
Unknown

CVE-2023-28791

Disclosure Date: October 06, 2023 (last updated October 09, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Gangesh Matta Simple Org Chart plugin <= 2.3.4 versions.
Attacker Value
Unknown

CVE-2023-40008

Disclosure Date: October 06, 2023 (last updated October 11, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Gangesh Matta Simple Org Chart plugin <= 2.3.4 versions.
Attacker Value
Unknown

CVE-2023-41175

Disclosure Date: October 05, 2023 (last updated April 30, 2024)
A vulnerability was found in libtiff due to multiple potential integer overflows in raw2tiff.c. This flaw allows remote attackers to cause a denial of service or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow.
Attacker Value
Unknown

CVE-2023-40745

Disclosure Date: October 05, 2023 (last updated April 30, 2024)
LibTIFF is vulnerable to an integer overflow. This flaw allows remote attackers to cause a denial of service (application crash) or possibly execute an arbitrary code via a crafted tiff image, which triggers a heap-based buffer overflow.
Attacker Value
Unknown

CVE-2023-3576

Disclosure Date: October 04, 2023 (last updated April 25, 2024)
A memory leak flaw was found in Libtiff's tiffcrop utility. This issue occurs when tiffcrop operates on a TIFF image file, allowing an attacker to pass a crafted TIFF image file to tiffcrop utility, which causes this memory leak issue, resulting an application crash, eventually leading to a denial of service.
Attacker Value
Unknown

CVE-2023-36328

Disclosure Date: September 01, 2023 (last updated March 08, 2024)
Integer Overflow vulnerability in mp_grow in libtom libtommath before commit beba892bc0d4e4ded4d667ab1d2a94f4d75109a9, allows attackers to execute arbitrary code and cause a denial of service (DoS).
Attacker Value
Unknown

CVE-2023-3162

Disclosure Date: August 31, 2023 (last updated November 09, 2023)
The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.7.7. This is due to insufficient verification on the user being supplied during a Stripe checkout through the plugin. This allows unauthenticated attackers to log in as users who have orders, who are typically customers.
Attacker Value
Unknown

CVE-2022-40090

Disclosure Date: August 22, 2023 (last updated October 08, 2023)
An issue was discovered in function TIFFReadDirectory libtiff before 4.4.0 allows attackers to cause a denial of service via crafted TIFF file.
Attacker Value
Unknown

CVE-2020-18768

Disclosure Date: August 22, 2023 (last updated October 08, 2023)
There exists one heap buffer overflow in _TIFFmemcpy in tif_unix.c in libtiff 4.0.10, which allows an attacker to cause a denial-of-service through a crafted tiff file.
Attacker Value
Unknown

CVE-2023-4040

Disclosure Date: August 18, 2023 (last updated November 09, 2023)
The Stripe Payment Plugin for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the eh_callback_handler function in versions up to, and including, 3.7.9. This makes it possible for unauthenticated attackers to modify the order status of arbitrary WooCommerce orders.