Show filters
50 Total Results
Displaying 1-10 of 50
Sort by:
Attacker Value
Unknown
CVE-2024-11872
Disclosure Date: December 12, 2024 (last updated December 21, 2024)
Epic Games Launcher Incorrect Default Permissions Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Epic Games Launcher. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
The specific flaw exists within the product installer. The product applies incorrect default permissions to a sensitive folder. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-24329.
0
Attacker Value
Unknown
CVE-2023-40182
Disclosure Date: August 25, 2023 (last updated October 08, 2023)
Silverware Games is a premium social network where people can play games online. When using the Recovery form, a noticeably different amount of time passes depending of whether the specified email address presents in our database or not. This has been fixed in version 1.3.7.
0
Attacker Value
Unknown
CVE-2023-40179
Disclosure Date: August 25, 2023 (last updated October 08, 2023)
Silverware Games is a premium social network where people can play games online. Prior to version 1.3.6, the Password Recovery form would throw an error if the specified email was not found in our database. It would only display the "Enter the code" form if the email is associated with a member of the site. Since version 1.3.6, the "Enter the code" form is always returned, showing the message "If the entered email is associated with an account, a code will be sent now". This change prevents potential violators from determining if our site has a user with the specified email.
0
Attacker Value
Unknown
CVE-2023-29192
Disclosure Date: April 10, 2023 (last updated October 08, 2023)
SilverwareGames.io versions before 1.2.19 allow users with access to the game upload panel to edit download links for games uploaded by other developers. This has been fixed in version 1.2.19.
0
Attacker Value
Unknown
CVE-2020-22647
Disclosure Date: March 16, 2023 (last updated October 08, 2023)
An issue found in DepositGame v.1.0 allows an attacker to gain sensitive information via the GetBonusWithdraw and withdraw functions.
0
Attacker Value
Unknown
CVE-2008-10003
Disclosure Date: March 05, 2023 (last updated October 08, 2023)
A vulnerability was found in iGamingModules flashgames 1.1.0. It has been classified as critical. Affected is an unknown function of the file game.php. The manipulation of the argument lid leads to sql injection. It is possible to launch the attack remotely. The name of the patch is 6e57683704885be32eea2ea614f80c9bb8f012c5. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-222288.
0
Attacker Value
Unknown
CVE-2022-23543
Disclosure Date: December 19, 2022 (last updated October 08, 2023)
Silverware Games is a social network where people can play games online. Users can attach URLs to YouTube videos, the site will generate related `<iframe>` when the post will be published. The handler has some sort of protection so non-YouTube links can't be posted, as well as HTML tags are being stripped. However, it was still possible to add custom HTML attributes (e.g. `onclick=alert("xss")`) to the `<iframe>'. This issue was fixed in the version `1.1.34` and does not require any extra actions from our members. There has been no evidence that this vulnerability was used by anyone at this time.
0
Attacker Value
Unknown
CVE-2022-36072
Disclosure Date: September 06, 2022 (last updated October 08, 2023)
SilverwareGames.io is a social network for users to play video games online. In version 1.1.8 and prior, due to an unobvious feature of PHP, hashes generated by built-in functions and starting with the `0e` symbols were being handled as zero multiplied with the `e` number. Therefore, the hash value was equal to 0. The maintainers fixed this in version 1.1.9 by using `===` instead of `==` in comparisons where it is possible (e.g. on sign in/sign up handlers).
0
Attacker Value
Unknown
CVE-2020-5976
Disclosure Date: September 18, 2020 (last updated November 28, 2024)
NVIDIA GeForce NOW, versions prior to 2.0.23 (Windows, macOS) and versions prior to 5.31 (Android, Shield TV), contains a vulnerability in the application software where the network test component transmits sensitive information insecurely, which may lead to information disclosure.
0
Attacker Value
Unknown
CVE-2020-2248
Disclosure Date: September 01, 2020 (last updated February 22, 2025)
Jenkins JSGames Plugin 0.2 and earlier evaluates part of a URL as code, resulting in a reflected cross-site scripting (XSS) vulnerability.
0