Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown

CVE-2023-47845

Disclosure Date: June 12, 2024 (last updated June 12, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in Lim Kai Yang Grab & Save.This issue affects Grab & Save: from n/a through 1.0.4.
0
Attacker Value
Unknown

CVE-2024-25958

Disclosure Date: March 26, 2024 (last updated January 29, 2025)
Dell Grab for Windows, versions up to and including 5.0.4, contain Weak Application Folder Permissions vulnerability. A local authenticated attacker could potentially exploit this vulnerability, leading to privilege escalation, unauthorized access to application data, unauthorized modification of application data and service disruption.
Attacker Value
Unknown

CVE-2024-25957

Disclosure Date: March 26, 2024 (last updated January 29, 2025)
Dell Grab for Windows, versions 5.0.4 and below, contains a cleartext storage of sensitive information vulnerability in its appsync module. An authenticated local attacker could potentially exploit this vulnerability, leading to information disclosure that could be used to access the appsync application with elevated privileges.
Attacker Value
Unknown

CVE-2024-25956

Disclosure Date: March 26, 2024 (last updated January 29, 2025)
Dell Grab for Windows, versions 5.0.4 and below, contains an improper file permissions vulnerability. A locally authenticated attacker could potentially exploit this vulnerability, leading to the information disclosure of certain system information.
Attacker Value
Unknown

CVE-2023-47844

Disclosure Date: November 30, 2023 (last updated December 06, 2023)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Lim Kai Yang Grab & Save allows Reflected XSS.This issue affects Grab & Save: from n/a through 1.0.4.
Attacker Value
Unknown

CVE-2010-10001

Disclosure Date: March 28, 2022 (last updated February 23, 2025)
A vulnerability, which was classified as problematic, was found in Shemes GrabIt up to 1.7.2 Beta 4. This affects the component NZB Date Parser. The manipulation of the argument date with the input 1000000000000000 as part of a NZB File leads to a denial of service. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Attacker Value
Unknown

CVE-2015-9469

Disclosure Date: October 10, 2019 (last updated November 27, 2024)
The content-grabber plugin 1.0 for WordPress has XSS via obj_field_name or obj_field_id.
Attacker Value
Unknown

CVE-2019-15769

Disclosure Date: August 29, 2019 (last updated November 27, 2024)
The handl-utm-grabber plugin before 2.6.5 for WordPress has CSRF via add_option and update_option.
0
Attacker Value
Unknown

CVE-2009-1586

Disclosure Date: May 07, 2009 (last updated October 04, 2023)
Stack-based buffer overflow in the NZB importer feature in GrabIt 1.7.2 Beta 3 and earlier allows remote attackers to execute arbitrary code via a crafted DTD reference in a DOCTYPE element in an NZB file.
0
Attacker Value
Unknown

CVE-2008-0959

Disclosure Date: May 29, 2008 (last updated October 04, 2023)
Multiple stack-based buffer overflows in the Online Media Technologies NCTSoft NCTAudioInformation2 ActiveX control in NCTAudioInformation2.dll, as used in (1) Power Audio CD Grabber 1.0, (2) Power Audio CD Burner 1.02, (3) CinematicMP3 1.4.0.0, (4) Alive MP3 WAV Converter 3.9.3.2, and possibly other products, allow remote attackers to execute arbitrary code via unspecified vectors.
0