Show filters
205 Total Results
Displaying 1-10 of 205
Sort by:
Attacker Value
Low

CVE-2019-11358

Disclosure Date: April 20, 2019 (last updated February 17, 2024)
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
Attacker Value
High

CVE-2014-0160 (AKA: Heartbleed)

Disclosure Date: April 07, 2014 (last updated July 03, 2024)
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to d1_both.c and t1_lib.c, aka the Heartbleed bug.
Attacker Value
Unknown

CVE-2023-45364

Disclosure Date: October 09, 2023 (last updated October 13, 2023)
An issue was discovered in includes/page/Article.php in MediaWiki 1.36.x through 1.39.x before 1.39.5 and 1.40.x before 1.40.1. Deleted revision existence is leaked due to incorrect permissions being checked. This reveals that a given revision ID belonged to the given page title, and its timestamp, both of which are not supposed to be public information.
Attacker Value
Unknown

CVE-2023-45363

Disclosure Date: October 09, 2023 (last updated October 13, 2023)
An issue was discovered in ApiPageSet.php in MediaWiki before 1.35.12, 1.36.x through 1.39.x before 1.39.5, and 1.40.x before 1.40.1. It allows attackers to cause a denial of service (unbounded loop and RequestTimeoutException) when querying pages redirected to other variants with redirects and converttitles set.
Attacker Value
Unknown

CVE-2023-3550

Disclosure Date: September 25, 2023 (last updated February 14, 2025)
Mediawiki v1.40.0 does not validate namespaces used in XML files. Therefore, if the instance administrator allows XML file uploads, a remote attacker with a low-privileged user account can use this exploit to become an administrator by sending a malicious link to the instance administrator.
0
Attacker Value
Unknown

CVE-2022-1270

Disclosure Date: September 28, 2022 (last updated December 22, 2024)
In GraphicsMagick, a heap buffer overflow was found when parsing MIFF.
Attacker Value
Unknown

CVE-2022-37797

Disclosure Date: September 12, 2022 (last updated November 29, 2024)
In lighttpd 1.4.65, mod_wstunnel does not initialize a handler function pointer if an invalid HTTP request (websocket handshake) is received. It leads to null pointer dereference which crashes the server. It could be used by an external attacker to cause denial of service condition.
Attacker Value
Unknown

CVE-2022-1304

Disclosure Date: April 14, 2022 (last updated October 07, 2023)
An out-of-bounds read/write vulnerability was found in e2fsprogs 1.46.5. This issue leads to a segmentation fault and possibly arbitrary code execution via a specially crafted filesystem.
Attacker Value
Unknown

CVE-2022-0996

Disclosure Date: March 23, 2022 (last updated October 07, 2023)
A vulnerability was found in the 389 Directory Server that allows expired passwords to access the database to cause improper authentication.
Attacker Value
Unknown

CVE-2022-0918

Disclosure Date: March 16, 2022 (last updated February 14, 2025)
A vulnerability was discovered in the 389 Directory Server that allows an unauthenticated attacker with network access to the LDAP port to cause a denial of service. The denial of service is triggered by a single message sent over a TCP connection, no bind or other authentication is required. The message triggers a segmentation fault that results in slapd crashing.