Show filters
212 Total Results
Displaying 1-10 of 212
Sort by:
Attacker Value
Unknown
VLC zlib_decompress_extra Double Free Vulnerability
Disclosure Date: June 18, 2019 (last updated October 06, 2023)
An issue was discovered in zlib_decompress_extra in modules/demux/mkv/util.cpp in VideoLAN VLC media player 3.x through 3.0.7. The Matroska demuxer, while parsing a malformed MKV file type, has a double free.
0
Attacker Value
Unknown
CVE-2022-4974
Disclosure Date: October 16, 2024 (last updated October 16, 2024)
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
0
Attacker Value
Unknown
CVE-2024-31941
Disclosure Date: April 15, 2024 (last updated April 15, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in CodePeople CP Media Player.This issue affects CP Media Player: from n/a through 1.1.3.
0
Attacker Value
Unknown
CVE-2023-46814
Disclosure Date: November 22, 2023 (last updated November 30, 2023)
A binary hijacking vulnerability exists within the VideoLAN VLC media player before 3.0.19 on Windows. The uninstaller attempts to execute code with elevated privileges out of a standard user writable location. Standard users may use this to gain arbitrary code execution as SYSTEM.
0
Attacker Value
Unknown
CVE-2023-47360
Disclosure Date: November 07, 2023 (last updated November 14, 2023)
Videolan VLC prior to version 3.0.20 contains an Integer underflow that leads to an incorrect packet length.
0
Attacker Value
Unknown
CVE-2023-47359
Disclosure Date: November 07, 2023 (last updated November 14, 2023)
Videolan VLC prior to version 3.0.20 contains an incorrect offset read that leads to a Heap-Based Buffer Overflow in function GetPacket() and results in a memory corruption.
0
Attacker Value
Unknown
CVE-2022-36246
Disclosure Date: May 29, 2023 (last updated October 08, 2023)
Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Insecure Permissions.
0
Attacker Value
Unknown
CVE-2022-36244
Disclosure Date: May 29, 2023 (last updated October 08, 2023)
Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 suffers from Multiple Stored Cross-Site Scripting (XSS) vulnerabilities via Shop Beat Control Panel found at www.shopbeat.co.za controlpanel.shopbeat.co.za.
0
Attacker Value
Unknown
CVE-2022-36247
Disclosure Date: May 29, 2023 (last updated October 08, 2023)
Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to IDOR via controlpanel.shopbeat.co.za.
0
Attacker Value
Unknown
CVE-2022-36249
Disclosure Date: May 29, 2023 (last updated October 08, 2023)
Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Bypass 2FA via APIs. For Controlpanel Lite. "After login we are directly able to use the bearer token or jsession ID to access the apis instead of entering the 2FA code. Thus, leading to bypass of 2FA on API level.
0