Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown
CVE-2024-5965
Disclosure Date: June 22, 2024 (last updated June 25, 2024)
The Mosaic theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter within the theme's Button shortcode in all versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2022-31521
Disclosure Date: July 11, 2022 (last updated February 24, 2025)
The Niyaz-Mohamed/mosaic repository through 1.0.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
0
Attacker Value
Unknown
CVE-2017-6890
Disclosure Date: May 15, 2017 (last updated November 26, 2024)
A boundary error within the "foveon_load_camf()" function (dcraw_foveon.c) when initializing a huffman table in LibRaw-demosaic-pack-GPL2 before 0.18.2 can be exploited to cause a stack-based buffer overflow.
0
Attacker Value
Unknown
CVE-2017-6889
Disclosure Date: May 15, 2017 (last updated November 26, 2024)
An integer overflow error within the "foveon_load_camf()" function (dcraw_foveon.c) in LibRaw-demosaic-pack-GPL2 before 0.18.2 can be exploited to cause a heap-based buffer overflow.
0
Attacker Value
Unknown
CVE-2014-3426
Disclosure Date: May 08, 2014 (last updated October 05, 2023)
NCSA Mosaic 2.1 through 2.7b5 allows local users to cause a denial of service ("remote control" outage) by creating a /tmp/Mosaic.pid file for every possible PID.
0
Attacker Value
Unknown
CVE-2014-3425
Disclosure Date: May 08, 2014 (last updated October 05, 2023)
NCSA Mosaic 2.0 and earlier allows local users to cause a denial of service ("remote control" outage) by creating a /tmp/xmosaic.pid file for every possible PID.
0
Attacker Value
Unknown
CVE-2008-4599
Disclosure Date: October 18, 2008 (last updated October 04, 2023)
SQL injection vulnerability in category.php in Mosaic Commerce allows remote attackers to execute arbitrary SQL commands via the cid parameter.
0