Show filters
24 Total Results
Displaying 1-10 of 24
Sort by:
Attacker Value
Unknown
CVE-2024-47536
Disclosure Date: September 30, 2024 (last updated October 01, 2024)
Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. A user with the editmyprivateinfo right or who can otherwise change their name can XSS themselves by setting their "real name" to an XSS payload. This vulnerability is fixed in 2.31.0.
0
Attacker Value
Unknown
CVE-2024-36123
Disclosure Date: June 03, 2024 (last updated June 04, 2024)
Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. The page `MediaWiki:Tagline` has its contents used unescaped, so custom HTML (including Javascript) can be injected by someone with the ability to edit the MediaWiki namespace (typically those with the `editinterface` permission, or sysops). This vulnerability is fixed in 2.16.0.
0
Attacker Value
Unknown
CVE-2016-1203
Disclosure Date: October 31, 2023 (last updated November 09, 2023)
Improper file verification vulnerability in SaAT Netizen installer ver.1.2.0.424 and earlier, and SaAT Netizen ver.1.2.0.8 (Build427) and earlier allows a remote unauthenticated attacker to conduct a man-in-the-middle attack. A successful exploitation may result in a malicious file being downloaded and executed.
0
Attacker Value
Unknown
CVE-2022-40279
Disclosure Date: September 29, 2022 (last updated October 08, 2023)
An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). l2_packet_receive_timeout in wpa_supplicant/src/l2_packet/l2_packet_pcap.c has a missing check on the return value of pcap_dispatch, leading to a denial of service (malfunction).
0
Attacker Value
Unknown
CVE-2022-40278
Disclosure Date: September 29, 2022 (last updated October 08, 2023)
An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). createDB in security/provisioning/src/provisioningdatabasemanager.c has a missing sqlite3_free after sqlite3_exec, leading to a denial of service.
0
Attacker Value
Unknown
CVE-2022-40281
Disclosure Date: September 08, 2022 (last updated October 08, 2023)
An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). cyassl_connect_step2 in curl/vtls/cyassl.c has a missing X509_free after SSL_get_peer_certificate, leading to information disclosure.
0
Attacker Value
Unknown
CVE-2022-40280
Disclosure Date: September 08, 2022 (last updated October 08, 2023)
An issue was discovered in Samsung TizenRT through 3.0_GBM (and 3.1_PRE). createDB in security/provisioning/src/provisioningdatabasemanager.c has a missing sqlite3_close after sqlite3_open_v2, leading to a denial of service.
0
Attacker Value
Unknown
CVE-2021-22684
Disclosure Date: August 31, 2021 (last updated February 23, 2025)
Tizen RT RTOS version 3.0.GBB is vulnerable to integer wrap-around in functions_calloc and mm_zalloc. This improper memory assignment can lead to arbitrary memory allocation, resulting in unexpected behavior such as a crash
0
Attacker Value
Unknown
CVE-2021-25435
Disclosure Date: July 08, 2021 (last updated February 23, 2025)
Improper input validation vulnerability in Tizen bootloader prior to Firmware update JUL-2021 Release allows arbitrary code execution using recovery partition in wireless firmware download mode.
0
Attacker Value
Unknown
CVE-2021-25434
Disclosure Date: July 08, 2021 (last updated February 23, 2025)
Improper input validation vulnerability in Tizen bootloader prior to Firmware update JUL-2021 Release allows arbitrary code execution using param partition in wireless firmware download mode.
0