Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown
CVE-2023-29748
Disclosure Date: June 01, 2023 (last updated October 08, 2023)
Story Saver for Instragram - Video Downloader 1.0.6 for Android has an exposed component that provides a method to modify the SharedPreference file. An attacker can leverage this method to inject a large amount of data into any SharedPreference file, which will be loaded into memory when the application is opened. When an attacker injects too much data, the application will trigger an OOM error and crash at startup, resulting in a persistent denial of service.
0
Attacker Value
Unknown
CVE-2023-29747
Disclosure Date: May 31, 2023 (last updated October 08, 2023)
Story Saver for Instragram - Video Downloader 1.0.6 for Android exists exposed component, the component provides the method to modify the SharedPreference file. The attacker can use the method to modify the data in any SharedPreference file, these data will be loaded into the memory when the application is opened. Depending on how the data is used, this can result in various attack consequences, such as ad display exceptions.
0
Attacker Value
Unknown
CVE-2020-24142
Disclosure Date: July 07, 2021 (last updated February 23, 2025)
Server-side request forgery in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker send crafted requests from the back-end server of a vulnerable web application via the njt-tk-download-video parameter. It can help identify open ports, local network hosts and execute command on services
0
Attacker Value
Unknown
CVE-2020-24143
Disclosure Date: July 07, 2021 (last updated February 23, 2025)
Directory traversal in the Video Downloader for TikTok (aka downloader-tiktok) plugin 1.3 for WordPress lets an attacker get access to files that are stored outside the web root folder via the njt-tk-download-video parameter.
0
Attacker Value
Unknown
CVE-2019-18893
Disclosure Date: January 13, 2020 (last updated February 21, 2025)
XSS in the Video Downloader component before 1.5 of Avast Secure Browser 77.1.1831.91 and AVG Secure Browser 77.0.1790.77 allows websites to execute their code in the context of this component. While Video Downloader is technically a browser extension, it is granted a very wide set of privileges and can for example access cookies and browsing history, spy on the user while they are surfing the web, and alter their surfing experience in almost arbitrary ways.
0
Attacker Value
Unknown
CVE-2018-10000
Disclosure Date: April 11, 2018 (last updated November 26, 2024)
The Video Downloader professional extension before 2018-04-05 for Chrome has Universal XSS (UXSS) via vectors related to a link64_msgAddLinks event.
0
Attacker Value
Unknown
CVE-2017-15956
Disclosure Date: October 29, 2017 (last updated November 26, 2024)
ConverTo Video Downloader & Converter 1.4.1 allows Arbitrary File Download via the token parameter to download.php.
0
Attacker Value
Unknown
CVE-2014-6971
Disclosure Date: October 16, 2014 (last updated October 05, 2023)
The Easy Video Downloader (aka com.simon.padillar.EasyVideo) application 4.4.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
0