Show filters
1,566 topics marked with the following tags:
Displaying 1-10 of 1,566
Sort by:
Attacker Value
Unknown

CVE-2019-12725

Disclosure Date: July 19, 2019 (last updated October 06, 2023)
Zeroshell 3.9.0 is prone to a remote command execution vulnerability. Specifically, this issue occurs because the web application mishandles a few HTTP parameters. An unauthenticated attacker can exploit this issue by injecting OS commands inside the vulnerable parameters.
Attacker Value
Unknown

CVE-2009-1151

Disclosure Date: March 26, 2009 (last updated October 04, 2023)
Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitrary PHP code into a configuration file via the save action.
1
Attacker Value
Unknown

CVE-2020-3837

Disclosure Date: February 27, 2020 (last updated October 06, 2023)
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3.1 and iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1, watchOS 6.1.2. An application may be able to execute arbitrary code with kernel privileges.
Attacker Value
Unknown

CVE-2022-22706

Disclosure Date: March 03, 2022 (last updated October 07, 2023)
Arm Mali GPU Kernel Driver allows a non-privileged user to achieve write access to read-only memory pages. This affects Midgard r26p0 through r31p0, Bifrost r0p0 through r35p0, and Valhall r19p0 through r35p0.
Attacker Value
Unknown

CVE-2016-7855

Disclosure Date: November 01, 2016 (last updated October 05, 2023)
Use-after-free vulnerability in Adobe Flash Player before 23.0.0.205 on Windows and OS X and before 11.2.202.643 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in October 2016.
Attacker Value
Unknown

CVE-2019-9670

Disclosure Date: May 29, 2019 (last updated October 06, 2023)
mailboxd component in Synacor Zimbra Collaboration Suite 8.7.x before 8.7.11p10 has an XML External Entity injection (XXE) vulnerability, as demonstrated by Autodiscover/Autodiscover.xml.
Attacker Value
Unknown

CVE-2022-26485

Disclosure Date: December 22, 2022 (last updated October 08, 2023)
Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw. This vulnerability affects Firefox < 97.0.2, Firefox ESR < 91.6.1, Firefox for Android < 97.3.0, Thunderbird < 91.6.2, and Focus < 97.3.0.
Attacker Value
Unknown

CVE-2023-20867

Disclosure Date: June 13, 2023 (last updated October 08, 2023)
A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine.
Attacker Value
Unknown

CVE-2021-39226

Disclosure Date: October 05, 2021 (last updated November 08, 2023)
Grafana is an open source data visualization platform. In affected versions unauthenticated and authenticated users are able to view the snapshot with the lowest database key by accessing the literal paths: /dashboard/snapshot/:key, or /api/snapshots/:key. If the snapshot "public_mode" configuration setting is set to true (vs default of false), unauthenticated users are able to delete the snapshot with the lowest database key by accessing the literal path: /api/snapshots-delete/:deleteKey. Regardless of the snapshot "public_mode" setting, authenticated users are able to delete the snapshot with the lowest database key by accessing the literal paths: /api/snapshots/:key, or /api/snapshots-delete/:deleteKey. The combination of deletion and viewing enables a complete walk through all snapshot data while resulting in complete snapshot data loss. This issue has been resolved in versions 8.1.6 and 7.5.11. If for some reason you cannot upgrade you can use a reverse proxy or similar to block …
Attacker Value
Unknown

CVE-2022-4135

Disclosure Date: November 25, 2022 (last updated October 08, 2023)
Heap buffer overflow in GPU in Google Chrome prior to 107.0.5304.121 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)