Show filters
27 Total Results
Displaying 1-10 of 27
Sort by:
Attacker Value
Unknown

CVE-2024-39684

Disclosure Date: July 09, 2024 (last updated July 10, 2024)
Tencent RapidJSON is vulnerable to privilege escalation due to an integer overflow in the `GenericReader::ParseNumber()` function of `include/rapidjson/reader.h` when parsing JSON text from a stream. An attacker needs to send the victim a crafted file which needs to be opened; this triggers the integer overflow vulnerability (when the file is parsed), leading to elevation of privilege.
0
Attacker Value
Unknown

CVE-2024-38517

Disclosure Date: July 09, 2024 (last updated July 10, 2024)
Tencent RapidJSON is vulnerable to privilege escalation due to an integer underflow in the `GenericReader::ParseNumber()` function of `include/rapidjson/reader.h` when parsing JSON text from a stream. An attacker needs to send the victim a crafted file which needs to be opened; this triggers the integer underflow vulnerability (when the file is parsed), leading to elevation of privilege.
0
Attacker Value
Unknown

CVE-2023-52286

Disclosure Date: December 31, 2023 (last updated January 06, 2024)
Tencent tdsqlpcloud through 1.8.5 allows unauthenticated remote attackers to discover database credentials via an index.php/api/install/get_db_info request, a related issue to CVE-2023-42387.
Attacker Value
Unknown

CVE-2023-40829

Disclosure Date: October 12, 2023 (last updated October 25, 2023)
There is an interface unauthorized access vulnerability in the background of Tencent Enterprise Wechat Privatization 2.5.x and 2.6.930000.
Attacker Value
Unknown

CVE-2023-39988

Disclosure Date: September 04, 2023 (last updated November 08, 2023)
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in 标准云(std.Cloud) WxSync plugin <= 2.7.23 versions.
Attacker Value
Unknown

CVE-2023-34312

Disclosure Date: June 01, 2023 (last updated October 08, 2023)
In Tencent QQ through 9.7.8.29039 and TIM through 3.4.7.22084, QQProtect.exe and QQProtectEngine.dll do not validate pointers from inter-process communication, which leads to a write-what-where condition.
Attacker Value
Unknown

CVE-2023-30363

Disclosure Date: April 26, 2023 (last updated October 08, 2023)
vConsole v3.15.0 was discovered to contain a prototype pollution due to incorrect key and value resolution in setOptions in core.ts.
Attacker Value
Unknown

CVE-2022-35158

Disclosure Date: August 03, 2022 (last updated October 08, 2023)
A vulnerability in the lua parser of TscanCode tsclua v2.15.01 allows attackers to cause a Denial of Service (DoS) via a crafted lua script.
Attacker Value
Unknown

CVE-2021-40180

Disclosure Date: July 26, 2022 (last updated October 07, 2023)
In the WeChat application 8.0.10 for Android and iOS, a mini program can obtain sensitive information from a user's address book via wx.searchContacts.
Attacker Value
Unknown

CVE-2021-33057

Disclosure Date: July 26, 2022 (last updated October 07, 2023)
The QQ application 8.7.1 for Android and iOS does not enforce the permission requirements (e.g., android.permission.ACCESS_FINE_LOCATION) for determining the device's physical location. An attacker can use qq.createMapContext to create a MapContext object, use MapContext.moveToLocation to move the center of the map to the device's location, and use MapContext.getCenterLocation to get the latitude and longitude of the current map center.