Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown
CVE-2023-48238
Disclosure Date: November 17, 2023 (last updated November 30, 2023)
joaquimserafim/json-web-token is a javascript library use to interact with JSON Web Tokens (JWT) which are a compact URL-safe means of representing claims to be transferred between two parties. Affected versions of the json-web-token library are vulnerable to a JWT algorithm confusion attack. On line 86 of the 'index.js' file, the algorithm to use for verifying the signature of the JWT token is taken from the JWT token, which at that point is still unverified and thus shouldn't be trusted. To exploit this vulnerability, an attacker needs to craft a malicious JWT token containing the HS256 algorithm, signed with the public RSA key of the victim application. This attack will only work against this library is the RS256 algorithm is in use, however it is a best practice to use that algorithm.
0
Attacker Value
Unknown
CVE-2023-34965
Disclosure Date: June 13, 2023 (last updated October 08, 2023)
SSPanel-Uim 2023.3 does not restrict access to the /link/ interface which can lead to a leak of user information.
0
Attacker Value
Unknown
CVE-2023-27455
Disclosure Date: May 10, 2023 (last updated October 08, 2023)
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Maui Marketing Update Image Tag Alt Attribute plugin <= 2.4.5 versions.
0
Attacker Value
Unknown
CVE-2012-1640
Disclosure Date: September 19, 2012 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the Managesite module 6.x-1.x before 6.1-1.1 for Drupal allow remote authenticated users with "administer managesite" permissions to inject arbitrary web script or HTML via the title parameter when (1) adding or (2) updating a category.
0
Attacker Value
Unknown
CVE-2007-5101
Disclosure Date: September 26, 2007 (last updated October 04, 2023)
ChironFS before 1.0 RC7 sets user/group ownership to the mounter account instead of the creator account when files are created, which allows local users to gain privileges.
0
Attacker Value
Unknown
CVE-2005-3149
Disclosure Date: October 05, 2005 (last updated February 22, 2025)
Uim 0.4.x before 0.4.9.1 and 0.5.0 and earlier does not properly handle the LIBUIM_VANILLA environment variable when a suid or sgid application is linked to libuim, such as immodule for Qt, which allows local users to gain privileges.
0
Attacker Value
Unknown
CVE-2005-0503
Disclosure Date: February 21, 2005 (last updated February 22, 2025)
uim before 0.4.5.1 trusts certain environment variables when libUIM is used in setuid or setgid applications, which allows local users to gain privileges.
0