All CVEs — page 40 of 42
The complete archive, 25 per page, newest first. 1030 records. Search instead.
The flaw allows an anonymous or low-privileged client to execute a denied method by batching it with an allowed one, bypassing authorization checks.
The flaw allows an unauthenticated remote client to exhaust monitored-item quotas by triggering a `StackOverflowError` during PubSub ExtensionObject decoding, leading to denial of service for monitored item creation.
The flaw allows an attacker to perform a padding oracle attack on RSA PKCS#1 v1.5 padding in `Basic128Rsa15`-encrypted username tokens, enabling password recovery and unauthorized access.
The flaw allows an anonymous client to bypass role-permission checks by exploiting a configuration issue in Eclipse Milo versions 1.0.0 through 1.1.4, leading to unauthorized access.
The flaw involves information disclosure in Firefox for Android and Firefox Focus for Android, potentially exposing sensitive user data.
The flaw allows external control of file names or paths in pardus-image-writer before version 0.9.0, potentially leading to removal of important client functionality.
The flaw is a stack-based buffer overflow in fbxsdk::ExtractDrive when processing maliciously crafted FBX files, allowing arbitrary code execution. This matters because it can lead to unauthorized access and system compromise.
This flaw involves a stack-based buffer overflow in the parsing of FBX files using Autodesk's FBX SDK, allowing arbitrary code execution.
The flaw allows attackers to bypass authentication by sending a crafted `Authorization` header with password characters replaced by '?', matching any non-ISO-8859-1 password of the same length.
The flaw involves an improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie, allowing for exponential data expansion and potential denial of service.
The flaw is a cleartext storage of sensitive information and SQL Injection vulnerability in HUMANIST Digital Human Resources versions before 26.1, allowing attackers to access sensitive data through unencrypted storage and execute malicious SQL commands.
The flaw is a session hijacking vulnerability due to sensitive query strings being exposed via GET requests. This matters because attackers can exploit it to take over user sessions.
The flaw involves a hard-coded cryptographic key in HUMANIST Digital Human Resources software, allowing sensitive constants to be read from an executable. This can lead to unauthorized access to critical information.
This flaw allows session IDs to be reused, enabling attackers to replay sessions and potentially gain unauthorized access.
The flaw is a path traversal vulnerability that allows attackers to access sensitive files by manipulating file paths. This matters because it can lead to unauthorized data exposure.
Allows attackers to upload a web shell by exploiting an unrestricted file upload vulnerability, leading to remote code execution.
This vulnerability allows an admin to upload and execute arbitrary files, leading to remote code execution.
This vulnerability allows a local attacker to execute arbitrary code by placing a crafted DLL in an unsafe directory, potentially leading to unauthorized access and control of the GV-ASManager process.
The flaw involves an embedded RSA private key in the Lighttpd firmware, allowing attackers to decrypt HTTPS traffic and spoof the server.