Categoria: CVE

CVE-2017-13314 | Google Android 7/8/8.1 NetworkManagementService.java setAllowOnlyVpnForUids permission

A vulnerability, which was classified as critical, was found in Google Android 7/8/8.1. Affected is the function setAllowOnlyVpnForUids of the file NetworkManagementService.java. The manipulation leads to permission issues. This vulnerability is traded as CVE-2017-13314. The attack needs to be approached locally. There is no exploit available. It is recommended to apply a patch to fix this...

Per saperne di più

CVE-2024-10883 | SimpleForm Plugin up to 2.2.0 on WordPress add_query_arg/remove_query_arg cross site scripting

A vulnerability, which was classified as problematic, has been found in SimpleForm Plugin up to 2.2.0 on WordPress. This issue affects the function add_query_arg/remove_query_arg. The manipulation leads to cross site scripting. The identification of this vulnerability is CVE-2024-10883. The attack may be initiated remotely. There is no exploit...

Per saperne di più

CVE-2024-11263 | zephyrproject-rtos Zephyr up to 3.7 Global Pointer privilege context switching error (GHSA-jjf3-7×72-pqm9)

A vulnerability classified as critical was found in zephyrproject-rtos Zephyr up to 3.7. This vulnerability affects unknown code of the component Global Pointer. The manipulation leads to privilege context switching error. This vulnerability was named CVE-2024-11263. Attacking locally is a requirement. There is no exploit...

Per saperne di più

CVE-2017-13313 | Google Android 6/6.0.1/7/8/8.1 ESQueue.cpp dequeueAccessUnitMPEG4Video resource consumption

A vulnerability classified as problematic has been found in Google Android 6/6.0.1/7/8/8.1. This affects the function ElementaryStreamQueue::dequeueAccessUnitMPEG4Video of the file ESQueue.cpp. The manipulation leads to resource consumption. This vulnerability is uniquely identified as CVE-2017-13313. It is possible to initiate the attack remotely. There is no exploit available. It is recommended to apply a patch to fix this...

Per saperne di più

CVE-2024-10614 | ivole Customer Reviews for WooCommerce Plugin up to 5.61.0 on WordPress cancel_import authorization

A vulnerability was found in ivole Customer Reviews for WooCommerce Plugin up to 5.61.0 on WordPress. It has been rated as problematic. Affected by this issue is the function cancel_import. The manipulation leads to missing authorization. This vulnerability is handled as CVE-2024-10614. The attack may be launched remotely. There is no exploit...

Per saperne di più

CVE-2024-10728 | wpxpo Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX Plugin Installation install_required_plugin_callback authorization

A vulnerability was found in wpxpo Post Grid Gutenberg Blocks and WordPress Blog Plugin – PostX up to 4.1.16 on WordPress. It has been declared as critical. Affected by this vulnerability is the function install_required_plugin_callback of the component Plugin Installation Handler. The manipulation leads to missing authorization. This vulnerability is known as CVE-2024-10728. The attack can be launched remotely. There is no exploit...

Per saperne di più

CVE-2024-8856 | revmakx Backup and Staging by WP Time Capsule Plugin up to 1.22.21 on WordPress UploadHandler.php unrestricted upload

A vulnerability was found in revmakx Backup and Staging by WP Time Capsule Plugin up to 1.22.21 on WordPress. It has been classified as critical. Affected is an unknown function of the file UploadHandler.php. The manipulation leads to unrestricted upload. This vulnerability is traded as CVE-2024-8856. It is possible to launch the attack remotely. There is no exploit...

Per saperne di più
Caricamento