MetaMask before 10.11.3 might allow an attacker to access a user's secret recovery phrase because an input field is used for a BIP39 mnemonic, and Firefox and Chromium save such fields to disk in orde ...
Continue ReadingJune 29, 2022
ApiFest OAuth 2.0 Server 0.3.1 does not validate the redirect URI in accordance with RFC 6749 and is susceptible to an open redirector attack. Specifically, it directly sends an authorization code to ...
Continue ReadingJune 29, 2022
XLPD v7.0.0094 and below contains an unquoted service path vulnerability which allows local users to launch processes with elevated privileges.Read More ...
Continue ReadingJune 29, 2022
A binary hijack in Embarcadero Dev-CPP v6.3 allows attackers to execute arbitrary code via a crafted .exe file.Read More ...
Continue ReadingJune 29, 2022
Incorrect permissions for the folder C:ProgramDataNoMachinevaruninstall of Nomachine v7.9.2 allows attackers to perform a DLL hijacking attack and execute arbitrary code.Read More ...
Continue ReadingJune 29, 2022
A binary hijack in Orwell-Dev-Cpp v5.11 allows attackers to execute arbitrary code via a crafted .exe file.Read More ...
Continue ReadingJune 29, 2022
ThinkPHP v6.0.12 was discovered to contain a deserialization vulnerability via the component vendorleagueflysystem-cached-adaptersrcStorageAbstractCache.php. This vulnerability allows attackers to exe ...
Continue ReadingJune 29, 2022
CVA6 commit 909d85a gives incorrect permission to use special multiplication units when the format of instructions is wrong.Read More ...
Continue ReadingJune 29, 2022
Back to Main