| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| An issue was discovered on Samsung mobile devices with P(9.0) (Exynos chipsets) software. The Wi-Fi kernel drivers have an out-of-bounds Read. The Samsung IDs are SVE-2019-15692, SVE-2019-15693 (December 2019). |
| An issue was discovered on Samsung mobile devices with N(7.1), O(8.x), P(9.0), and Q(10.0) software. Arbitrary code execution is possible on the lock screen. The Samsung ID is SVE-2019-15266 (December 2019). |
| In core/doctype/prepared_report/prepared_report.py in Frappe 11 and 12, data files generated with Prepared Report were being stored as public files (no authentication is required to access; having a link is sufficient) instead of private files. |
| Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp username parameter. |
| Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp serverURL parameter. |
| Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp password parameter. |
| Ignite Realtime Openfire 4.4.1 allows XSS via the setup/setup-datasource-standard.jsp driver parameter. |
| ilchCMS 2.1.23 allows XSS via the index.php/partner/index Banner parameter. |
| ilchCMS 2.1.23 allows XSS via the index.php/partner/index Name parameter. |
| ilchCMS 2.1.23 allows XSS via the index.php/partner/index Link parameter. |
| ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/ URI. |
| ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the api/method/ URI. |
| ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the user/ URI, as demonstrated by a crafted e-mail address. |
| ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the project/ URI. |
| ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the contact/ URI. |
| ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the blog/ URI. |
| ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the addresses/ URI. |
| ERPNext 11.1.47 allows reflected XSS via the PATH_INFO to the address/ URI. |
| Open edX Ironwood.1 allows support/certificates?user= reflected XSS. |
| Open edX Ironwood.1 allows support/certificates?course_id= reflected XSS. |