Inappropriate implementation in SiteIsolation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
Inappropriate implementation in SiteIsolation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
Insufficient validation of untrusted input in Network in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
H5Z__filter_fletcher32 in H5Zfletcher32.c in HDF5 through 2.3.0 computes the data length to checksum by subtracting the 4-byte trailing checksum size from the input buffer size without checking that the buffer is at least 4 bytes, allowing a size_t underflow. This allows attackers to cause a denial of service (massively out-of-bounds read and application crash in H5_checksum_fletcher32) via a crafted HDF5 file with a Fletcher32-filtered chunk smaller than 4 bytes, triggered via H5Dread, e.g. by
The H5Z__nbit_decompress_one_byte, H5Z__nbit_decompress_one_nooptype, and H5Z__nbit_decompress_one_atomic functions in H5Znbit.c in HDF5 through 2.3.0 advance a read index into the compressed chunk buffer without bounding it against the buffer's actual size. This allows attackers to cause an out-of-bounds heap read, and in constrained cases disclosure of adjacent heap memory into decompressed dataset values, via a crafted HDF5 file whose N-Bit filter parameters describe more decompressed data th
A flaw has been found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. The affected element is an unknown function of the file /dm/dispatch/user/findAll. Executing a manipulation of the argument Name can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
A security vulnerability has been detected in ttttonyhe OBlog up to 3ca6a45a2fcc81f6086751d8af124658720e8f8f. This issue affects some unknown processing of the file /tags.php. Such manipulation of the argument day leads to cross site scripting. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. T
Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
Rejected reason: Erroneously reserved under wrong year by automation defect; never assigned.
Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.
Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.
Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.
Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.
Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.
Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.
Rejected reason: Erroneously reserved under wrong year by automation defect; superseded by correct-year CVE.