NA - CVE-2024-7318 - A vulnerability was found in Keycloak. Expired...
A vulnerability was found in Keycloak. Expired OTP codes are still usable when using FreeOTP when the OTP token period is set to 30 seconds (default). Instead of expiring and deemed unusable around...
NA - CVE-2024-7341 - A session fixation issue was discovered in the...
A session fixation issue was discovered in the SAML adapters provided by Keycloak. The session ID and JSESSIONID cookie are not changed at login time, even when the turnOffChangeSessionIdOnLogin...
NA - CVE-2023-50883 - ONLYOFFICE Docs before 8.0.1 allows XSS because...
ONLYOFFICE Docs before 8.0.1 allows XSS because a macro is an immediately-invoked function expression (IIFE), and therefore a sandbox escape is possible by directly calling the constructor of the...
NA - CVE-2024-27364 - An issue was discovered in Mobile Processor,...
An issue was discovered in Mobile Processor, Wearable Processor Exynos 980, Exynos 850, Exynos 1080, Exynos 1280, Exynos 1380, Exynos 1330, Exynos 1480, Exynos W920, Exynos W930. In the function...
NA - CVE-2024-27383 - An issue was discovered in Samsung Mobile...
An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_get_scan_extra_ies(), there is no input validation check...
NA - CVE-2024-27387 - An issue was discovered in Samsung Mobile...
An issue was discovered in Samsung Mobile Processor Exynos 980, Exynos 850, Exynos 1280, Exynos 1380, and Exynos 1330. In the function slsi_rx_range_done_ind(), there is no input validation check...