Vulnerabilities (CVE)

Filtered by CWE-99
Total 43 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-8615 1 Haxx 1 Curl 2024-11-21 5.0 MEDIUM 5.3 MEDIUM
A flaw was found in curl before version 7.51. If cookie state is written into a cookie jar file that is later read back and used for subsequent requests, a malicious HTTP server can inject new cookies for arbitrary domains into said cookie jar.
CVE-2024-7438 1 Simplemachines 1 Simple Machines Forum 2024-09-11 4.0 MEDIUM 4.3 MEDIUM
A vulnerability has been found in SimpleMachines SMF 2.1.4 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /index.php?action=profile;u=2;area=showalerts;do=read of the component User Alert Read Status Handler. The manipulation of the argument aid leads to improper control of resource identifiers. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
CVE-2024-7437 1 Simplemachines 1 Simple Machines Forum 2024-09-11 5.5 MEDIUM 5.4 MEDIUM
A vulnerability, which was classified as critical, was found in SimpleMachines SMF 2.1.4. Affected is an unknown function of the file /index.php?action=profile;u=2;area=showalerts;do=remove of the component Delete User Handler. The manipulation of the argument aid leads to improper control of resource identifiers. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.