7 results (0.002 seconds)

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 2

The Simplenia Pages plugin 2.6.0 for Atlassian Bitbucket Server has XSS. El plugin Simplenia Pages 2.6.0 para Atlassian Bitbucket Server tiene Cross-Site Scripting (XSS). Pages for Bitbucket Server versions 2.6.0 and below suffer from multiple cross site scripting vulnerabilities. • http://packetstormsecurity.com/files/151466/Pages-For-Bitbucket-Server-2.6.0-Cross-Site-Scripting.html https://marketplace.atlassian.com/apps/1212525/pages-for-bitbucket-server/version-history https://seclists.org/bugtraq/2019/Jan/53 https://www.syss.de/fileadmin/dokumente/Publikationen/Advisories/SYSS-2018-037.txt • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 5.3EPSS: 0%CPEs: 6EXPL: 0

An issue was discovered in certain Apple products. Pages before 6.1, Numbers before 4.1, and Keynote before 7.1 on macOS and Pages before 3.1, Numbers before 3.1, and Keynote before 3.1 on iOS are affected. The issue involves the "Export" component. It allows users to bypass iWork PDF password protection by leveraging use of 40-bit RC4. Se ha descubierto un problema en ciertos productos Apple. • http://www.securityfocus.com/bid/97126 http://www.securitytracker.com/id/1038134 http://www.securitytracker.com/id/1038135 http://www.securitytracker.com/id/1038136 https://support.apple.com/HT207595 • CWE-326: Inadequate Encryption Strength •

CVSS: 4.3EPSS: 0%CPEs: 4EXPL: 0

The Apple iWork application before 2.6 for iOS, Apple Keynote before 6.6, Apple Pages before 5.6, and Apple Numbers before 3.6 allow remote attackers to obtain sensitive information via a crafted document. La aplicación Apple iWork en versiones anteriores a 2.6 para iOS, Apple Keynote en versiones anteriores a 6.6, Apple Pages en versiones anteriores a 5.6 y Apple Numbers en versiones anteriores a 3.6 permite a atacantes remotos obtener información sensible a través de un documento manipulado. • http://lists.apple.com/archives/security-announce/2015/Oct/msg00000.html http://www.securitytracker.com/id/1033823 http://www.securitytracker.com/id/1033825 http://www.securitytracker.com/id/1033826 https://support.apple.com/HT205373 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVSS: 6.8EPSS: 3%CPEs: 4EXPL: 0

The Apple iWork application before 2.6 for iOS, Apple Keynote before 6.6, Apple Pages before 5.6, and Apple Numbers before 3.6 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted document. La aplicación Apple iWork en versiones anteriores a 2.6 para iOS, Apple Keynote en versiones anteriores a 6.6, Apple Pages en versiones anteriores a 5.6 y Apple Numbers en versiones anteriores a 3.6 permite a atacantes remotos ejecutar código arbitrario o causar una denegación de servicio (corrupción de memoria y caída de la aplicación) a través de un documento manipulado. • http://lists.apple.com/archives/security-announce/2015/Oct/msg00000.html http://www.securitytracker.com/id/1033823 http://www.securitytracker.com/id/1033825 http://www.securitytracker.com/id/1033826 https://support.apple.com/HT205373 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •

CVSS: 6.8EPSS: 1%CPEs: 2EXPL: 0

The Apple iWork application before 2.6 for iOS and Apple Pages before 5.6 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Pages document. La aplicación Apple iWork en versiones anteriores a 2.6 para iOS y Apple Pages en versiones anteriores a 5.6 permite a atacantes remotos ejecutar código arbitrario o causar una denegación de servicio (corrupción de memoria y caída de la aplicación) a través de un documento Pages manipulado. • http://lists.apple.com/archives/security-announce/2015/Oct/msg00000.html http://www.securitytracker.com/id/1033821 https://support.apple.com/HT205373 • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •