CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
OpenSSL 1.1.1 introduced a rewritten random number generator (RNG). This was intended to include protection in the event of a fork() system call in order to ensure that the parent and child processes did not share the same RNG state. However this protection was not being used in the default case. A partial mitigation for this issue is that the output from a high precision timer is mixed into the RNG state so the likelihood of a parent and child process sharing state is significantly reduced. If an application already calls OPENSSL_init_crypto() explicitly using OPENSSL_INIT_ATFORK then this problem does not occur at all. Fixed in OpenSSL 1.1.1d (Affected 1.1.1-1.1.1c).
laracom (aka Laravel FREE E-Commerce Software) 1.4.11 has search?q= XSS.
Ignite Realtime Openfire before 4.4.1 has reflected XSS via an LDAP setup test.
DfE School Experience before v16333-GA has XSS via a teacher training URL.
django-js-reverse (aka Django JS Reverse) before 0.9.1 has XSS via js_reverse_inline.
Bolt before 3.6.10 has XSS via createFolder or createFile in Controller/Async/FilesystemManager.php.
Bolt before 3.6.10 has XSS via an image's alt or title field.
Bolt before 3.6.10 has XSS via a title that is mishandled in the system log.
selectize-plugin-a11y before 1.1.0 has XSS via the msg field.
Kimai v2 before 1.1 has XSS via a timesheet description.
