Show filters
3,391 Total Results
Displaying 191-200 of 3,391
Sort by:
Attacker Value
Unknown

CVE-2024-7448

Disclosure Date: August 21, 2024 (last updated August 24, 2024)
Magnet Forensics AXIOM Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Magnet Forensics AXIOM. User interaction is required to exploit this vulnerability in that the target must acquire data from a malicious mobile device. The specific flaw exists within the Android device image acquisition functionality. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the current user. Was ZDI-CAN-23964.
Attacker Value
Unknown

CVE-2024-7795

Disclosure Date: August 21, 2024 (last updated August 24, 2024)
Autel MaxiCharger AC Elite Business C50 AppAuthenExchangeRandomNum Stack-Based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Autel MaxiCharger AC Elite Business C50 EV chargers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the AppAuthenExchangeRandomNum BLE command. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the device. Was ZDI-CAN-23384.
Attacker Value
Unknown

CVE-2024-5880

Disclosure Date: August 21, 2024 (last updated August 21, 2024)
The Hide My Site plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2 due to the plugin not restricting access to the REST API when password protection is enabled. This makes it possible for unauthenticated attackers to gain unauthorized access to the site.
Attacker Value
Unknown

CVE-2024-6004

Disclosure Date: August 16, 2024 (last updated August 17, 2024)
A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to deny printer connections until the system is rebooted.
Attacker Value
Unknown

CVE-2024-5210

Disclosure Date: August 16, 2024 (last updated August 17, 2024)
A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to prevent printer services from being reachable until the system is rebooted.
Attacker Value
Unknown

CVE-2024-5209

Disclosure Date: August 16, 2024 (last updated August 17, 2024)
A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to deny printing capabilities until the system is rebooted.
Attacker Value
Unknown

CVE-2024-4782

Disclosure Date: August 16, 2024 (last updated August 17, 2024)
A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to disrupt the printer's functionality until a manual system reboot occurs.
Attacker Value
Unknown

CVE-2024-4781

Disclosure Date: August 16, 2024 (last updated August 17, 2024)
A denial-of-service vulnerability was reported in some Lenovo printers that could allow an unauthenticated attacker on a shared network to crash printer communications until the system is rebooted.
Attacker Value
Unknown

CVE-2024-6347

Disclosure Date: August 15, 2024 (last updated August 17, 2024)
* Unprotected privileged mode access through UDS session in the Blind Spot Detection Sensor ECU firmware in Nissan Altima (2022) allows attackers to trigger denial-of-service (DoS) by unauthorized access to the ECU's programming session. * No preconditions implemented for ECU management functionality through UDS session in the Blind Spot Detection Sensor ECU in Nissan Altima (2022) allows attackers to disrupt normal ECU operations by triggering a control command without authentication.
Attacker Value
Unknown

CVE-2024-3913

Disclosure Date: August 13, 2024 (last updated September 14, 2024)
An unauthenticated remote attacker can use this vulnerability to change the device configuration due to a file writeable for short time after system startup.