Show filters
2,864 Total Results
Displaying 341-350 of 2,864
Sort by:
Attacker Value
Unknown
CVE-2024-5557
Disclosure Date: June 12, 2024 (last updated February 26, 2025)
CWE-532: Insertion of Sensitive Information into Log File vulnerability exists that could cause
exposure of SNMP credentials when an attacker has access to the controller logs.
0
Attacker Value
Unknown
CVE-2024-30075
Disclosure Date: June 11, 2024 (last updated February 26, 2025)
Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability
0
Attacker Value
Unknown
CVE-2024-30074
Disclosure Date: June 11, 2024 (last updated February 26, 2025)
Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability
0
Attacker Value
Unknown
CVE-2024-30063
Disclosure Date: June 11, 2024 (last updated February 26, 2025)
Windows Distributed File System (DFS) Remote Code Execution Vulnerability
0
Attacker Value
Unknown
CVE-2024-5269
Disclosure Date: June 06, 2024 (last updated February 26, 2025)
Sonos Era 100 SMB2 Message Handling Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos Era 100 smart speakers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the handling of SMB2 messages. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-22459.
0
Attacker Value
Unknown
CVE-2024-5268
Disclosure Date: June 06, 2024 (last updated February 26, 2025)
Sonos Era 100 SMB2 Message Handling Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sonos Era 100 smart speakers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the handling of SMB2 messages. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-22428.
0
Attacker Value
Unknown
CVE-2024-5267
Disclosure Date: June 06, 2024 (last updated February 26, 2025)
Sonos Era 100 SMB2 Message Handling Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Sonos Era 100 smart speakers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the handling of SMB2 messages. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-22384.
0
Attacker Value
Unknown
CVE-2024-5256
Disclosure Date: June 06, 2024 (last updated February 26, 2025)
Sonos Era 100 SMB2 Message Handling Integer Underflow Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of Sonos Era 100 smart speakers. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the handling of SMB2 messages. The issue results from the lack of proper validation of user-supplied data, which can result in an integer underflow before reading from memory. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of root. Was ZDI-CAN-22336.
0
Attacker Value
Unknown
CVE-2024-5684
Disclosure Date: June 06, 2024 (last updated February 26, 2025)
An attacker with access to the private network (the charger is connected to) or local access to the Ethernet-Interface can exploit a faulty implementation of the JWT-library in order to bypass the password authentication to the web configuration interface and then has full access as the user would have. However, an attacker will not have developer or admin rights. If the implementation of the JWT-library is wrongly configured to accept "none"-algorithms, the server will pass insecure JWT. A local, unauthenticated attacker can exploit this vulnerability to bypass the authentication mechanism.
0
Attacker Value
Unknown
CVE-2024-4008
Disclosure Date: June 05, 2024 (last updated February 26, 2025)
FDSK Leak in ABB, Busch-Jaeger, FTS Display (version 1.00) and BCU (version 1.3.0.33) allows attacker to take control via access to local KNX Bus-System
0