Show filters
1,625 Total Results
Displaying 591-600 of 1,625
Sort by:
Attacker Value
Unknown

CVE-2022-20034

Disclosure Date: February 09, 2022 (last updated October 07, 2023)
In Preloader XFLASH, there is a possible escalation of privilege due to an improper certificate validation. This could lead to local escalation of privilege for an attacker who has physical access to the device with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS06160806; Issue ID: ALPS06160806.
Attacker Value
Unknown

CVE-2021-33107

Disclosure Date: February 09, 2022 (last updated October 07, 2023)
Insufficiently protected credentials in USB provisioning for Intel(R) AMT SDK before version 16.0.3, Intel(R) SCS before version 12.2 and Intel(R) MEBx before versions 11.0.0.0012, 12.0.0.0011, 14.0.0.0004 and 15.0.0.0004 may allow an unauthenticated user to potentially enable information disclosure via physical access.
Attacker Value
Unknown

CVE-2021-0125

Disclosure Date: February 09, 2022 (last updated October 07, 2023)
Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via physical access.
Attacker Value
Unknown

CVE-2021-0124

Disclosure Date: February 09, 2022 (last updated October 07, 2023)
Improper access control in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via physical access.
Attacker Value
Unknown

CVE-2021-0119

Disclosure Date: February 09, 2022 (last updated October 07, 2023)
Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via physical access.
Attacker Value
Unknown

CVE-2021-0060

Disclosure Date: February 09, 2022 (last updated October 07, 2023)
Insufficient compartmentalization in HECI subsystem for the Intel(R) SPS before versions SPS_E5_04.01.04.516.0, SPS_E5_04.04.04.033.0, SPS_E5_04.04.03.281.0, SPS_E5_03.01.03.116.0, SPS_E3_05.01.04.309.0, SPS_02.04.00.101.0, SPS_SoC-A_05.00.03.114.0, SPS_SoC-X_04.00.04.326.0, SPS_SoC-X_03.00.03.117.0, IGN_E5_91.00.00.167.0, SPS_PHI_03.01.03.078.0 may allow an authenticated user to potentially enable escalation of privilege via physical access.
Attacker Value
Unknown

CVE-2022-23255

Disclosure Date: February 09, 2022 (last updated November 29, 2024)
Microsoft OneDrive for Android Security Feature Bypass Vulnerability
0
Attacker Value
Unknown

CVE-2022-22566

Disclosure Date: February 07, 2022 (last updated October 07, 2023)
Select Dell Client Commercial and Consumer platforms contain a pre-boot direct memory access (DMA) vulnerability. An authenticated attacker with physical access to the system may potentially exploit this vulnerability in order to execute arbitrary code on the device.
Attacker Value
Unknown

CVE-2022-23035

Disclosure Date: January 25, 2022 (last updated October 07, 2023)
Insufficient cleanup of passed-through device IRQs The management of IRQs associated with physical devices exposed to x86 HVM guests involves an iterative operation in particular when cleaning up after the guest's use of the device. In the case where an interrupt is not quiescent yet at the time this cleanup gets invoked, the cleanup attempt may be scheduled to be retried. When multiple interrupts are involved, this scheduling of a retry may get erroneously skipped. At the same time pointers may get cleared (resulting in a de-reference of NULL) and freed (resulting in a use-after-free), while other code would continue to assume them to be valid.
Attacker Value
Unknown

CVE-2022-23728

Disclosure Date: January 21, 2022 (last updated October 07, 2023)
Attacker can reset the device with AT Command in the process of rebooting the device. The LG ID is LVE-SMP-210011.