Show filters
96 Total Results
Displaying 1-10 of 96
Sort by:
Attacker Value
Unknown

CVE-2020-27950

Disclosure Date: December 08, 2020 (last updated February 22, 2025)
A memory initialization issue was addressed. This issue is fixed in macOS Big Sur 11.0.1, watchOS 7.1, iOS 12.4.9, watchOS 6.2.9, Security Update 2020-006 High Sierra, Security Update 2020-006 Mojave, iOS 14.2 and iPadOS 14.2, watchOS 5.3.9, macOS Catalina 10.15.7 Supplemental Update, macOS Catalina 10.15.7 Update. A malicious application may be able to disclose kernel memory.
Attacker Value
High

CVE-2019-7244

Disclosure Date: March 25, 2020 (last updated February 21, 2025)
An issue was discovered in kerneld.sys in AIDA64 before 5.99. The vulnerable driver exposes a wrmsr instruction via IOCTL 0x80112084 and does not properly filter the Model Specific Register (MSR). Allowing arbitrary MSR writes can lead to Ring-0 code execution and escalation of privileges.
Attacker Value
Unknown

CVE-2024-39864

Disclosure Date: July 05, 2024 (last updated February 23, 2025)
The CloudStack integration API service allows running its unauthenticated API server (usually on port 8096 when configured and enabled via integration.api.port global setting) for internal portal integrations and for testing purposes. By default, the integration API service port is disabled and is considered disabled when integration.api.port is set to 0 or negative. Due to an improper initialisation logic, the integration API service would listen on a random port when its port value is set to 0 (default value). An attacker that can access the CloudStack management network could scan and find the randomised integration API service port and exploit it to perform unauthorised administrative actions and perform remote code execution on CloudStack managed hosts and result in complete compromise of the confidentiality, integrity, and availability of CloudStack managed infrastructure. Users are recommended to restrict the network access on the CloudStack management server hosts to only ess…
Attacker Value
Unknown

CVE-2021-39636

Disclosure Date: December 15, 2021 (last updated February 23, 2025)
In do_ipt_get_ctl and do_ipt_set_ctl of ip_tables.c, there is a possible way to leak kernel information due to uninitialized data. This could lead to local information disclosure with system execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-120612905References: Upstream kernel
Attacker Value
Unknown

CVE-2021-0120

Disclosure Date: November 17, 2021 (last updated February 23, 2025)
Improper initialization in the installer for some Intel(R) Graphics DCH Drivers for Windows 10 before version 27.20.100.9316 may allow an authenticated user to potentially enable denial of service via local access.
Attacker Value
Unknown

CVE-2021-0053

Disclosure Date: November 17, 2021 (last updated February 23, 2025)
Improper initialization in firmware for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi in Windows 10 may allow an authenticated user to potentially enable information disclosure via adjacent access.
Attacker Value
Unknown

CVE-2021-41264

Disclosure Date: November 12, 2021 (last updated February 23, 2025)
OpenZeppelin Contracts is a library for smart contract development. In affected versions upgradeable contracts using `UUPSUpgradeable` may be vulnerable to an attack affecting uninitialized implementation contracts. A fix is included in version 4.3.2 of `@openzeppelin/contracts` and `@openzeppelin/contracts-upgradeable`. For users unable to upgrade; initialize implementation contracts using `UUPSUpgradeable` by invoking the initializer function (usually called `initialize`). An example is provided [in the forum](https://forum.openzeppelin.com/t/security-advisory-initialize-uups-implementation-contracts/15301).
0
Attacker Value
Unknown

CVE-2021-26326

Disclosure Date: November 09, 2021 (last updated February 23, 2025)
Failure to validate VM_HSAVE_PA during SNP_INIT may result in a loss of memory integrity.
Attacker Value
Unknown

CVE-2021-26312

Disclosure Date: November 09, 2021 (last updated February 23, 2025)
Failure to flush the Translation Lookaside Buffer (TLB) of the I/O memory management unit (IOMMU) may lead an IO device to write to memory it should not be able to access, resulting in a potential loss of integrity.
Attacker Value
Unknown

CVE-2021-36319

Disclosure Date: November 01, 2021 (last updated February 23, 2025)
Dell Networking OS10 versions 10.4.3.x, 10.5.0.x and 10.5.1.x contain an information exposure vulnerability. A low privileged authenticated malicious user can gain access to SNMP authentication failure messages.