Show filters
347 Total Results
Displaying 51-60 of 347
Sort by:
Attacker Value
Unknown
CVE-2024-39229
Disclosure Date: August 06, 2024 (last updated February 26, 2025)
An issue in GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, XE3000/X3000 v4, and B2200/MV1000/MV1000W/USB150/N300/SF1200 v3.216 allows attackers to intercept communications via a man-in-the-middle attack when DDNS clients are reporting data to the server.
0
Attacker Value
Unknown
CVE-2024-41889
Disclosure Date: August 05, 2024 (last updated February 26, 2025)
Multiple Pimax products accept WebSocket connections from unintended endpoints. If this vulnerability is exploited, arbitrary code may be executed by a remote unauthenticated attacker.
0
Attacker Value
Unknown
CVE-2024-40832
Disclosure Date: July 29, 2024 (last updated February 26, 2025)
The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6. An app may be able to view a contact's phone number in system logs.
0
Attacker Value
Unknown
CVE-2024-40813
Disclosure Date: July 29, 2024 (last updated February 26, 2025)
A lock screen issue was addressed with improved state management. This issue is fixed in watchOS 10.6, iOS 17.6 and iPadOS 17.6. An attacker with physical access may be able to use Siri to access sensitive user data.
0
Attacker Value
Unknown
CVE-2020-11639
Disclosure Date: July 23, 2024 (last updated February 26, 2025)
An attacker could exploit the vulnerability by
injecting garbage data or specially crafted data. Depending on the data injected each process might be
affected differently. The process could crash or cause communication issues on the affected node, effectively causing a denial-of-service attack. The attacker could tamper with the data transmitted, causing
the product to store wrong information or act on wrong data or display wrong information.
This issue affects Advant MOD 300 AdvaBuild: from 3.0 through 3.7 SP2.
For an attack to be successful, the attacker must have local access to a node in the system and be able to
start a specially crafted application that disrupts the communication.
An attacker who successfully exploited the vulnerability would be able to manipulate the data in such
way as allowing reads and writes to the controllers or cause Windows processes in 800xA for MOD 300
and AdvaBuild to crash.
0
Attacker Value
Unknown
CVE-2024-6916
Disclosure Date: July 19, 2024 (last updated February 26, 2025)
A vulnerability in Zowe CLI allows local, privileged actors to display securely stored properties in cleartext within a terminal using the '--show-inputs-only' flag.
0
Attacker Value
Unknown
CVE-2024-29120
Disclosure Date: July 17, 2024 (last updated February 26, 2025)
In Streampark (version < 2.1.4), when a user logged in successfully, the Backend service would return "Authorization" as the front-end authentication credential. User can use this credential to request other users' information, including the administrator's username, password, salt value, etc.
Mitigation:
all users should upgrade to 2.1.4
0
Attacker Value
Unknown
CVE-2024-38496
Disclosure Date: July 15, 2024 (last updated February 26, 2025)
The vulnerability allows a malicious low-privileged PAM user to access information about other PAM users and their group memberships.
0
Attacker Value
Unknown
CVE-2024-39537
Disclosure Date: July 11, 2024 (last updated February 26, 2025)
An Improper Restriction of Communication Channel to Intended Endpoints vulnerability in Juniper Networks Junos OS Evolved on ACX 7000 Series allows an unauthenticated, network-based attacker to cause a limited information disclosure and availability impact to the device.
Due to a wrong initialization, specific processes which should only be able to communicate internally within the device can be reached over the network via open ports.
This issue affects Junos OS Evolved on ACX 7000 Series:
* All versions before 21.4R3-S7-EVO,
* 22.2-EVO
versions
before 22.2R3-S4-EVO,
* 22.3-EVO versions before 22.3R3-S3-EVO,
* 22.4-EVO versions before 22.4R3-S2-EVO,
* 23.2-EVO versions before 23.2R2-EVO,
* 23.4-EVO versions before 23.4R1-S1-EVO, 23.4R2-EVO.
0
Attacker Value
Unknown
CVE-2024-34721
Disclosure Date: July 09, 2024 (last updated February 26, 2025)
In ensureFileColumns of MediaProvider.java, there is a possible disclosure of files owned by another user due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.
0