Show filters
89 Total Results
Displaying 11-20 of 89
Sort by:
Attacker Value
Unknown
CVE-2024-4762
Disclosure Date: December 16, 2024 (last updated December 18, 2024)
An improper validation vulnerability was reported in the firmware update mechanism of LADM and LDCC that could allow a local attacker to escalate privileges.
0
Attacker Value
Unknown
CVE-2024-4763
Disclosure Date: August 16, 2024 (last updated January 05, 2025)
An insecure driver vulnerability was reported in Lenovo Display Control Center (LDCC) and Lenovo Accessories and Display Manager (LADM)
that could allow a local attacker to escalate privileges to kernel.
0
Attacker Value
Unknown
CVE-2024-2175
Disclosure Date: August 16, 2024 (last updated January 05, 2025)
An insecure permissions vulnerability was reported in Lenovo Display Control Center (LDCC) and Lenovo Accessories and Display Manager (LADM)
that could allow a local attacker to escalate privileges.
0
Attacker Value
Unknown
CVE-2024-2224
Disclosure Date: April 09, 2024 (last updated February 08, 2025)
Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability in the UpdateServer component of Bitdefender GravityZone allows an attacker to execute arbitrary code on vulnerable instances. This issue affects the following products that include the vulnerable component:
Bitdefender Endpoint Security for Linux version 7.0.5.200089
Bitdefender Endpoint Security for Windows version 7.9.9.380
GravityZone Control Center (On Premises) version 6.36.1
0
Attacker Value
Unknown
CVE-2024-2223
Disclosure Date: April 09, 2024 (last updated February 08, 2025)
An Incorrect Regular Expression vulnerability in Bitdefender GravityZone Update Server allows an attacker to cause a Server Side Request Forgery and reconfigure the relay. This issue affects the following products that include the vulnerable component:
Bitdefender Endpoint Security for Linux version 7.0.5.200089
Bitdefender Endpoint Security for Windows version 7.9.9.380
GravityZone Control Center (On Premises) version 6.36.1
0
Attacker Value
Unknown
CVE-2023-35020
Disclosure Date: January 19, 2024 (last updated January 25, 2024)
IBM Sterling Control Center 6.3.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 257874.
0
Attacker Value
Unknown
CVE-2024-21589
Disclosure Date: January 12, 2024 (last updated January 20, 2024)
An Improper Access Control vulnerability in the Juniper Networks Paragon Active Assurance Control Center allows an unauthenticated network-based attacker to access reports without authenticating, potentially containing sensitive configuration information.
A feature was introduced in version 3.1.0 of the Paragon Active Assurance Control Center which allows users to selectively share account data. By exploiting this vulnerability, it is possible to access reports without being logged in, resulting in the opportunity for malicious exfiltration of user data.
Note that the Paragon Active Assurance Control Center SaaS offering is not affected by this issue.
This issue affects Juniper Networks Paragon Active Assurance versions 3.1.0, 3.2.0, 3.2.2, 3.3.0, 3.3.1, 3.4.0.
This issue does not affect Juniper Networks Paragon Active Assurance versions earlier than 3.1.0.
0
Attacker Value
Unknown
CVE-2023-39257
Disclosure Date: December 02, 2023 (last updated December 07, 2023)
Dell Rugged Control Center, version prior to 4.7, contains an Improper Access Control vulnerability. A local malicious standard user could potentially exploit this vulnerability to modify the content in an unsecured folder when product installation repair is performed, leading to privilege escalation on the system.
0
Attacker Value
Unknown
CVE-2023-39256
Disclosure Date: December 02, 2023 (last updated December 07, 2023)
Dell Rugged Control Center, version prior to 4.7, contains an improper access control vulnerability. A local malicious standard user could potentially exploit this vulnerability to modify the content in an unsecured folder during product installation and upgrade, leading to privilege escalation on the system.
0
Attacker Value
Unknown
CVE-2023-43089
Disclosure Date: December 01, 2023 (last updated December 07, 2023)
Dell Rugged Control Center, version prior to 4.7, contains insufficient protection for the Policy folder. A local malicious standard user could potentially exploit this vulnerability to modify the content of the policy file, leading to unauthorized access to resources.
0