Show filters
133 Total Results
Displaying 11-20 of 133
Sort by:
Attacker Value
Unknown

CVE-2023-27356

Disclosure Date: May 03, 2024 (last updated January 06, 2025)
NETGEAR RAX30 logCtrl Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of NETGEAR RAX30 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the logCtrl action. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-19825.
Attacker Value
Unknown

CVE-2023-45079

Disclosure Date: November 08, 2023 (last updated November 17, 2023)
A memory leakage vulnerability was reported in the NvmramSmm SMM driver that may allow a local attacker with elevated privileges to write to NVRAM variables.
Attacker Value
Unknown

CVE-2023-45078

Disclosure Date: November 08, 2023 (last updated November 17, 2023)
A memory leakage vulnerability was reported in the DustFilterAlertSmm SMM driver that may allow a local attacker with elevated privileges to write to NVRAM variables.
Attacker Value
Unknown

CVE-2023-45077

Disclosure Date: November 08, 2023 (last updated November 17, 2023)
A memory leakage vulnerability was reported in the 534D0740 DXE driver that may allow a local attacker with elevated privileges to write to NVRAM variables.
Attacker Value
Unknown

CVE-2023-45076

Disclosure Date: November 08, 2023 (last updated November 17, 2023)
A memory leakage vulnerability was reported in the 534D0140 DXE driver that may allow a local attacker with elevated privileges to write to NVRAM variables.
Attacker Value
Unknown

CVE-2023-45075

Disclosure Date: November 08, 2023 (last updated November 17, 2023)
A memory leakage vulnerability was reported in the SWSMI_Shadow DXE driver that may allow a local attacker with elevated privileges to write to NVRAM variables.
Attacker Value
Unknown

CVE-2023-43581

Disclosure Date: November 08, 2023 (last updated November 16, 2023)
A buffer overflow was reported in the Update_WMI module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.
Attacker Value
Unknown

CVE-2023-43580

Disclosure Date: November 08, 2023 (last updated November 16, 2023)
A buffer overflow was reported in the SmuV11DxeVMR module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.
Attacker Value
Unknown

CVE-2023-43579

Disclosure Date: November 08, 2023 (last updated November 16, 2023)
A buffer overflow was reported in the SmuV11Dxe driver in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.
Attacker Value
Unknown

CVE-2023-43578

Disclosure Date: November 08, 2023 (last updated November 16, 2023)
A buffer overflow was reported in the SmiFlash module in some Lenovo Desktop products that may allow a local attacker with elevated privileges to execute arbitrary code.