Show filters
380 Total Results
Displaying 11-20 of 380
Sort by:
Attacker Value
Unknown

CVE-2022-39189

Disclosure Date: September 02, 2022 (last updated October 08, 2023)
An issue was discovered the x86 KVM subsystem in the Linux kernel before 5.18.17. Unprivileged guest users can compromise the guest kernel because TLB flush operations are mishandled in certain KVM_VCPU_PREEMPTED situations.
Attacker Value
Unknown

CVE-2020-1971

Disclosure Date: December 08, 2020 (last updated November 08, 2023)
The X.509 GeneralName type is a generic type for representing different types of names. One of those name types is known as EDIPartyName. OpenSSL provides a function GENERAL_NAME_cmp which compares different instances of a GENERAL_NAME to see if they are equal or not. This function behaves incorrectly when both GENERAL_NAMEs contain an EDIPARTYNAME. A NULL pointer dereference and a crash may occur leading to a possible denial of service attack. OpenSSL itself uses the GENERAL_NAME_cmp function for two purposes: 1) Comparing CRL distribution point names between an available CRL and a CRL distribution point embedded in an X509 certificate 2) When verifying that a timestamp response token signer matches the timestamp authority name (exposed via the API functions TS_RESP_verify_response and TS_RESP_verify_token) If an attacker can control both items being compared then that attacker could trigger a crash. For example if the attacker can trick a client or server into checking a malicious c…
Attacker Value
Unknown

CVE-2017-5753

Disclosure Date: January 04, 2018 (last updated January 15, 2025)
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
Attacker Value
Unknown

CVE-2024-22315

Disclosure Date: January 28, 2025 (last updated January 28, 2025)
IBM Fusion and IBM Fusion HCI 2.3.0 through 2.8.2 is vulnerable to insecure network connection by allowing an attacker who gains access to a Fusion container to establish an external network connection.
Attacker Value
Unknown

CVE-2024-49060

Disclosure Date: November 15, 2024 (last updated January 24, 2025)
Azure Stack HCI Elevation of Privilege Vulnerability
0
Attacker Value
Unknown

CVE-2024-38179

Disclosure Date: October 08, 2024 (last updated October 23, 2024)
Azure Stack Hyperconverged Infrastructure (HCI) Elevation of Privilege Vulnerability
Attacker Value
Unknown

CVE-2024-39689

Disclosure Date: July 05, 2024 (last updated February 15, 2025)
Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi starting in 2021.5.30 and prior to 2024.7.4 recognized root certificates from `GLOBALTRUST`. Certifi 2024.7.04 removes root certificates from `GLOBALTRUST` from the root store. These are in the process of being removed from Mozilla's trust store. `GLOBALTRUST`'s root certificates are being removed pursuant to an investigation which identified "long-running and unresolved compliance issues."
Attacker Value
Unknown

CVE-2023-43040

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
IBM Spectrum Fusion HCI 2.5.2 through 2.7.2 could allow an attacker to perform unauthorized actions in RGW for Ceph due to improper bucket access. IBM X-Force ID: 266807.
0
Attacker Value
Unknown

CVE-2024-28917

Disclosure Date: April 09, 2024 (last updated January 12, 2025)
Azure Arc-enabled Kubernetes Extension Cluster-Scope Elevation of Privilege Vulnerability
0
Attacker Value
Unknown

CVE-2024-26462

Disclosure Date: February 29, 2024 (last updated February 15, 2025)
Kerberos 5 (aka krb5) 1.21.2 contains a memory leak vulnerability in /krb5/src/kdc/ndr.c.