Show filters
67 Total Results
Displaying 11-20 of 67
Sort by:
Attacker Value
Unknown

CVE-2023-45319

Disclosure Date: November 08, 2023 (last updated February 25, 2025)
In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the commit function was identified. Reported by Jason Geffner. 
Attacker Value
Unknown

CVE-2023-35767

Disclosure Date: November 08, 2023 (last updated February 25, 2025)
In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the shutdown function was identified. Reported by Jason Geffner.  
Attacker Value
Unknown

CVE-2023-38647

Disclosure Date: July 26, 2023 (last updated February 25, 2025)
An attacker can use SnakeYAML to deserialize java.net.URLClassLoader and make it load a JAR from a specified URL, and then deserialize javax.script.ScriptEngineManager to load code using that ClassLoader. This unbounded deserialization can likely lead to remote code execution. The code can be run in Helix REST start and Workflow creation. Affect all the versions lower and include 1.2.0. Affected products: helix-core, helix-rest Mitigation: Short term, stop using any YAML based configuration and workflow creation.                   Long term, all Helix version bumping up to 1.3.0 
Attacker Value
Unknown

CVE-2022-47500

Disclosure Date: December 19, 2022 (last updated February 24, 2025)
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Software Foundation Apache Helix UI component.This issue affects Apache Helix all releases from 0.8.0 to 1.0.4. Solution: removed the the forward component since it was improper designed for UI embedding.  User please upgrade to 1.1.0 to fix this issue.
Attacker Value
Unknown

CVE-2022-1107

Disclosure Date: April 22, 2022 (last updated February 23, 2025)
During an internal product security audit a potential vulnerability due to use of Boot Services in the SmmOEMInt15 SMI handler was discovered in some ThinkPad models could be exploited by an attacker with elevated privileges that could allow for execution of code.
Attacker Value
Unknown

CVE-2021-3786

Disclosure Date: November 12, 2021 (last updated February 23, 2025)
A potential vulnerability in the SMI callback function used in CSME configuration of some Lenovo Notebook and ThinkPad systems could be used to leak out data out of the SMRAM range.
Attacker Value
Unknown

CVE-2021-3453

Disclosure Date: July 16, 2021 (last updated February 23, 2025)
Some Lenovo Notebook, ThinkPad, and Lenovo Desktop systems have BIOS modules unprotected by Intel Boot Guard that could allow an attacker with physical access the ability to write to the SPI flash storage.
Attacker Value
Unknown

CVE-2021-28973

Disclosure Date: April 13, 2021 (last updated February 22, 2025)
The XML Import functionality of the Administration console in Perforce Helix ALM 2020.3.1 Build 22 accepts XML input data that is parsed by insecurely configured software components, leading to XXE attacks.
Attacker Value
Unknown

CVE-2020-8323

Disclosure Date: June 09, 2020 (last updated November 28, 2024)
A potential vulnerability in the SMI callback function used in the Legacy SD driver in some Lenovo ThinkPad, ThinkStation, and Lenovo Notebook models may allow arbitrary code execution.
Attacker Value
Unknown

A potential vulnerability in some Lenovo ThinkPads may allow an attacker to exe…

Disclosure Date: November 12, 2019 (last updated November 27, 2024)
A potential vulnerability in the SMI callback function used in the Legacy USB driver using boot services structure in runtime phase in some Lenovo ThinkPad models may allow arbitrary code execution.