Show filters
508 Total Results
Displaying 11-20 of 508
Sort by:
Attacker Value
Unknown
CVE-2023-20515
Disclosure Date: February 11, 2025 (last updated February 12, 2025)
Improper access control in the fTPM driver in the trusted OS could allow a privileged attacker to corrupt system memory, potentially leading to loss of integrity, confidentiality, or availability.
0
Attacker Value
Unknown
CVE-2024-21925
Disclosure Date: February 11, 2025 (last updated February 12, 2025)
Improper input validation within the AmdPspP2CmboxV2 driver may allow a privileged attacker to overwrite SMRAM, leading to arbitrary code execution.
0
Attacker Value
Unknown
CVE-2024-21924
Disclosure Date: February 11, 2025 (last updated February 12, 2025)
SMM callout vulnerability within the AmdPlatformRasSspSmm driver could allow a ring 0 attacker to modify boot services handlers, potentially resulting in arbitrary code execution.
0
Attacker Value
Unknown
CVE-2024-0179
Disclosure Date: February 11, 2025 (last updated February 12, 2025)
SMM Callout vulnerability within the AmdCpmDisplayFeatureSMM driver could allow locally authenticated attackers to overwrite SMRAM, potentially resulting in arbitrary code execution.
0
Attacker Value
Unknown
CVE-2023-20507
Disclosure Date: February 11, 2025 (last updated February 12, 2025)
An integer overflow in the ASP could allow a privileged attacker to perform an out-of-bounds write, potentially resulting in loss of data integrity.
0
Attacker Value
Unknown
CVE-2024-21966
Disclosure Date: February 11, 2025 (last updated February 12, 2025)
A DLL hijacking vulnerability in the AMD Ryzen™ Master Utility could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code execution.
0
Attacker Value
Unknown
CVE-2025-0696
Disclosure Date: January 27, 2025 (last updated January 27, 2025)
A NULL Pointer Dereference vulnerability in Cesanta Frozen versions less than 1.7 allows an attacker to induce a crash of the component embedding the library by supplying a maliciously crafted JSON as input.
0
Attacker Value
Unknown
CVE-2025-0695
Disclosure Date: January 27, 2025 (last updated January 27, 2025)
An Allocation of Resources Without Limits or Throttling vulnerability in Cesanta Frozen versions less than 1.7 allows an attacker to induce a crash of the component embedding the library by supplying a maliciously crafted JSON as input.
0
Attacker Value
Unknown
CVE-2024-22063
Disclosure Date: December 30, 2024 (last updated January 29, 2025)
The ZENIC ONE R58 products by ZTE Corporation have a command injection vulnerability. An authenticated attacker can exploit this vulnerability to tamper with messages, inject malicious code, and subsequently launch attacks on related devices.
0
Attacker Value
Unknown
CVE-2024-12443
Disclosure Date: December 16, 2024 (last updated December 18, 2024)
The CRM Perks – WordPress HelpDesk Integration – Zendesk, Freshdesk, HelpScout plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'crm-perks-tickets' shortcode in all versions up to, and including, 1.1.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0