Show filters
80 Total Results
Displaying 11-20 of 80
Sort by:
Attacker Value
Unknown

CVE-2024-51720

Disclosure Date: November 12, 2024 (last updated November 13, 2024)
An insufficient entropy vulnerability in the SecuSUITE Secure Client Authentication (SCA) Server of SecuSUITE versions 5.0.420 and earlier could allow an attacker to potentially enroll an attacker-controlled device to the victim’s account and telephone number.
0
Attacker Value
Unknown

CVE-2024-35215

Disclosure Date: October 08, 2024 (last updated October 09, 2024)
NULL pointer dereference in IP socket options processing of the Networking Stack in QNX Software Development Platform (SDP) version(s) 7.1 and 7.0 could allow an attacker with local access to cause a denial-of-service condition in the context of the Networking Stack process.
0
Attacker Value
Unknown

CVE-2024-35214

Disclosure Date: August 20, 2024 (last updated August 21, 2024)
A tampering vulnerability in the CylanceOPTICS Windows Installer Package of CylanceOPTICS for Windows version 3.2 and 3.3 could allow an attacker to potentially uninstall CylanceOPTICS from a system thereby leaving it with only the protection of CylancePROTECT.
0
Attacker Value
Unknown

CVE-2024-35213

Disclosure Date: June 11, 2024 (last updated June 12, 2024)
An improper input validation vulnerability in the SGI Image Codec of QNX SDP version(s) 6.6, 7.0, and 7.1 could allow an attacker to potentially cause a denial-of-service condition or execute code in the context of the image processing process.
0
Attacker Value
Unknown

CVE-2023-32701

Disclosure Date: November 14, 2023 (last updated November 22, 2023)
Improper Input Validation in the Networking Stack of QNX SDP version(s) 6.6, 7.0, and 7.1 could allow an attacker to potentially cause Information Disclosure or a Denial-of-Service condition.
Attacker Value
Unknown

CVE-2023-21523

Disclosure Date: September 12, 2023 (last updated October 08, 2023)
A Stored Cross-site Scripting (XSS) vulnerability in the Management Console (User Management and Alerts) of BlackBerry AtHoc version 7.15 could allow an attacker to execute script commands in the context of the affected user account.
Attacker Value
Unknown

CVE-2023-21520

Disclosure Date: September 12, 2023 (last updated October 08, 2023)
A PII Enumeration via Credential Recovery in the Self Service (Credential Recovery) of BlackBerry AtHoc version 7.15 could allow an attacker to potentially associate a list of contact details with an AtHoc IWS organization.
Attacker Value
Unknown

CVE-2023-21522

Disclosure Date: September 12, 2023 (last updated October 08, 2023)
A Reflected Cross-site Scripting (XSS) vulnerability in the Management Console (Reports) of BlackBerry AtHoc version 7.15 could allow an attacker to potentially control a script that is executed in the victim's browser then they can execute script commands in the context of the affected user account. 
Attacker Value
Unknown

CVE-2023-21521

Disclosure Date: September 12, 2023 (last updated November 08, 2023)
An SQL Injection vulnerability in the Management Console  (Operator Audit Trail) of BlackBerry AtHoc version 7.15 could allow an attacker to potentially read sensitive data from the database, modify database data (Insert/Update/Delete), execute administration operations on the database, recover the content of a given file present on the DBMS file system and in some cases issue commands to the operating system.
Attacker Value
Unknown

CVE-2021-32025

Disclosure Date: March 10, 2022 (last updated October 07, 2023)
An elevation of privilege vulnerability in the QNX Neutrino Kernel of affected versions of QNX Software Development Platform version(s) 6.4.0 to 7.0, QNX Momentics all 6.3.x versions, QNX OS for Safety versions 1.0.0 to 1.0.2, QNX OS for Safety versions 2.0.0 to 2.0.1, QNX for Medical versions 1.0.0 to 1.1.1, and QNX OS for Medical version 2.0.0 could allow an attacker to potentially access data, modify behavior, or permanently crash the system.