Show filters
662 Total Results
Displaying 101-110 of 662
Sort by:
Attacker Value
Unknown
CVE-2024-27287
Disclosure Date: March 06, 2024 (last updated March 07, 2024)
ESPHome is a system to control your ESP8266/ESP32 for Home Automation systems. Starting in version 2023.12.9 and prior to version 2024.2.2, editing the configuration file API in dashboard component of ESPHome version 2023.12.9 (command line installation and Home Assistant add-on) serves unsanitized data with `Content-Type: text/html; charset=UTF-8`, allowing a remote authenticated user to inject arbitrary web script and exfiltrate session cookies via Cross-Site scripting. It is possible for a malicious authenticated user to inject arbitrary Javascript in configuration files using a POST request to the /edit endpoint, the configuration parameter allows to specify the file to write. To trigger the XSS vulnerability, the victim must visit the page` /edit?configuration=[xss file]`. Abusing this vulnerability a malicious actor could perform operations on the dashboard on the behalf of a logged user, access sensitive information, create, edit and delete configuration files and flash firmwar…
0
Attacker Value
Unknown
CVE-2023-43553
Disclosure Date: March 04, 2024 (last updated January 12, 2025)
Memory corruption while parsing beacon/probe response frame when AP sends more supported links in MLIE.
0
Attacker Value
Unknown
CVE-2023-43552
Disclosure Date: March 04, 2024 (last updated January 12, 2025)
Memory corruption while processing MBSSID beacon containing several subelement IE.
0
Attacker Value
Unknown
CVE-2023-43549
Disclosure Date: March 04, 2024 (last updated January 12, 2025)
Memory corruption while processing TPC target power table in FTM TPC.
0
Attacker Value
Unknown
CVE-2023-43539
Disclosure Date: March 04, 2024 (last updated January 12, 2025)
Transient DOS while processing an improperly formatted 802.11az Fine Time Measurement protocol frame.
0
Attacker Value
Unknown
CVE-2023-33105
Disclosure Date: March 04, 2024 (last updated January 12, 2025)
Transient DOS in WLAN Host and Firmware when large number of open authentication frames are sent with an invalid transaction sequence number.
0
Attacker Value
Unknown
CVE-2023-33066
Disclosure Date: March 04, 2024 (last updated January 12, 2025)
Memory corruption in Audio while processing RT proxy port register driver.
0
Attacker Value
Unknown
CVE-2023-28578
Disclosure Date: March 04, 2024 (last updated January 12, 2025)
Memory corruption in Core Services while executing the command for removing a single event listener.
0
Attacker Value
Unknown
CVE-2024-27081
Disclosure Date: February 26, 2024 (last updated February 08, 2025)
ESPHome is a system to control your ESP8266/ESP32. A security misconfiguration in the edit configuration file API in the dashboard component of ESPHome version 2023.12.9 (command line installation) allows authenticated remote attackers to read and write arbitrary files under the configuration directory rendering remote code execution possible. This vulnerability is patched in 2024.2.1.
0
Attacker Value
Unknown
CVE-2023-44283
Disclosure Date: February 14, 2024 (last updated October 18, 2024)
In Dell SupportAssist for Home PCs (between v3.0 and v3.14.1) and SupportAssist for Business PCs (between v3.0 and v3.4.1), a security concern has been identified, impacting locally authenticated users on their respective PCs. This issue may potentially enable privilege escalation and the execution of arbitrary code, in the Windows system context, and confined to that specific local PC.
0