Show filters
726 Total Results
Displaying 101-110 of 726
Sort by:
Attacker Value
Unknown
CVE-2023-32460
Disclosure Date: December 08, 2023 (last updated February 25, 2025)
Dell PowerEdge BIOS contains an improper privilege management security vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to privilege escalation.
0
Attacker Value
Unknown
CVE-2023-43744
Disclosure Date: December 08, 2023 (last updated February 25, 2025)
An OS command injection vulnerability in Zultys MX-SE, MX-SE II, MX-E, MX-Virtual, MX250, and MX30 with firmware versions prior to 17.0.10 patch 17161 and 16.04 patch 16109 allows an administrator to execute arbitrary OS commands via a file name parameter in a patch application function. The Zultys MX Administrator client has a "Patch Manager" section that allows administrators to apply patches to the device. The user supplied filename for the patch file is passed to a shell script without validation. Including bash command substitution characters in a patch file name results in execution of the provided command.
0
Attacker Value
Unknown
CVE-2023-43743
Disclosure Date: December 08, 2023 (last updated February 25, 2025)
A SQL injection vulnerability in Zultys MX-SE, MX-SE II, MX-E, MX-Virtual, MX250, and MX30 with firmware versions prior to 17.0.10 patch 17161 and 16.04 patch 16109 allows an authenticated attacker to execute arbitrary SQL queries on the backend database via the filter parameter in requests to the /newapi/ endpoint in the Zultys MX web interface.
0
Attacker Value
Unknown
CVE-2023-43742
Disclosure Date: December 08, 2023 (last updated February 25, 2025)
An authentication bypass in Zultys MX-SE, MX-SE II, MX-E, MX-Virtual, MX250, and MX30 with firmware versions prior to 17.0.10 patch 17161 and 16.04 patch 16109 allows an unauthenticated attacker to obtain an administrative session via a protection mechanism failure in the authentication function. In normal operation, the Zultys MX Administrator Windows client connects to port 7505 and attempts authentication, submitting the administrator username and password to the server. Upon authentication failure, the server sends a login failure message prompting the client to disconnect. However, if the client ignores the failure message instead and attempts to continue, the server does not forcibly close the connection and processes all subsequent requests from the client as if authentication had been successful.
0
Attacker Value
Unknown
CVE-2023-44298
Disclosure Date: December 05, 2023 (last updated February 25, 2025)
Dell PowerEdge platforms 16G Intel E5 BIOS and Dell Precision BIOS, version 1.4.4, contain active debug code security vulnerability. An unauthenticated physical attacker could potentially exploit this vulnerability, leading to information tampering, code execution, denial of service.
0
Attacker Value
Unknown
CVE-2023-44297
Disclosure Date: December 05, 2023 (last updated February 25, 2025)
Dell PowerEdge platforms 16G Intel E5 BIOS and Dell Precision BIOS, version 1.4.4, contain active debug code security vulnerability. An unauthenticated physical attacker could potentially exploit this vulnerability, leading to information disclosure, information tampering, code execution, denial of service.
0
Attacker Value
Unknown
CVE-2023-6357
Disclosure Date: December 05, 2023 (last updated February 25, 2025)
A low-privileged remote attacker could exploit the vulnerability and inject additional system commands via file system libraries which could give the attacker full control of the device.
0
Attacker Value
Unknown
CVE-2021-35437
Disclosure Date: November 16, 2023 (last updated February 25, 2025)
SQL injection vulnerability in LMXCMS v.1.4 allows attacker to execute arbitrary code via the TagsAction.class.
0
Attacker Value
Unknown
CVE-2023-22327
Disclosure Date: November 14, 2023 (last updated February 25, 2025)
Out-of-bounds write in firmware for some Intel(R) FPGA products before version 2.8.1 may allow a privileged user to potentially enable information disclosure via local access.
0
Attacker Value
Unknown
CVE-2023-46958
Disclosure Date: November 02, 2023 (last updated February 25, 2025)
An issue in lmxcms v.1.41 allows a remote attacker to execute arbitrary code via a crafted script to the admin.php file.
0