Show filters
4,200 Total Results
Displaying 111-120 of 4,200
Sort by:
Attacker Value
Unknown

CVE-2024-49816

Disclosure Date: December 17, 2024 (last updated January 13, 2025)
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores potentially sensitive information in log files that could be read by a local privileged user.
Attacker Value
Unknown

CVE-2024-10251

Disclosure Date: December 11, 2024 (last updated December 18, 2024)
Under specific circumstances, insecure permissions in Ivanti Security Controls before version 2024.4.1 allows a local authenticated attacker to achieve local privilege escalation.
Attacker Value
Unknown

CVE-2024-10256

Disclosure Date: December 10, 2024 (last updated December 21, 2024)
Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbitrary files.
0
Attacker Value
Unknown

CVE-2024-12174

Disclosure Date: December 09, 2024 (last updated December 21, 2024)
An Improper Certificate Validation vulnerability exists in Tenable Security Center where an authenticated, privileged attacker could intercept email messages sent from Security Center via a rogue SMTP server.
0
Attacker Value
Unknown

CVE-2024-11585

Disclosure Date: December 06, 2024 (last updated December 21, 2024)
The WP Hide & Security Enhancer plugin for WordPress is vulnerable to arbitrary file contents deletion due to a missing authorization and insufficient file path validation in the file-process.php in all versions up to, and including, 2.5.1. This makes it possible for unauthenticated attackers to delete the contents of arbitrary files on the server, which can break the site or lead to data loss.
0
Attacker Value
Unknown

CVE-2024-52548

Disclosure Date: December 03, 2024 (last updated December 21, 2024)
An attacker who can execute arbitrary Operating Systems commands, can bypass code signing enforcements in the kernel, and execute arbitrary native code. This vulnerability has been resolved in firmware version 2.800.0000000.8.R.20241111.
0
Attacker Value
Unknown

CVE-2024-52547

Disclosure Date: December 03, 2024 (last updated December 21, 2024)
An authenticated attacker can trigger a stack based buffer overflow in the DHIP Service (TCP port 80). This vulnerability has been resolved in firmware version 2.800.0000000.8.R.20241111.
0
Attacker Value
Unknown

CVE-2024-52546

Disclosure Date: December 03, 2024 (last updated December 21, 2024)
An unauthenticated attacker can perform a null pointer dereference in the DHIP Service (UDP port 37810). This vulnerability has been resolved in firmware version 2.800.0000000.8.R.20241111.
0
Attacker Value
Unknown

CVE-2024-52545

Disclosure Date: December 03, 2024 (last updated December 21, 2024)
An unauthenticated attacker can perform an out of bounds heap read in the IQ Service (TCP port 9876). This vulnerability has been resolved in firmware version 2.800.0000000.8.R.20241111.
0
Attacker Value
Unknown

CVE-2024-52544

Disclosure Date: December 03, 2024 (last updated December 21, 2024)
An unauthenticated attacker can trigger a stack based buffer overflow in the DP Service (TCP port 3500). This vulnerability has been resolved in firmware version 2.800.0000000.8.R.20241111.
0