Show filters
336 Total Results
Displaying 111-120 of 336
Sort by:
Attacker Value
Unknown
CVE-2021-28685
Disclosure Date: April 08, 2021 (last updated February 22, 2025)
AsIO2_64.sys and AsIO2_32.sys in ASUS GPUTweak II before 2.3.0.3 allow low-privileged users to interact directly with physical memory (by calling one of several driver routines that map physical memory into the virtual address space of the calling process) and to interact with MSR registers. This could enable low-privileged users to achieve NT AUTHORITY\SYSTEM privileges via a DeviceIoControl.
0
Attacker Value
Unknown
CVE-2021-28686
Disclosure Date: April 08, 2021 (last updated February 22, 2025)
AsIO2_64.sys and AsIO2_32.sys in ASUS GPUTweak II before 2.3.0.3 allow low-privileged users to trigger a stack-based buffer overflow. This could enable low-privileged users to achieve Denial of Service via a DeviceIoControl.
0
Attacker Value
Unknown
CVE-2021-28198
Disclosure Date: April 06, 2021 (last updated February 22, 2025)
The Firmware protocol configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
0
Attacker Value
Unknown
CVE-2021-28182
Disclosure Date: April 06, 2021 (last updated February 22, 2025)
The Web Service configuration function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
0
Attacker Value
Unknown
CVE-2021-28204
Disclosure Date: April 06, 2021 (last updated February 22, 2025)
The specific function in ASUS BMC’s firmware Web management page (Modify user’s information function) does not filter the specific parameter. As obtaining the administrator permission, remote attackers can launch command injection to execute command arbitrary.
0
Attacker Value
Unknown
CVE-2021-28201
Disclosure Date: April 06, 2021 (last updated February 22, 2025)
The Service configuration-1 function in ASUS BMC’s firmware Web management page does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
0
Attacker Value
Unknown
CVE-2021-28196
Disclosure Date: April 06, 2021 (last updated February 22, 2025)
The specific function in ASUS BMC’s firmware Web management page (Generate SSL certificate function) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
0
Attacker Value
Unknown
CVE-2021-28194
Disclosure Date: April 06, 2021 (last updated February 22, 2025)
The specific function in ASUS BMC’s firmware Web management page (Remote image configuration setting) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
0
Attacker Value
Unknown
CVE-2021-28185
Disclosure Date: April 06, 2021 (last updated February 22, 2025)
The specific function in ASUS BMC’s firmware Web management page (ActiveX configuration-1 acquisition) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
0
Attacker Value
Unknown
CVE-2021-28186
Disclosure Date: April 06, 2021 (last updated February 22, 2025)
The specific function in ASUS BMC’s firmware Web management page (ActiveX configuration-2 acquisition) does not verify the string length entered by users, resulting in a Buffer overflow vulnerability. As obtaining the privileged permission, remote attackers use the leakage to abnormally terminate the Web service.
0