Show filters
492 Total Results
Displaying 121-130 of 492
Sort by:
Attacker Value
Unknown
CVE-2022-40134
Disclosure Date: January 30, 2023 (last updated February 24, 2025)
An information leak vulnerability in the SMI Set BIOS Password SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.
0
Attacker Value
Unknown
CVE-2022-34888
Disclosure Date: January 30, 2023 (last updated February 24, 2025)
The Remote Mount feature can potentially be abused by valid, authenticated users to make connections to internal services that may not normally be accessible to users. Internal service access controls, as applicable, remain in effect.
0
Attacker Value
Unknown
CVE-2022-34884
Disclosure Date: January 30, 2023 (last updated February 24, 2025)
A buffer overflow exists in the Remote Presence subsystem which can potentially allow valid, authenticated users to cause a recoverable subsystem denial of service.
0
Attacker Value
Unknown
CVE-2022-34460
Disclosure Date: January 18, 2023 (last updated February 24, 2025)
Prior Dell BIOS versions contain an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
0
Attacker Value
Unknown
CVE-2022-34393
Disclosure Date: January 18, 2023 (last updated February 24, 2025)
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
0
Attacker Value
Unknown
CVE-2021-3942
Disclosure Date: December 12, 2022 (last updated February 24, 2025)
Certain HP Print products and Digital Sending products may be vulnerable to potential remote code execution and buffer overflow with use of Link-Local Multicast Name Resolution or LLMNR.
0
Attacker Value
Unknown
CVE-2022-40204
Disclosure Date: December 01, 2022 (last updated February 24, 2025)
A cross-site scripting (XSS) vulnerability exists in all current versions of Digital Alert Systems DASDEC software via the Host Header in undisclosed pages after login.
0
Attacker Value
Unknown
CVE-2019-18265
Disclosure Date: November 30, 2022 (last updated February 24, 2025)
Digital Alert Systems’ DASDEC software prior to version 4.1 contains a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web script or HTML via the SSH username, username field of the login page, or via the HTTP host header. The injected content is stored in logs and rendered when viewed in the web application.
0
Attacker Value
Unknown
CVE-2022-20943
Disclosure Date: November 15, 2022 (last updated February 24, 2025)
Multiple vulnerabilities in the Server Message Block Version 2 (SMB2) processor of the Snort detection engine on multiple Cisco products could allow an unauthenticated, remote attacker to bypass the configured policies or cause a denial of service (DoS) condition on an affected device.
These vulnerabilities are due to improper management of system resources when the Snort detection engine is processing SMB2 traffic. An attacker could exploit these vulnerabilities by sending a high rate of certain types of SMB2 packets through an affected device. A successful exploit could allow the attacker to trigger a reload of the Snort process, resulting in a DoS condition.
Note: When the snort preserve-connection option is enabled for the Snort detection engine, a successful exploit could also allow the attacker to bypass the configured policies and deliver a malicious payload to the protected network. The snort preserve-connection setting is enabled by default. See the Details ["#details"]…
0
Attacker Value
Unknown
CVE-2020-12930
Disclosure Date: November 08, 2022 (last updated February 24, 2025)
Improper parameters handling in AMD Secure Processor (ASP) drivers may allow a privileged attacker to elevate their privileges potentially leading to loss of integrity.
0