Show filters
726 Total Results
Displaying 121-130 of 726
Sort by:
Attacker Value
Unknown

CVE-2023-39979

Disclosure Date: September 02, 2023 (last updated February 25, 2025)
There is a vulnerability in MXsecurity versions prior to 1.0.1 that can be exploited to bypass authentication. A remote attacker might access the system if the web service authenticator has insufficient random values.  
Attacker Value
Unknown

CVE-2023-40239

Disclosure Date: September 01, 2023 (last updated February 25, 2025)
Certain Lexmark devices (such as CS310) before 2023-08-25 allow XXE attacks, leading to information disclosure. The fixed firmware version is LW80.*.P246, i.e., '*' indicates that the full version specification varies across product model family, but firmware level P246 (or higher) is required to remediate the vulnerability.
Attacker Value
Unknown

CVE-2022-43505

Disclosure Date: August 11, 2023 (last updated February 25, 2025)
Insufficient control flow management in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable denial of service via local access.
Attacker Value
Unknown

CVE-2022-38083

Disclosure Date: August 11, 2023 (last updated February 25, 2025)
Improper initialization in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
Attacker Value
Unknown

CVE-2022-4046

Disclosure Date: August 03, 2023 (last updated February 25, 2025)
In CODESYS Control in multiple versions a improper restriction of operations within the bounds of a memory buffer allow an remote attacker with user privileges to gain full access of the device.
Attacker Value
Unknown

CVE-2023-37559

Disclosure Date: August 03, 2023 (last updated February 25, 2025)
After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted network communication requests with inconsistent content can cause the CmpAppForce component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37558
Attacker Value
Unknown

CVE-2023-37558

Disclosure Date: August 03, 2023 (last updated February 25, 2025)
After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted network communication requests with inconsistent content can cause the CmpAppForce component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37559
Attacker Value
Unknown

CVE-2023-37557

Disclosure Date: August 03, 2023 (last updated February 25, 2025)
After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted remote communication requests can cause the CmpAppBP component to overwrite a heap-based buffer, which can lead to a denial-of-service condition.
Attacker Value
Unknown

CVE-2023-37556

Disclosure Date: August 03, 2023 (last updated February 25, 2025)
In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37552, CVE-2023-37553, CVE-2023-37554 and CVE-2023-37555.
Attacker Value
Unknown

CVE-2023-37555

Disclosure Date: August 03, 2023 (last updated February 25, 2025)
In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability is different to CVE-2023-37552, CVE-2023-37553, CVE-2023-37554 and CVE-2023-37556.