Show filters
495 Total Results
Displaying 121-130 of 495
Sort by:
Attacker Value
Unknown

CVE-2023-6044

Disclosure Date: January 19, 2024 (last updated January 27, 2024)
A privilege escalation vulnerability was reported in Lenovo Vantage that could allow a local attacker with physical access to impersonate Lenovo Vantage Service and execute arbitrary code with elevated privileges.
Attacker Value
Unknown

CVE-2023-6043

Disclosure Date: January 19, 2024 (last updated January 27, 2024)
A privilege escalation vulnerability was reported in Lenovo Vantage that could allow a local attacker to bypass integrity checks and execute arbitrary code with elevated privileges.
Attacker Value
Unknown

CVE-2022-41990

Disclosure Date: January 17, 2024 (last updated January 25, 2024)
Cross-Site Request Forgery (CSRF) vulnerability in Vinoj Cardoza 3D Tag Cloud allows Stored XSS.This issue affects 3D Tag Cloud: from n/a through 3.8.
Attacker Value
Unknown

CVE-2022-36418

Disclosure Date: January 17, 2024 (last updated January 25, 2024)
Missing Authorization vulnerability in Vagary Digital HREFLANG Tags Lite.This issue affects HREFLANG Tags Lite: from n/a through 2.0.0.
Attacker Value
Unknown

CVE-2016-20021

Disclosure Date: January 12, 2024 (last updated January 23, 2024)
In Gentoo Portage before 3.0.47, there is missing PGP validation of executed code: the standalone emerge-webrsync downloads a .gpgsig file but does not perform signature verification. Unless emerge-webrsync is used, Portage is not vulnerable.
Attacker Value
Unknown

CVE-2023-50671

Disclosure Date: January 11, 2024 (last updated January 19, 2024)
In exiftags 1.01, nikon_prop1 in nikon.c has a heap-based buffer overflow (write of size 28) because snprintf can write to an unexpected address.
Attacker Value
Unknown

CVE-2024-20715

Disclosure Date: January 10, 2024 (last updated January 18, 2024)
Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Attacker Value
Unknown

CVE-2024-20714

Disclosure Date: January 10, 2024 (last updated January 18, 2024)
Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Attacker Value
Unknown

CVE-2024-20713

Disclosure Date: January 10, 2024 (last updated January 13, 2024)
Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Attacker Value
Unknown

CVE-2024-20712

Disclosure Date: January 10, 2024 (last updated January 13, 2024)
Adobe Substance 3D Stager versions 2.1.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.