Show filters
423 Total Results
Displaying 121-130 of 423
Sort by:
Attacker Value
Unknown

CVE-2024-50317

Disclosure Date: November 12, 2024 (last updated November 19, 2024)
A null pointer dereference in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.
Attacker Value
Unknown

CVE-2024-47909

Disclosure Date: November 12, 2024 (last updated November 19, 2024)
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to cause a denial of service.
Attacker Value
Unknown

CVE-2024-47907

Disclosure Date: November 12, 2024 (last updated November 19, 2024)
A stack-based buffer overflow in IPsec of Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to cause a denial of service.
Attacker Value
Unknown

CVE-2024-47906

Disclosure Date: November 12, 2024 (last updated January 18, 2025)
Excessive binary privileges in Ivanti Connect Secure before version 22.7R2.3 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.2 (Not Applicable to 9.1Rx) allows a local authenticated attacker to escalate privileges.
Attacker Value
Unknown

CVE-2024-47905

Disclosure Date: November 12, 2024 (last updated November 19, 2024)
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to cause a denial of service.
Attacker Value
Unknown

CVE-2024-11007

Disclosure Date: November 12, 2024 (last updated November 22, 2024)
Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Applicable to 9.1Rx) allows a remote authenticated attacker with admin privileges to achieve remote code execution.
Attacker Value
Unknown

CVE-2024-29821

Disclosure Date: October 18, 2024 (last updated October 19, 2024)
Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified attack vector.
0
Attacker Value
Unknown

CVE-2024-29213

Disclosure Date: October 18, 2024 (last updated October 19, 2024)
Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified attack vector.
0
Attacker Value
Unknown

CVE-2024-9381

Disclosure Date: October 08, 2024 (last updated October 17, 2024)
Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions.
Attacker Value
Unknown

CVE-2024-9380

Disclosure Date: October 08, 2024 (last updated October 12, 2024)
An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to obtain remote code execution.