Show filters
726 Total Results
Displaying 161-170 of 726
Sort by:
Attacker Value
Unknown

CVE-2023-25537

Disclosure Date: May 22, 2023 (last updated February 25, 2025)
Dell PowerEdge 14G server BIOS versions prior to 2.18.1 and Dell Precision BIOS versions prior to 2.18.2, contain an Out of Bounds write vulnerability. A local attacker with low privileges could potentially exploit this vulnerability leading to exposure of some SMRAM stack/data/code in System Management Mode, leading to arbitrary code execution or escalation of privilege.
Attacker Value
Unknown

CVE-2023-33236

Disclosure Date: May 22, 2023 (last updated February 25, 2025)
MXsecurity version 1.0 is vulnearble to hardcoded credential vulnerability. This vulnerability has been reported that can be exploited to craft arbitrary JWT tokens and subsequently bypass authentication for web-based APIs.
Attacker Value
Unknown

CVE-2023-33235

Disclosure Date: May 22, 2023 (last updated February 25, 2025)
MXsecurity version 1.0 is vulnearble to command injection vulnerability. This vulnerability has been reported in the SSH CLI program, which can be exploited by attackers who have gained authorization privileges. The attackers can break out of the restricted shell and subsequently execute arbitrary code.
Attacker Value
Unknown

CVE-2022-47393

Disclosure Date: May 15, 2023 (last updated February 24, 2025)
An authenticated, remote attacker may use a Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple versions of multiple CODESYS products to force a denial-of-service situation.
Attacker Value
Unknown

CVE-2022-47392

Disclosure Date: May 15, 2023 (last updated February 24, 2025)
An authenticated, remote attacker may use a improper input validation vulnerability in the CmpApp/CmpAppBP/CmpAppForce Components of multiple CODESYS products in multiple versions to read from an invalid address which can lead to a denial-of-service condition.
Attacker Value
Unknown

CVE-2022-47391

Disclosure Date: May 15, 2023 (last updated February 24, 2025)
In multiple CODESYS products in multiple versions an unauthorized, remote attacker may use a improper input validation vulnerability to read from invalid addresses leading to a denial of service.
Attacker Value
Unknown

CVE-2022-47390

Disclosure Date: May 15, 2023 (last updated February 24, 2025)
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
Attacker Value
Unknown

CVE-2022-47389

Disclosure Date: May 15, 2023 (last updated February 24, 2025)
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
Attacker Value
Unknown

CVE-2022-47388

Disclosure Date: May 15, 2023 (last updated February 24, 2025)
An authenticated, remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.
Attacker Value
Unknown

CVE-2022-47387

Disclosure Date: May 15, 2023 (last updated February 24, 2025)
An authenticated remote attacker may use a stack based out-of-bounds write vulnerability in the CmpTraceMgr Component of multiple CODESYS products in multiple versions to write data into the stack which can lead to a denial-of-service condition, memory overwriting, or remote code execution.