Show filters
9,338 Total Results
Displaying 161-170 of 9,338
Sort by:
Attacker Value
Unknown

CVE-2024-45775

Disclosure Date: February 18, 2025 (last updated February 27, 2025)
A flaw was found in grub2 where the grub_extcmd_dispatcher() function calls grub_arg_list_alloc() to allocate memory for the grub's argument list. However, it fails to check in case the memory allocation fails. Once the allocation fails, a NULL point will be processed by the parse_option() function, leading grub to crash or, in some rare scenarios, corrupt the IVT data.
Attacker Value
Unknown

CVE-2025-26465

Disclosure Date: February 18, 2025 (last updated February 27, 2025)
A vulnerability was found in OpenSSH when the VerifyHostKeyDNS option is enabled. A machine-in-the-middle attack can be performed by a malicious machine impersonating a legit server. This issue occurs due to how OpenSSH mishandles error codes in specific conditions when verifying the host key. For an attack to be considered successful, the attacker needs to manage to exhaust the client's memory resource first, turning the attack complexity high.
0
Attacker Value
Unknown

CVE-2024-45774

Disclosure Date: February 18, 2025 (last updated February 27, 2025)
A flaw was found in grub2. A specially crafted JPEG file can cause the JPEG parser of grub2 to incorrectly check the bounds of its internal buffers, resulting in an out-of-bounds write. The possibility of overwriting sensitive information to bypass secure boot protections is not discarded.
Attacker Value
Unknown

CVE-2024-47935

Disclosure Date: February 17, 2025 (last updated February 27, 2025)
Improper Validation of Integrity Check Value vulnerability in TXOne Networks StellarProtect (Legacy Mode), StellarEnforce, and Safe Lock allows an attacker to escalate their privileges in the victim’s device. The attacker needs to hijack the DLL file in advance. This issue affects StellarProtect (Legacy Mode): before 3.2; StellarEnforce: before 3.2; Safe Lock: from 3.0.0 before 3.1.1076. *Note: StellarProtect (Legacy Mode) is the new name for StellarEnforce, they are the same product.
0
Attacker Value
Unknown

CVE-2025-0593

Disclosure Date: February 14, 2025 (last updated February 27, 2025)
The vulnerability may allow a remote low priviledged attacker to run arbitrary shell commands by using lower-level functions to interact with the device.
0
Attacker Value
Unknown

CVE-2025-0592

Disclosure Date: February 14, 2025 (last updated February 27, 2025)
The vulnerability may allow a remote low priviledged attacker to run arbitrary shell commands by manipulating the firmware file and uploading it to the device.
0
Attacker Value
Unknown

CVE-2025-26508

Disclosure Date: February 14, 2025 (last updated February 27, 2025)
Certain HP LaserJet Pro, HP LaserJet Enterprise, and HP LaserJet Managed Printers may potentially be vulnerable to Remote Code Execution and Elevation of Privilege when processing a PostScript print job.
0
Attacker Value
Unknown

CVE-2025-26507

Disclosure Date: February 14, 2025 (last updated February 27, 2025)
Certain HP LaserJet Pro, HP LaserJet Enterprise, and HP LaserJet Managed Printers may potentially be vulnerable to Remote Code Execution and Elevation of Privilege when processing a PostScript print job.
0
Attacker Value
Unknown

CVE-2025-26506

Disclosure Date: February 14, 2025 (last updated February 27, 2025)
Certain HP LaserJet Pro, HP LaserJet Enterprise, and HP LaserJet Managed Printers may potentially be vulnerable to Remote Code Execution and Elevation of Privilege when processing a PostScript print job.
0
Attacker Value
Unknown

CVE-2025-0937

Disclosure Date: February 12, 2025 (last updated February 27, 2025)
Nomad Community and Nomad Enterprise ("Nomad") event stream configured with a wildcard namespace can bypass the ACL Policy allowing reads on other namespaces.
0