Show filters
3,556 Total Results
Displaying 171-180 of 3,556
Sort by:
Attacker Value
Unknown
CVE-2022-48220
Disclosure Date: February 14, 2024 (last updated February 15, 2024)
Potential vulnerabilities have been identified in certain HP Desktop PC products using the HP TamperLock feature, which might allow intrusion detection bypass via a physical attack. HP is releasing firmware and guidance to mitigate these potential vulnerabilities.
0
Attacker Value
Unknown
CVE-2022-48219
Disclosure Date: February 14, 2024 (last updated February 15, 2024)
Potential vulnerabilities have been identified in certain HP Desktop PC products using the HP TamperLock feature, which might allow intrusion detection bypass via a physical attack. HP is releasing firmware and guidance to mitigate these potential vulnerabilities.
0
Attacker Value
Unknown
CVE-2024-0849
Disclosure Date: February 07, 2024 (last updated September 05, 2024)
Leanote version 2.7.0 allows obtaining arbitrary local files. This is possible because the application is vulnerable to LFR.
0
Attacker Value
Unknown
CVE-2023-28063
Disclosure Date: February 06, 2024 (last updated February 15, 2024)
Dell BIOS contains a Signed to Unsigned Conversion Error vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to denial of service.
0
Attacker Value
Unknown
CVE-2024-0589
Disclosure Date: January 31, 2024 (last updated February 03, 2024)
Cross-site scripting (XSS) vulnerability in the entry overview tab in Devolutions Remote Desktop Manager 2023.3.36 and earlier on Windows allows an attacker with access to a data source to inject a malicious script via a specially crafted input in an entry.
0
Attacker Value
Unknown
CVE-2024-0409
Disclosure Date: January 18, 2024 (last updated May 22, 2024)
A flaw was found in the X.Org server. The cursor code in both Xephyr and Xwayland uses the wrong type of private at creation. It uses the cursor bits type with the cursor as private, and when initiating the cursor, that overwrites the XSELINUX context.
0
Attacker Value
Unknown
CVE-2024-0408
Disclosure Date: January 18, 2024 (last updated May 22, 2024)
A flaw was found in the X.Org server. The GLX PBuffer code does not call the XACE hook when creating the buffer, leaving it unlabeled. When the client issues another request to access that resource (as with a GetGeometry) or when it creates another resource that needs to access that buffer, such as a GC, the XSELINUX code will try to use an object that was never labeled and crash because the SID is NULL.
0
Attacker Value
Unknown
CVE-2023-6816
Disclosure Date: January 18, 2024 (last updated April 25, 2024)
A flaw was found in X.Org server. Both DeviceFocusEvent and the XIQueryPointer reply contain a bit for each logical button currently down. Buttons can be arbitrarily mapped to any value up to 255, but the X.Org Server was only allocating space for the device's particular number of buttons, leading to a heap overflow if a bigger value was used.
0
Attacker Value
Unknown
CVE-2023-6184
Disclosure Date: January 18, 2024 (last updated January 25, 2024)
Cross SiteScripting vulnerability in Citrix Session Recording allows attacker to perform Cross Site Scripting
0
Attacker Value
Unknown
CVE-2023-49647
Disclosure Date: January 12, 2024 (last updated January 23, 2024)
Improper access control in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom SDKs for Windows before version 5.16.10 may allow an authenticated user to conduct an escalation of privilege via local access.
0