Show filters
423 Total Results
Displaying 171-180 of 423
Sort by:
Attacker Value
Unknown

CVE-2024-37399

Disclosure Date: August 14, 2024 (last updated August 16, 2024)
A NULL pointer dereference in WLAvalancheService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the service, resulting in a DoS.
Attacker Value
Unknown

CVE-2024-37373

Disclosure Date: August 14, 2024 (last updated August 16, 2024)
Improper input validation in the Central Filestore in Ivanti Avalanche 6.3.1 allows a remote authenticated attacker with admin rights to achieve RCE.
Attacker Value
Unknown

CVE-2024-36136

Disclosure Date: August 14, 2024 (last updated August 16, 2024)
An off-by-one error in WLInfoRailService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the service, resulting in a DoS.
Attacker Value
Unknown

CVE-2024-7570

Disclosure Date: August 13, 2024 (last updated September 07, 2024)
Improper certificate validation in Ivanti ITSM on-prem and Neurons for ITSM Versions 2023.4 and earlier allows a remote attacker in a MITM position to craft a token that would allow access to ITSM as any user.
Attacker Value
Unknown

CVE-2024-7569

Disclosure Date: August 13, 2024 (last updated September 07, 2024)
An information disclosure vulnerability in Ivanti ITSM on-prem and Neurons for ITSM versions 2023.4 and earlier allows an unauthenticated attacker to obtain the OIDC client secret via debug information.
Attacker Value
Unknown

CVE-2024-37403

Disclosure Date: August 07, 2024 (last updated August 13, 2024)
Ivanti Docs@Work for Android, before 2.26.0 is affected by the 'Dirty Stream' vulnerability. The application fails to properly sanitize file names, resulting in a path traversal-affiliated vulnerability. This potentially enables other malicious apps on the device to read sensitive information stored in the app root.
Attacker Value
Unknown

CVE-2024-36132

Disclosure Date: August 07, 2024 (last updated August 13, 2024)
Insufficient verification of authentication controls in EPMM prior to 12.1.0.1 allows a remote attacker to bypass authentication and access sensitive resources.
Attacker Value
Unknown

CVE-2024-36131

Disclosure Date: August 07, 2024 (last updated August 13, 2024)
An insecure deserialization vulnerability in web component of EPMM prior to 12.1.0.1 allows an authenticated remote attacker to execute arbitrary commands on the underlying operating system of the appliance.
Attacker Value
Unknown

CVE-2024-36130

Disclosure Date: August 07, 2024 (last updated August 13, 2024)
An insufficient authorization vulnerability in web component of EPMM prior to 12.1.0.1 allows an unauthorized attacker within the network to execute arbitrary commands on the underlying operating system of the appliance.
Attacker Value
Unknown

CVE-2024-34788

Disclosure Date: August 07, 2024 (last updated August 13, 2024)
An improper authentication vulnerability in web component of EPMM prior to 12.1.0.1 allows a remote malicious user to access potentially sensitive information