Show filters
119 Total Results
Displaying 21-30 of 119
Sort by:
Attacker Value
Unknown

CVE-2024-36136

Disclosure Date: August 14, 2024 (last updated August 16, 2024)
An off-by-one error in WLInfoRailService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the service, resulting in a DoS.
Attacker Value
Unknown

CVE-2024-29848

Disclosure Date: May 31, 2024 (last updated June 01, 2024)
An unrestricted file upload vulnerability in web component of Ivanti Avalanche before 6.4.x allows an authenticated, privileged user to execute arbitrary commands as SYSTEM.
0
Attacker Value
Unknown

CVE-2024-23527

Disclosure Date: April 25, 2024 (last updated April 25, 2024)
An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information in memory.
0
Attacker Value
Unknown

CVE-2024-29204

Disclosure Date: April 19, 2024 (last updated April 19, 2024)
A Heap Overflow vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows a remote unauthenticated attacker to execute arbitrary commands
0
Attacker Value
Unknown

CVE-2024-27984

Disclosure Date: April 19, 2024 (last updated April 19, 2024)
A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to delete specific type of files and/or cause denial of service.
0
Attacker Value
Unknown

CVE-2024-27978

Disclosure Date: April 19, 2024 (last updated April 19, 2024)
A Null Pointer Dereference vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an authenticated remote attacker to perform denial of service attacks.
0
Attacker Value
Unknown

CVE-2024-27977

Disclosure Date: April 19, 2024 (last updated April 19, 2024)
A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to delete arbitrary files, thereby leading to Denial-of-Service.
0
Attacker Value
Unknown

CVE-2024-27976

Disclosure Date: April 19, 2024 (last updated April 19, 2024)
A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.
0
Attacker Value
Unknown

CVE-2024-27975

Disclosure Date: April 19, 2024 (last updated April 19, 2024)
An Use-after-free vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.
0
Attacker Value
Unknown

CVE-2024-25000

Disclosure Date: April 19, 2024 (last updated April 19, 2024)
A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.
0