Show filters
188 Total Results
Displaying 21-30 of 188
Sort by:
Attacker Value
Unknown

CVE-2024-27109

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
Insufficiently protected credentials in GE HealthCare EchoPAC products
0
Attacker Value
Unknown

CVE-2024-27108

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
Non privileged access to critical file vulnerability in GE HealthCare EchoPAC products
0
Attacker Value
Unknown

CVE-2024-27107

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
Weak account password in GE HealthCare EchoPAC products
0
Attacker Value
Unknown

CVE-2024-27106

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
Vulnerable data in transit in GE HealthCare EchoPAC products
0
Attacker Value
Unknown

CVE-2024-2877

Disclosure Date: April 30, 2024 (last updated May 01, 2024)
Vault Enterprise, when configured with performance standby nodes and a configured audit device, will inadvertently log request headers on the standby node. These logs may have included sensitive HTTP request information in cleartext. This vulnerability, CVE-2024-2877, was fixed in Vault Enterprise 1.15.8.
0
Attacker Value
Unknown

CVE-2024-28917

Disclosure Date: April 09, 2024 (last updated January 12, 2025)
Azure Arc-enabled Kubernetes Extension Cluster-Scope Elevation of Privilege Vulnerability
0
Attacker Value
Unknown

CVE-2024-2660

Disclosure Date: April 04, 2024 (last updated September 26, 2024)
Vault and Vault Enterprise TLS certificates auth method did not correctly validate OCSP responses when one or more OCSP sources were configured. This vulnerability, CVE-2024-2660, affects Vault and Vault Enterprise 1.14.0 and above, and is fixed in Vault 1.16.0 and Vault Enterprise 1.16.1, 1.15.7, and 1.14.11.
0
Attacker Value
Unknown

CVE-2024-2048

Disclosure Date: March 04, 2024 (last updated March 05, 2024)
Vault and Vault Enterprise (“Vault”) TLS certificate auth method did not correctly validate client certificates when configured with a non-CA certificate as trusted certificate. In this configuration, an attacker may be able to craft a malicious certificate that could be used to bypass authentication. Fixed in Vault 1.15.5 and 1.14.10.
0
Attacker Value
Unknown

CVE-2024-20911

Disclosure Date: February 17, 2024 (last updated December 21, 2024)
Vulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected are 20.1-20.9. Difficult to exploit vulnerability allows high privileged attacker with network access via Oracle Net to compromise Oracle Audit Vault and Database Firewall. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Audit Vault and Database Firewall, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Audit Vault and Database Firewall accessible data. CVSS 3.1 Base Score 2.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:N/A:N).
Attacker Value
Unknown

CVE-2024-20909

Disclosure Date: February 17, 2024 (last updated December 21, 2024)
Vulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected are 20.1-20.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Audit Vault and Database Firewall. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Audit Vault and Database Firewall accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).