Show filters
242 Total Results
Displaying 21-30 of 242
Sort by:
Attacker Value
Low
CVE-2020-15408
Disclosure Date: July 28, 2020 (last updated November 28, 2024)
An issue was discovered in Pulse Secure Pulse Connect Secure before 9.1R8. An authenticated attacker can access the admin page console via the end-user web interface because of a rewrite.
0
Attacker Value
Unknown
CVE-2018-16890
Disclosure Date: February 06, 2019 (last updated November 08, 2023)
libcurl versions from 7.36.0 to before 7.64.0 is vulnerable to a heap buffer out-of-bounds read. The function handling incoming NTLM type-2 messages (`lib/vauth/ntlm.c:ntlm_decode_type2_target`) does not validate incoming data correctly and is subject to an integer overflow vulnerability. Using that overflow, a malicious or broken NTLM server could trick libcurl to accept a bad length + offset combination that would lead to a buffer read out-of-bounds.
1
Attacker Value
Unknown
CVE-2024-38657
Disclosure Date: February 21, 2025 (last updated February 23, 2025)
External control of a file name in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to write arbitrary files.
0
Attacker Value
Unknown
CVE-2025-22467
Disclosure Date: February 11, 2025 (last updated February 21, 2025)
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6 allows a remote authenticated attacker to achieve remote code execution.
0
Attacker Value
Unknown
CVE-2024-13843
Disclosure Date: February 11, 2025 (last updated February 21, 2025)
Cleartext storage of information in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a local authenticated attacker with admin privileges to read sensitive data.
0
Attacker Value
Unknown
CVE-2024-13842
Disclosure Date: February 11, 2025 (last updated February 21, 2025)
A hardcoded key in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.3 allows a local authenticated attacker with admin privileges to read sensitive data.
0
Attacker Value
Unknown
CVE-2024-13830
Disclosure Date: February 11, 2025 (last updated February 14, 2025)
Reflected XSS in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a remote unauthenticated attacker to obtain admin privileges. User interaction is required.
0
Attacker Value
Unknown
CVE-2024-12058
Disclosure Date: February 11, 2025 (last updated February 12, 2025)
External control of a file name in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to read arbitrary files.
0
Attacker Value
Unknown
CVE-2024-10644
Disclosure Date: February 11, 2025 (last updated February 12, 2025)
Code injection in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
0
Attacker Value
Unknown
CVE-2025-0283
Disclosure Date: January 08, 2025 (last updated January 15, 2025)
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a local authenticated attacker to escalate their privileges.
0