Show filters
1,948 Total Results
Displaying 231-240 of 1,948
Sort by:
Attacker Value
Unknown

CVE-2024-21864

Disclosure Date: May 16, 2024 (last updated February 26, 2025)
Improper neutralization in some Intel(R) Arc(TM) & Iris(R) Xe Graphics software before version 31.0.101.5081 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent network access.
0
Attacker Value
Unknown

CVE-2023-5938

Disclosure Date: May 15, 2024 (last updated February 26, 2025)
Multiple functions use archives without properly validating the filenames therein, rendering the application vulnerable to path traversal via 'zip slip' attacks. An administrator able to provide tampered archives to be processed by the affected versions of Arc may be able to have arbitrary files extracted to arbitrary filesystem locations. Leveraging this issue, an attacker may be able to overwrite arbitrary files on the target filesystem and cause critical impacts on the system (e.g., arbitrary command execution on the victim’s machine).
0
Attacker Value
Unknown

CVE-2023-5937

Disclosure Date: May 15, 2024 (last updated February 26, 2025)
On Windows systems, the Arc configuration files resulted to be world-readable. This can lead to information disclosure by local attackers, via exfiltration of sensitive data from configuration files.
0
Attacker Value
Unknown

CVE-2023-5936

Disclosure Date: May 15, 2024 (last updated February 26, 2025)
On Unix systems (Linux, MacOS), Arc uses a temporary file with unsafe privileges. By tampering with such file, a malicious local user in the system may be able to trigger arbitrary code execution with root privileges.
0
Attacker Value
Unknown

CVE-2023-5935

Disclosure Date: May 15, 2024 (last updated February 26, 2025)
When configuring Arc (e.g. during the first setup), a local web interface is provided to ease the configuration process. Such web interface lacks authentication and may thus be abused by a local attacker or malware running on the machine itself. A malicious local user or process, during a window of opportunity when the local web interface is active, may be able to extract sensitive information or change Arc's configuration. This could also lead to arbitrary code execution if a malicious update package is installed.
0
Attacker Value
Unknown

CVE-2024-30041

Disclosure Date: May 14, 2024 (last updated February 26, 2025)
Microsoft Bing Search Spoofing Vulnerability
Attacker Value
Unknown

CVE-2024-34557

Disclosure Date: May 14, 2024 (last updated February 26, 2025)
Cross-Site Request Forgery (CSRF) vulnerability in UkrSolution Barcode Scanner with Inventory & Order Manager.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through 1.5.4.
0
Attacker Value
Unknown

CVE-2024-34556

Disclosure Date: May 14, 2024 (last updated February 26, 2025)
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in UkrSolution Barcode Scanner with Inventory & Order Manager.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through 1.5.4.
0
Attacker Value
Unknown

CVE-2024-34418

Disclosure Date: May 14, 2024 (last updated February 26, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tech9logy Creators WPCS ( WordPress Custom Search ) allows Stored XSS.This issue affects WPCS ( WordPress Custom Search ): from n/a through 1.1.
0
Attacker Value
Unknown

CVE-2024-33950

Disclosure Date: May 14, 2024 (last updated February 26, 2025)
Administrator Cross Site Scripting (XSS) in Archives Calendar Widget <= 1.0.15 versions.
0