Show filters
662 Total Results
Displaying 231-240 of 662
Sort by:
Attacker Value
Unknown
CVE-2023-25771
Disclosure Date: May 10, 2023 (last updated February 24, 2025)
Improper access control for some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable denial of service via local access.
0
Attacker Value
Unknown
CVE-2022-36330
Disclosure Date: May 10, 2023 (last updated February 24, 2025)
A buffer overflow vulnerability was discovered on firmware version validation that could lead to an unauthenticated remote code execution in Western Digital My Cloud Home, My Cloud Home Duo and SanDisk ibi devices. An attacker would require exploitation of another vulnerability to raise their privileges in order to exploit this buffer overflow vulnerability.
This issue affects My Cloud Home and My Cloud Home Duo: before 9.4.0-191; ibi: before 9.4.0-191.
0
Attacker Value
Unknown
CVE-2023-22813
Disclosure Date: May 08, 2023 (last updated February 24, 2025)
A device API
endpoint was missing access controls on Western Digital My Cloud OS 5 iOS and Anroid Mobile Apps, My Cloud Home iOS and Android Mobile Apps, SanDisk ibi iOS and Android Mobile Apps, My Cloud OS 5 Web App, My Cloud Home Web App and the SanDisk ibi Web App. Due to a permissive CORS policy
and missing authentication requirement for private IPs, a remote attacker on
the same network as the device could obtain device information by convincing a
victim user to visit an attacker-controlled server and issue a cross-site
request.
This issue affects
My Cloud OS 5 Mobile App: before 4.21.0; My Cloud Home Mobile App: before 4.21.0; ibi Mobile App: before 4.21.0; My
Cloud OS 5 Web App: before 4.26.0-6126; My Cloud Home Web App: before 4.26.0-6126;
ibi Web App: before 4.26.0-6126.
0
Attacker Value
Unknown
CVE-2023-21666
Disclosure Date: May 02, 2023 (last updated February 24, 2025)
Memory Corruption in Graphics while accessing a buffer allocated through the graphics pool.
0
Attacker Value
Unknown
CVE-2023-29410
Disclosure Date: April 18, 2023 (last updated February 24, 2025)
A CWE-20: Improper Input Validation vulnerability exists that could allow an authenticated
attacker to gain the same privilege as the application on the server when a malicious payload is
provided over HTTP for the server to execute.
0
Attacker Value
Unknown
CVE-2022-43480
Disclosure Date: April 16, 2023 (last updated February 24, 2025)
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Magneticlab Sàrl Homepage Pop-up plugin <= 1.2.5 versions.
0
Attacker Value
Unknown
CVE-2022-40532
Disclosure Date: April 13, 2023 (last updated February 24, 2025)
Memory corruption due to integer overflow or wraparound in WLAN while sending WMI cmd from host to target.
0
Attacker Value
Unknown
CVE-2022-33291
Disclosure Date: April 13, 2023 (last updated February 24, 2025)
Information disclosure in Modem due to buffer over-read while receiving a IP header with malformed length.
0
Attacker Value
Unknown
CVE-2022-33287
Disclosure Date: April 13, 2023 (last updated February 24, 2025)
Information disclosure in Modem due to buffer over-read while getting length of Unfragmented headers in an IPv6 packet.
0
Attacker Value
Unknown
CVE-2022-33231
Disclosure Date: April 13, 2023 (last updated February 24, 2025)
Memory corruption due to double free in core while initializing the encryption key.
0