Show filters
498 topics marked with the following tags:
Displaying 231-240 of 498
Sort by:
Attacker Value
High

CVE-2020-15588

Disclosure Date: July 29, 2020 (last updated October 07, 2023)
An issue was discovered in the client side of Zoho ManageEngine Desktop Central 10.0.552.W. An attacker-controlled server can trigger an integer overflow in InternetSendRequestEx and InternetSendRequestByBitrate that leads to a heap-based buffer overflow and Remote Code Execution with SYSTEM privileges. This issue will occur only when untrusted communication is initiated with server. In cloud, Agent will always connect with trusted communication.
Attacker Value
Very High

CVE-2021-30807

Disclosure Date: October 19, 2021 (last updated October 07, 2023)
A memory corruption issue was addressed with improved memory handling. This issue is fixed in macOS Big Sur 11.5.1, iOS 14.7.1 and iPadOS 14.7.1, watchOS 7.6.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited.
Attacker Value
High

CVE-2023-21768

Disclosure Date: January 10, 2023 (last updated October 08, 2023)
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Attacker Value
Very High
It was found that the fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient. An attacker could use a path traversal attack to map URLs to files outside the directories configured by Alias-like directives. If files outside of these directories are not protected by the usual default configuration "require all denied", these requests can succeed. If CGI scripts are also enabled for these aliased pathes, this could allow for remote code execution. This issue only affects Apache 2.4.49 and Apache 2.4.50 and not earlier versions. https://blog.talosintelligence.com/2021/10/apache-vuln-threat-advisory.html
3
Attacker Value
Very High

CVE-2019-7252

Disclosure Date: July 02, 2019 (last updated October 06, 2023)
Linear eMerge E3-Series devices have Default Credentials.
Attacker Value
Very High

CVE-2023-29357

Disclosure Date: June 14, 2023 (last updated October 08, 2023)
Microsoft SharePoint Server Elevation of Privilege Vulnerability
Attacker Value
High

CVE-2021-3560

Disclosure Date: February 16, 2022 (last updated October 07, 2023)
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privileges of the requestor to the root user. This flaw could be used by an unprivileged local attacker to, for example, create a new local administrator. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Attacker Value
High

CVE-2017-12542

Disclosure Date: February 15, 2018 (last updated October 06, 2023)
A authentication bypass and execution of code vulnerability in HPE Integrated Lights-out 4 (iLO 4) version prior to 2.53 was found.
Attacker Value
Very High

CVE-2020-24590

Disclosure Date: August 21, 2020 (last updated October 07, 2023)
The Management Console in WSO2 API Manager through 3.1.0 and API Microgateway 2.2.0 allows XML Entity Expansion attacks.
Attacker Value
Very High

CVE-2014-3074

Disclosure Date: July 02, 2014 (last updated October 05, 2023)
The runtime linker in IBM AIX 6.1 and 7.1 and VIOS 2.2.x allows local users to create a mode-666 root-owned file, and consequently gain privileges, by setting crafted MALLOCOPTIONS and MALLOCBUCKETS environment-variable values and then executing a setuid program.
1