Show filters
1,987 Total Results
Displaying 241-250 of 1,987
Sort by:
Attacker Value
Unknown

CVE-2023-49122

Disclosure Date: January 09, 2024 (last updated February 25, 2025)
A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.
Attacker Value
Unknown

CVE-2023-49121

Disclosure Date: January 09, 2024 (last updated February 25, 2025)
A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 10). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.
Attacker Value
Unknown

CVE-2023-38126

Disclosure Date: December 19, 2023 (last updated February 25, 2025)
Softing edgeAggregator Restore Configuration Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Softing edgeAggregator. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of backup zip files. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this to execute code in the context of root. Was ZDI-CAN-20543.
Attacker Value
Unknown

CVE-2021-42797

Disclosure Date: December 16, 2023 (last updated February 25, 2025)
Path traversal vulnerability in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior allows an unauthenticated user to steal the Windows access token of the user account configured for accessing external DB resources.
Attacker Value
Unknown

CVE-2021-42796

Disclosure Date: December 16, 2023 (last updated February 25, 2025)
An issue was discovered in ExecuteCommand() in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior that allows unauthenticated arbitrary commands to be executed.
Attacker Value
Unknown

CVE-2021-42794

Disclosure Date: December 16, 2023 (last updated December 21, 2023)
An issue was discovered in AVEVA Edge (formerly InduSoft Web Studio) versions R2020 and prior. The application allows a client to provide a malicious connection string that could allow an adversary to port scan the LAN, depending on the hosts' responses.
Attacker Value
Unknown

CVE-2023-36878

Disclosure Date: December 15, 2023 (last updated January 12, 2025)
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Attacker Value
Unknown

CVE-2023-6702

Disclosure Date: December 14, 2023 (last updated February 25, 2025)
Type confusion in V8 in Google Chrome prior to 120.0.6099.109 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Attacker Value
Unknown

CVE-2023-32460

Disclosure Date: December 08, 2023 (last updated February 25, 2025)
Dell PowerEdge BIOS contains an improper privilege management security vulnerability. An unauthenticated local attacker could potentially exploit this vulnerability, leading to privilege escalation.
Attacker Value
Unknown

CVE-2023-38174

Disclosure Date: December 07, 2023 (last updated January 12, 2025)
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability