Show filters
14,900 Total Results
Displaying 281-290 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown

CVE-2025-24836

Disclosure Date: February 13, 2025 (last updated February 27, 2025)
With a specially crafted Python script, an attacker could send continuous startMeasurement commands over an unencrypted Bluetooth connection to the affected device. This would prevent the device from connecting to a clinician's app to take patient readings and ostensibly flood it with requests, resulting in a denial-of-service condition.
0
Attacker Value
Unknown

CVE-2025-23421

Disclosure Date: February 13, 2025 (last updated February 27, 2025)
An attacker could obtain firmware files and reverse engineer their intended use leading to loss of confidentiality and integrity of the hardware devices enabled by the Qardio iOS and Android applications.
0
Attacker Value
Unknown

CVE-2025-20615

Disclosure Date: February 13, 2025 (last updated February 27, 2025)
The Qardio Arm iOS application exposes sensitive data such as usernames and passwords in a plist file. This allows an attacker to log in to production-level development accounts and access an engineering backdoor in the application. The engineering backdoor allows the attacker to send hex-based commands over a UI-based terminal.
0
Attacker Value
Unknown

CVE-2025-22480

Disclosure Date: February 13, 2025 (last updated February 27, 2025)
Dell SupportAssist OS Recovery versions prior to 5.5.13.1 contain a symbolic link attack vulnerability. A low-privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary file deletion and Elevation of Privileges.
Attacker Value
Unknown

CVE-2025-0327

Disclosure Date: February 13, 2025 (last updated February 27, 2025)
CWE-269: Improper Privilege Management vulnerability exists for two services (of which one managing audit trail data and the other acting as server managing client request) that could cause a loss of Confidentiality, Integrity and Availability of engineering workstation when an attacker with standard privilege modifies the executable path of the windows services. To be exploited, services need to be restarted.
0
Attacker Value
Unknown

CVE-2024-10083

Disclosure Date: February 13, 2025 (last updated February 27, 2025)
CWE-20: Improper Input Validation vulnerability exists that could cause denial of service of engineering workstation when specific driver interface is invoked locally by an authenticated user with crafted input.
0
Attacker Value
Unknown

CVE-2025-0896

Disclosure Date: February 13, 2025 (last updated February 27, 2025)
Orthanc server prior to version 1.5.8 does not enable basic authentication by default when remote access is enabled. This could result in unauthorized access by an attacker.
0
Attacker Value
Unknown

CVE-2024-42405

Disclosure Date: February 12, 2025 (last updated February 27, 2025)
Uncontrolled search path for some Intel(R) Quartus(R) Prime Software before version 23.1.1 Patch 1.01std may allow an authenticated user to potentially enable escalation of privilege via local access.
0
Attacker Value
Unknown

CVE-2024-36262

Disclosure Date: February 12, 2025 (last updated February 27, 2025)
Race condition in some Intel(R) System Security Report and System Resources Defense firmware may allow a privileged user to potentially enable escalation of privilege via local access.
0
Attacker Value
Unknown

CVE-2023-49618

Disclosure Date: February 12, 2025 (last updated February 27, 2025)
Improper buffer restrictions in some Intel(R) System Security Report and System Resources Defense firmware may allow a privileged user to potentially enable escalation of privilege via local access.
0