Show filters
292 Total Results
Displaying 31-40 of 292
Sort by:
Attacker Value
Unknown
CVE-2024-29133
Disclosure Date: March 21, 2024 (last updated February 14, 2025)
Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1.
Users are recommended to upgrade to version 2.10.1, which fixes the issue.
0
Attacker Value
Unknown
CVE-2024-29131
Disclosure Date: March 21, 2024 (last updated February 14, 2025)
Out-of-bounds Write vulnerability in Apache Commons Configuration.This issue affects Apache Commons Configuration: from 2.0 before 2.10.1.
Users are recommended to upgrade to version 2.10.1, which fixes the issue.
0
Attacker Value
Unknown
CVE-2023-28745
Disclosure Date: February 14, 2024 (last updated February 15, 2024)
Uncontrolled search path in Intel(R) QSFP+ Configuration Utility software, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.
0
Attacker Value
Unknown
CVE-2023-24591
Disclosure Date: February 14, 2024 (last updated October 30, 2024)
Uncontrolled search path in some Intel(R) Binary Configuration Tool software before version 3.4.4 may allow an authenticated user to potentially enable escalation of privilege via local access.
0
Attacker Value
Unknown
CVE-2024-23806
Disclosure Date: February 07, 2024 (last updated October 11, 2024)
Sensitive data can be extracted from HID iCLASS SE reader configuration cards. This could include credential and device administrator keys.
0
Attacker Value
Unknown
CVE-2023-47211
Disclosure Date: January 08, 2024 (last updated January 13, 2024)
A directory traversal vulnerability exists in the uploadMib functionality of ManageEngine OpManager 12.7.258. A specially crafted HTTP request can lead to arbitrary file creation. An attacker can send a malicious MiB file to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2023-35867
Disclosure Date: December 18, 2023 (last updated December 23, 2023)
An improper handling of a malformed API answer packets to API clients in Bosch BT software products can allow an unauthenticated attacker to cause a Denial of Service (DoS) situation. To exploit this vulnerability an attacker has to replace an existing API server e.g. through Man-in-the-Middle attacks.
0
Attacker Value
Unknown
CVE-2023-6105
Disclosure Date: November 15, 2023 (last updated February 14, 2025)
An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the user to access the ManageEngine product database.
0
Attacker Value
Unknown
CVE-2023-34997
Disclosure Date: November 14, 2023 (last updated November 22, 2023)
Insecure inherited permissions in the installer for some Intel Server Configuration Utility software before version 16.0.9 may allow an authenticated user to potentially enable escalation of privilege via local access.
0
Attacker Value
Unknown
CVE-2023-25075
Disclosure Date: November 14, 2023 (last updated November 29, 2023)
Unquoted search path in the installer for some Intel Server Configuration Utility software before version 16.0.9 may allow an authenticated user to potentially enable escalation of privilege via local access.
0