Show filters
309 Total Results
Displaying 31-40 of 309
Sort by:
Attacker Value
Unknown

CVE-2023-51385

Disclosure Date: December 18, 2023 (last updated January 04, 2024)
In ssh in OpenSSH before 9.6, OS command injection might occur if a user name or host name has shell metacharacters, and this name is referenced by an expansion token in certain situations. For example, an untrusted Git repository can have a submodule with shell metacharacters in a user name or host name.
Attacker Value
Unknown

CVE-2023-51384

Disclosure Date: December 18, 2023 (last updated May 17, 2024)
In ssh-agent in OpenSSH before 9.6, certain destination constraints can be incompletely applied. When destination constraints are specified during addition of PKCS#11-hosted private keys, these constraints are only applied to the first key, even if a PKCS#11 token returns multiple keys.
Attacker Value
Unknown

CVE-2023-33413

Disclosure Date: December 07, 2023 (last updated December 14, 2023)
The configuration functionality in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions through 3.17.02, allows remote authenticated users to execute arbitrary commands.
Attacker Value
Unknown

CVE-2023-33412

Disclosure Date: December 07, 2023 (last updated December 14, 2023)
The web interface in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions before 3.17.02, allows remote authenticated users to execute arbitrary commands via a crafted request targeting vulnerable cgi endpoints.
Attacker Value
Unknown

CVE-2023-33411

Disclosure Date: December 07, 2023 (last updated December 13, 2023)
A web server in the Intelligent Platform Management Interface (IPMI) baseboard management controller (BMC) implementation on Supermicro X11 and M11 based devices, with firmware versions up to 3.17.02, allows remote unauthenticated users to perform directory traversal, potentially disclosing sensitive information.
Attacker Value
Unknown

CVE-2023-46446

Disclosure Date: November 14, 2023 (last updated December 18, 2023)
An issue in AsyncSSH before 2.14.1 allows attackers to control the remote end of an SSH client session via packet injection/removal and shell emulation, aka a "Rogue Session Attack."
Attacker Value
Unknown

CVE-2023-46445

Disclosure Date: November 14, 2023 (last updated December 18, 2023)
An issue in AsyncSSH before 2.14.1 allows attackers to control the extension info message (RFC 8308) via a man-in-the-middle attack, aka a "Rogue Extension Negotiation."
Attacker Value
Unknown

CVE-2023-41939

Disclosure Date: September 06, 2023 (last updated October 08, 2023)
Jenkins SSH2 Easy Plugin 1.4 and earlier does not verify that permissions configured to be granted are enabled, potentially allowing users formerly granted (typically optional permissions, like Overall/Manage) to access functionality they're no longer entitled to.
Attacker Value
Unknown

CVE-2023-34853

Disclosure Date: August 22, 2023 (last updated October 08, 2023)
Buffer Overflow vulnerability in Supermicro motherboard X12DPG-QR 1.4b allows local attackers to hijack control flow via manipulation of SmcSecurityEraseSetupVar variable.
Attacker Value
Unknown

CVE-2020-22218

Disclosure Date: August 22, 2023 (last updated October 08, 2023)
An issue was discovered in function _libssh2_packet_add in libssh2 1.10.0 allows attackers to access out of bounds memory.