Show filters
508 Total Results
Displaying 31-40 of 508
Sort by:
Attacker Value
Unknown
CVE-2024-47536
Disclosure Date: September 30, 2024 (last updated October 01, 2024)
Citizen is a MediaWiki skin that makes extensions part of the cohesive experience. A user with the editmyprivateinfo right or who can otherwise change their name can XSS themselves by setting their "real name" to an XSS payload. This vulnerability is fixed in 2.31.0.
0
Attacker Value
Unknown
CVE-2024-39584
Disclosure Date: August 28, 2024 (last updated December 21, 2024)
Dell Client Platform BIOS contains a Use of Default Cryptographic Key Vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Secure Boot bypass and arbitrary code execution.
0
Attacker Value
Unknown
CVE-2024-5762
Disclosure Date: August 21, 2024 (last updated August 24, 2024)
Zen Cart findPluginAdminPage Local File Inclusion Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Zen Cart. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the findPluginAdminPage function. The issue results from the lack of proper validation of user-supplied data prior to passing it to a PHP include function. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the service account. Was ZDI-CAN-21408.
0
Attacker Value
Unknown
CVE-2024-21981
Disclosure Date: August 13, 2024 (last updated August 14, 2024)
Improper key usage control in AMD Secure Processor
(ASP) may allow an attacker with local access who has gained arbitrary code
execution privilege in ASP to
extract ASP cryptographic keys, potentially resulting in loss of
confidentiality and integrity.
0
Attacker Value
Unknown
CVE-2023-20518
Disclosure Date: August 13, 2024 (last updated August 14, 2024)
Incomplete cleanup in the ASP may expose the Master Encryption Key (MEK) to a privileged attacker with access to the BIOS menu or UEFI shell and a memory exfiltration vulnerability, potentially resulting in loss of confidentiality.
0
Attacker Value
Unknown
CVE-2022-23817
Disclosure Date: August 13, 2024 (last updated August 14, 2024)
Insufficient checking of memory buffer in ASP Secure OS may allow an attacker with a malicious TA to read/write to the ASP Secure OS kernel virtual address space, potentially leading to privilege escalation.
0
Attacker Value
Unknown
CVE-2022-23815
Disclosure Date: August 13, 2024 (last updated December 18, 2024)
Improper bounds checking in APCB firmware may allow an attacker to perform an out of bounds write, corrupting the APCB entry, potentially leading to arbitrary code execution.
0
Attacker Value
Unknown
CVE-2021-46772
Disclosure Date: August 13, 2024 (last updated August 14, 2024)
Insufficient input validation in the ABL may allow a privileged
attacker with access to the BIOS menu or UEFI shell to tamper with the
structure headers in SPI ROM causing an out of bounds memory read and write,
potentially resulting in memory corruption or denial of service.
0
Attacker Value
Unknown
CVE-2021-46746
Disclosure Date: August 13, 2024 (last updated August 14, 2024)
Lack of stack protection exploit mechanisms in ASP Secure OS Trusted Execution Environment (TEE) may allow a privileged attacker with access to AMD signing
keys to c006Frrupt the return address, causing a
stack-based buffer overrun, potentially leading to a denial of service.
0
Attacker Value
Unknown
CVE-2021-26387
Disclosure Date: August 13, 2024 (last updated August 14, 2024)
Insufficient access controls in ASP kernel may allow a
privileged attacker with access to AMD signing keys and the BIOS menu or UEFI
shell to map DRAM regions in protected areas, potentially leading to a loss of platform integrity.
0