Show filters
1,218 Total Results
Displaying 31-40 of 1,218
Sort by:
Attacker Value
Unknown

CVE-2024-47475

Disclosure Date: January 06, 2025 (last updated January 13, 2025)
Dell PowerScale OneFS 8.2.2.x through 9.8.0.x contains an incorrect permission assignment for critical resource vulnerability. A locally authenticated attacker could potentially exploit this vulnerability, leading to denial of service.
Attacker Value
Unknown

CVE-2024-51540

Disclosure Date: December 26, 2024 (last updated January 22, 2025)
Dell ECS, versions prior to 3.8.1.3 contains an arithmetic overflow vulnerability exists in retention period handling of ECS. An authenticated user with bucket or object-level access and the necessary privileges could potentially exploit this vulnerability to bypass retention policies and delete objects.
Attacker Value
Unknown

CVE-2024-52543

Disclosure Date: December 25, 2024 (last updated January 30, 2025)
Dell NativeEdge, version(s) 2.1.0.0, contain(s) a Creation of Temporary File With Insecure Permissions vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
Attacker Value
Unknown

CVE-2024-52534

Disclosure Date: December 25, 2024 (last updated January 22, 2025)
Dell ECS, version(s) prior to ECS 3.8.1.3, contain(s) an Authentication Bypass by Capture-replay vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Session theft.
Attacker Value
Unknown

CVE-2024-53291

Disclosure Date: December 25, 2024 (last updated January 30, 2025)
Dell NativeEdge, version(s) 2.1.0.0, contain(s) an Exposure of Sensitive Information Through Metadata vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure.
Attacker Value
Unknown

CVE-2024-52535

Disclosure Date: December 25, 2024 (last updated January 30, 2025)
Dell SupportAssist for Home PCs versions 4.6.1 and prior and Dell SupportAssist for Business PCs versions 4.5.0 and prior, contain a symbolic link (symlink) attack vulnerability in the software remediation component. A low-privileged authenticated user could potentially exploit this vulnerability, gaining privileges escalation, leading to arbitrary deletion of files and folders from the system.
Attacker Value
Unknown

CVE-2024-47978

Disclosure Date: December 25, 2024 (last updated January 30, 2025)
Dell NativeEdge, version(s) 2.1.0.0, contain(s) an Execution with Unnecessary Privileges vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.
Attacker Value
Unknown

CVE-2024-51532

Disclosure Date: December 19, 2024 (last updated January 30, 2025)
Dell PowerStore contains an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to modification of arbitrary system files.
Attacker Value
Unknown

CVE-2024-47480

Disclosure Date: December 18, 2024 (last updated February 05, 2025)
Dell Inventory Collector Client, versions prior to 12.7.0, contains an Improper Link Resolution Before File Access vulnerability. A low-privilege attacker with local access may exploit this vulnerability, potentially resulting in Elevation of Privileges and unauthorized file system access.
Attacker Value
Unknown

CVE-2024-52542

Disclosure Date: December 17, 2024 (last updated February 05, 2025)
Dell AppSync, version 4.6.0.x, contain a Symbolic Link (Symlink) Following vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to information tampering.