Show filters
1,065 Total Results
Displaying 41-50 of 1,065
Sort by:
Attacker Value
Unknown

CVE-2024-48930

Disclosure Date: October 21, 2024 (last updated February 26, 2025)
secp256k1-node is a Node.js binding for an Optimized C library for EC operations on curve secp256k1. In `elliptic`-based version, `loadUncompressedPublicKey` has a check that the public key is on the curve. Prior to versions 5.0.1, 4.0.4, and 3.8.1, however, `loadCompressedPublicKey` is missing that check. That allows the attacker to use public keys on low-cardinality curves to extract enough information to fully restore the private key from as little as 11 ECDH sessions, and very cheaply on compute power. Other operations on public keys are also affected, including e.g. `publicKeyVerify()` incorrectly returning `true` on those invalid keys, and e.g. `publicKeyTweakMul()` also returning predictable outcomes allowing to restore the tweak. Versions 5.0.1, 4.0.4, and 3.8.1 contain a fix for the issue.
0
Attacker Value
Unknown

CVE-2024-8281

Disclosure Date: September 13, 2024 (last updated February 26, 2025)
An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection through specially crafted command line input in the XCC SSH captive shell.
0
Attacker Value
Unknown

CVE-2024-8280

Disclosure Date: September 13, 2024 (last updated February 26, 2025)
An input validation weakness was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection or cause a recoverable denial of service using a specially crafted file.
0
Attacker Value
Unknown

CVE-2024-8279

Disclosure Date: September 13, 2024 (last updated February 26, 2025)
A privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection via specially crafted file uploads.
0
Attacker Value
Unknown

CVE-2024-8278

Disclosure Date: September 13, 2024 (last updated February 26, 2025)
A privilege escalation vulnerability was discovered in XCC that could allow a valid, authenticated XCC user with elevated privileges to perform command injection via specially crafted IPMI commands.
0
Attacker Value
Unknown

CVE-2024-8059

Disclosure Date: September 13, 2024 (last updated February 26, 2025)
IPMI credentials may be captured in XCC audit log entries when the account username length is 16 characters.
Attacker Value
Unknown

CVE-2024-45105

Disclosure Date: September 13, 2024 (last updated February 26, 2025)
An internal product security audit discovered a UEFI SMM (System Management Mode) callout vulnerability in some ThinkSystem servers that could allow a local attacker with elevated privileges to execute arbitrary code.
0
Attacker Value
Unknown

CVE-2024-21528

Disclosure Date: September 10, 2024 (last updated February 26, 2025)
All versions of the package node-gettext are vulnerable to Prototype Pollution via the addTranslations() function in gettext.js due to improper user input sanitization.
0
Attacker Value
Unknown

CVE-2024-36138

Disclosure Date: September 07, 2024 (last updated February 26, 2025)
Bypass incomplete fix of CVE-2024-27980, that arises from improper handling of batch files with all possible extensions on Windows via child_process.spawn / child_process.spawnSync. A malicious command line argument can inject arbitrary commands and achieve code execution even if the shell option is not enabled.
0
Attacker Value
Unknown

CVE-2024-36137

Disclosure Date: September 07, 2024 (last updated September 08, 2024)
A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-write flag is used. Node.js Permission Model do not operate on file descriptors, however, operations such as fs.fchown or fs.fchmod can use a "read-only" file descriptor to change the owner and permissions of a file.
0