Show filters
998 Total Results
Displaying 41-50 of 998
Sort by:
Attacker Value
Unknown

CVE-2024-34113

Disclosure Date: June 13, 2024 (last updated August 08, 2024)
ColdFusion versions 2023u7, 2021u13 and earlier are affected by a Weak Cryptography for Passwords vulnerability that could result in a security feature bypass. This vulnerability arises due to the use of insufficiently strong cryptographic algorithms or flawed implementation that compromises the confidentiality of password data. An attacker could exploit this weakness to decrypt or guess passwords, potentially gaining unauthorized access to protected resources. Exploitation of this issue does not require user interaction.
Attacker Value
Unknown

CVE-2024-34112

Disclosure Date: June 13, 2024 (last updated December 21, 2024)
ColdFusion versions 2023u7, 2021u13 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could exploit this vulnerability to gain unauthorized access to sensitive files or data. Exploitation of this issue does not require user interaction.
Attacker Value
Unknown

CVE-2024-22273

Disclosure Date: May 21, 2024 (last updated May 22, 2024)
The storage controllers on VMware ESXi, Workstation, and Fusion have out-of-bounds read/write vulnerability. A malicious actor with access to a virtual machine with storage controllers enabled may exploit this issue to create a denial of service condition or execute code on the hypervisor from a virtual machine in conjunction with other issues.
0
Attacker Value
Unknown

CVE-2024-22270

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
VMware Workstation and Fusion contain an information disclosure vulnerability in the Host Guest File Sharing (HGFS) functionality. A malicious actor with local administrative privileges on a virtual machine may be able to read privileged information contained in hypervisor memory from a virtual machine.
0
Attacker Value
Unknown

CVE-2024-22269

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
VMware Workstation and Fusion contain an information disclosure vulnerability in the vbluetooth device. A malicious actor with local administrative privileges on a virtual machine may be able to read privileged information contained in hypervisor memory from a virtual machine.
0
Attacker Value
Unknown

CVE-2024-22268

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
VMware Workstation and Fusion contain a heap buffer-overflow vulnerability in the Shader functionality. A malicious actor with non-administrative access to a virtual machine with 3D graphics enabled may be able to exploit this vulnerability to create a denial of service condition.
0
Attacker Value
Unknown

CVE-2023-43040

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
IBM Spectrum Fusion HCI 2.5.2 through 2.7.2 could allow an attacker to perform unauthorized actions in RGW for Ceph due to improper bucket access. IBM X-Force ID: 266807.
0
Attacker Value
Unknown

CVE-2024-32796

Disclosure Date: April 24, 2024 (last updated April 24, 2024)
Insertion of Sensitive Information into Log File vulnerability in Very Good Plugins WP Fusion Lite.This issue affects WP Fusion Lite: from n/a through 3.42.10.
0
Attacker Value
Unknown

CVE-2024-31462

Disclosure Date: April 12, 2024 (last updated April 13, 2024)
stable-diffusion-webui is a web interface for Stable Diffusion, implemented using Gradio library. Stable-diffusion-webui 1.7.0 is vulnerable to a limited file write affecting Windows systems. The create_ui method (Backup/Restore tab) in modules/ui_extensions.py takes user input into the config_save_name variable on line 653. This user input is later used in the save_config_state method and used to create a file path on line 65, which is afterwards opened for writing on line 67, which leads to a limited file write exploitable on Windows systems. This issue may lead to limited file write. It allows for writing json files anywhere on the server where the web server has access.
0
Attacker Value
Unknown

CVE-2024-27972

Disclosure Date: April 03, 2024 (last updated April 04, 2024)
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Very Good Plugins WP Fusion Lite allows Command Injection.This issue affects WP Fusion Lite: from n/a through 3.41.24.
0