Show filters
162 Total Results
Displaying 41-50 of 162
Sort by:
Attacker Value
Unknown
CVE-2023-32155
Disclosure Date: May 03, 2024 (last updated September 18, 2024)
Tesla Model 3 bcmdhd Out-Of-Bounds Write Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected Tesla Model 3 vehicles. An attacker must first obtain the ability to execute code on the wifi subsystem in order to exploit this vulnerability.
The specific flaw exists within the bcmdhd driver. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of the kernel.
. Was ZDI-CAN-20733.
0
Attacker Value
Unknown
CVE-2024-1961
Disclosure Date: April 16, 2024 (last updated April 16, 2024)
vertaai/modeldb is vulnerable to a path traversal attack due to improper sanitization of user-supplied file paths in its file upload functionality. Attackers can exploit this vulnerability to write arbitrary files anywhere in the file system by manipulating the 'artifact_path' parameter. This flaw can lead to Remote Code Execution (RCE) by overwriting critical files, such as the application's configuration file, especially when the application is run outside of Docker. The vulnerability is present in the NFSController.java and NFSService.java components of the application.
0
Attacker Value
Unknown
CVE-2024-30559
Disclosure Date: March 31, 2024 (last updated January 05, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Maurice Spin 360 deg and 3D Model Viewer allows Stored XSS.This issue affects Spin 360 deg and 3D Model Viewer: from n/a through 1.2.7.
0
Attacker Value
Unknown
CVE-2024-2052
Disclosure Date: March 18, 2024 (last updated April 01, 2024)
CWE-552: Files or Directories Accessible to External Parties vulnerability exists that could allow
unauthenticated files and logs exfiltration and download of files when an attacker modifies the
URL to download to a different location.
0
Attacker Value
Unknown
CVE-2024-2051
Disclosure Date: March 18, 2024 (last updated April 01, 2024)
CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that
could cause account takeover and unauthorized access to the system when an attacker
conducts brute-force attacks against the login form.
0
Attacker Value
Unknown
CVE-2024-2050
Disclosure Date: March 18, 2024 (last updated April 01, 2024)
CWE-79: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)
vulnerability exists when an attacker injects then executes arbitrary malicious JavaScript code
within the context of the product.
0
Attacker Value
Unknown
CVE-2024-21643
Disclosure Date: January 10, 2024 (last updated January 20, 2024)
IdentityModel Extensions for .NET provide assemblies for web developers that wish to use federated identity providers for establishing the caller's identity. Anyone leveraging the `SignedHttpRequest`protocol or the `SignedHttpRequestValidator`is vulnerable. Microsoft.IdentityModel trusts the `jku`claim by default for the `SignedHttpRequest`protocol. This raises the possibility to make any remote or local `HTTP GET` request. The vulnerability has been fixed in Microsoft.IdentityModel.Protocols.SignedHttpRequest. Users should update all their Microsoft.IdentityModel versions to 7.1.2 (for 7x) or higher, 6.34.0 (for 6x) or higher.
0
Attacker Value
Unknown
CVE-2024-21319
Disclosure Date: January 09, 2024 (last updated January 12, 2025)
Microsoft Identity Denial of service vulnerability
0
Attacker Value
Unknown
CVE-2023-6023
Disclosure Date: November 16, 2023 (last updated November 29, 2023)
An attacker can read any file on the filesystem on the server hosting ModelDB through an LFI in the artifact_path URL parameter.
0
Attacker Value
Unknown
CVE-2023-31203
Disclosure Date: November 14, 2023 (last updated November 22, 2023)
Improper input validation in some OpenVINO Model Server software before version 2022.3 for Intel Distribution of OpenVINO toolkit may allow an unauthenticated user to potentially enable denial of service via network access.
0