Show filters
1,720 Total Results
Displaying 51-60 of 1,720
Sort by:
Attacker Value
Unknown

CVE-2024-39809

Disclosure Date: August 14, 2024 (last updated February 26, 2025)
The Central Manager user session refresh token does not expire when a user logs out.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
Attacker Value
Unknown

CVE-2024-0115

Disclosure Date: August 12, 2024 (last updated February 26, 2025)
NVIDIA CV-CUDA for Ubuntu 20.04, Ubuntu 22.04, and Jetpack contains a vulnerability in Python APIs where a user may cause an uncontrolled resource consumption issue by a long running CV-CUDA Python process. A successful exploit of this vulnerability may lead to denial of service and data loss.
Attacker Value
Unknown

CVE-2022-43855

Disclosure Date: March 08, 2024 (last updated February 26, 2025)
IBM SPSS Statistics 26.0, 27.0.1, and 28.0 could allow a local user to create multiple files that could exhaust the file handles capacity and cause a denial of service. IBM X-Force ID: 230235.
Attacker Value
Unknown

CVE-2023-6152

Disclosure Date: February 13, 2024 (last updated February 26, 2025)
A user changing their email after signing up and verifying it can change it without verification in profile settings. The configuration option "verify_email_enabled" will only validate email only on sign up.
Attacker Value
Unknown

CVE-2024-22361

Disclosure Date: February 10, 2024 (last updated February 26, 2025)
IBM Semeru Runtime 8.0.302.0 through 8.0.392.0, 11.0.12.0 through 11.0.21.0, 17.0.1.0 - 17.0.9.0, and 21.0.1.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 281222.
Attacker Value
Unknown

CVE-2024-0918

Disclosure Date: January 26, 2024 (last updated February 26, 2025)
A vulnerability was found in TRENDnet TEW-800MB 1.0.1.0 and classified as critical. Affected by this issue is some unknown functionality of the component POST Request Handler. The manipulation of the argument DeviceURL leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-252122 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Attacker Value
Unknown

CVE-2024-22192

Disclosure Date: January 16, 2024 (last updated February 26, 2025)
Ursa is a cryptographic library for use with blockchains. The revocation scheme that is part of the Ursa CL-Signatures implementations has a flaw that could impact the privacy guarantees defined by the AnonCreds verifiable credential model. Notably, a malicious verifier may be able to generate a unique identifier for a holder providing a verifiable presentation that includes a Non-Revocation proof. The impact of the flaw is that a malicious verifier may be able to determine a unique identifier for a holder presenting a Non-Revocation proof. Ursa has moved to end-of-life status and no fix is expected.
Attacker Value
Unknown

CVE-2024-21670

Disclosure Date: January 16, 2024 (last updated February 26, 2025)
Ursa is a cryptographic library for use with blockchains. The revocation schema that is part of the Ursa CL-Signatures implementations has a flaw that could impact the privacy guarantees defined by the AnonCreds verifiable credential model, allowing a malicious holder of a revoked credential to generate a valid Non-Revocation Proof for that credential as part of an AnonCreds presentation. A verifier may verify a credential from a holder as being "not revoked" when in fact, the holder's credential has been revoked. Ursa has moved to end-of-life status and no fix is expected.
Attacker Value
Unknown

CVE-2023-50706

Disclosure Date: December 20, 2023 (last updated February 25, 2025)
A user without administrator permissions with access to the UC500 windows system could perform a memory dump of the running processes and extract clear credentials or valid session tokens.
Attacker Value
Unknown

CVE-2023-50705

Disclosure Date: December 20, 2023 (last updated February 25, 2025)
An attacker could create malicious requests to obtain sensitive information about the web server.