Show filters
155 Total Results
Displaying 51-60 of 155
Sort by:
Attacker Value
Unknown

CVE-2022-34884

Disclosure Date: January 30, 2023 (last updated October 08, 2023)
A buffer overflow exists in the Remote Presence subsystem which can potentially allow valid, authenticated users to cause a recoverable subsystem denial of service.
Attacker Value
Unknown

CVE-2022-38767

Disclosure Date: November 25, 2022 (last updated October 08, 2023)
An issue was discovered in Wind River VxWorks 6.9 and 7, that allows a specifically crafted packet sent by a Radius server, may cause Denial of Service during the IP Radius access procedure.
Attacker Value
Unknown

CVE-2022-20920

Disclosure Date: September 28, 2022 (last updated February 24, 2025)
A vulnerability in the SSH implementation of Cisco IOS Software and Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected device to reload. This vulnerability is due to improper handling of resources during an exceptional situation. An attacker could exploit this vulnerability by continuously connecting to an affected device and sending specific SSH requests. A successful exploit could allow the attacker to cause the affected device to reload.
Attacker Value
Unknown

CVE-2022-27176

Disclosure Date: June 14, 2022 (last updated February 23, 2025)
Incomplete filtering of special elements vulnerability exists in RevoWorks SCVX using 'File Sanitization Library' 1.043 and prior versions, RevoWorks Browser 2.2.67 and prior versions (when using 'File Sanitization Option'), and RevoWorks Desktop 2.1.84 and prior versions (when using 'File Sanitization Option'), which may allow an attacker to execute a malicious macro by having a user to download, import, and open a specially crafted file in the local environment.
Attacker Value
Unknown

CVE-2022-24382

Disclosure Date: May 12, 2022 (last updated February 23, 2025)
Improper input validation in firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access.
Attacker Value
Unknown

CVE-2022-24297

Disclosure Date: May 12, 2022 (last updated October 07, 2023)
Improper buffer restrictions in firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access.
Attacker Value
Unknown

CVE-2022-21237

Disclosure Date: May 12, 2022 (last updated February 23, 2025)
Improper buffer access in firmware for some Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access.
Attacker Value
Unknown

CVE-2021-3897

Disclosure Date: April 22, 2022 (last updated February 23, 2025)
An authentication bypass vulnerability was discovered in an internal service of the Lenovo Fan Power Controller2 (FPC2) and Lenovo System Management Module (SMM) firmware during an that could allow an unauthenticated attacker to execute commands on the SMM and FPC2. SMM2 is not affected.
Attacker Value
Unknown

CVE-2021-3849

Disclosure Date: April 22, 2022 (last updated February 23, 2025)
An authentication bypass vulnerability was discovered in the web interface of the Lenovo Fan Power Controller2 (FPC2) and Lenovo System Management Module (SMM) firmware that could allow an unauthenticated attacker to execute commands on the SMM and FPC2. SMM2 is not affected.
Attacker Value
Unknown

CVE-2022-23937

Disclosure Date: March 29, 2022 (last updated February 23, 2025)
In Wind River VxWorks 6.9 and 7, a specific crafted packet may lead to an out-of-bounds read during an IKE initial exchange scenario.