Show filters
794 Total Results
Displaying 61-70 of 794
Sort by:
Attacker Value
Unknown

CVE-2024-7347

Disclosure Date: August 14, 2024 (last updated January 23, 2025)
NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_mp4_module, which might allow an attacker to over-read NGINX worker memory resulting in its termination, using a specially crafted mp4 file. The issue only affects NGINX if it is built with the ngx_http_mp4_module and the mp4 directive is used in the configuration file. Additionally, the attack is possible only if an attacker can trigger the processing of a specially crafted mp4 file with the ngx_http_mp4_module.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Attacker Value
Unknown

CVE-2024-39792

Disclosure Date: August 14, 2024 (last updated August 20, 2024)
When the NGINX Plus is configured to use the MQTT pre-read module, undisclosed requests can cause an increase in memory resource utilization.  Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Attacker Value
Unknown

CVE-2024-41908

Disclosure Date: August 13, 2024 (last updated August 13, 2024)
A vulnerability has been identified in NX (All versions < V2406.3000). The affected applications contains an out of bounds read vulnerability while parsing specially crafted PRT files. This could allow an attacker to crash the application or execute code in the context of the current process.
0
Attacker Value
Unknown

CVE-2024-0113

Disclosure Date: August 12, 2024 (last updated January 05, 2025)
NVIDIA Mellanox OS, ONYX, Skyway, and MetroX-3 XCC contain a vulnerability in the web support, where an attacker can cause a CGI path traversal by a specially crafted URI. A successful exploit of this vulnerability might lead to escalation of privileges and information disclosure.
Attacker Value
Unknown

CVE-2024-0104

Disclosure Date: August 08, 2024 (last updated January 05, 2025)
NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in the LDAP AAA component, where a user can cause improper access. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and escalation of privileges.
Attacker Value
Unknown

CVE-2024-0101

Disclosure Date: August 08, 2024 (last updated January 05, 2025)
NVIDIA Mellanox OS, ONYX, Skyway, MetroX-2 and MetroX-3 XC contain a vulnerability in ipfilter, where improper ipfilter definitions could enable an attacker to cause a failure by attacking the switch. A successful exploit of this vulnerability might lead to denial of service.
Attacker Value
Unknown

CVE-2024-36491

Disclosure Date: July 17, 2024 (last updated September 28, 2024)
FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. allow a remote unauthenticated attacker to execute an arbitrary OS command, obtain and/or alter sensitive information, and be able to cause a denial of service (DoS) condition.
Attacker Value
Unknown

CVE-2024-36475

Disclosure Date: July 17, 2024 (last updated September 28, 2024)
FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. contain an active debug code vulnerability. If a user who knows how to use the debug function logs in to the product, the debug function may be used and an arbitrary OS command may be executed.
Attacker Value
Unknown

CVE-2024-31070

Disclosure Date: July 17, 2024 (last updated September 28, 2024)
Initialization of a resource with an insecure default vulnerability in FutureNet NXR series, VXR series and WXR series provided by Century Systems Co., Ltd. allows a remote unauthenticated attacker to access telnet service unlimitedly.
Attacker Value
Unknown

CVE-2024-33687

Disclosure Date: June 24, 2024 (last updated June 27, 2024)
Insufficient verification of data authenticity issue exists in NJ Series CPU Unit all versions and NX Series CPU Unit all versions. If a user program in the affected product is altered, the product may not be able to detect the alteration.