Show filters
2,038 Total Results
Displaying 61-70 of 2,038
Sort by:
Attacker Value
Unknown

CVE-2025-20128

Disclosure Date: January 22, 2025 (last updated February 19, 2025)
A vulnerability in the Object Linking and Embedding 2 (OLE2) decryption routine of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to an integer underflow in a bounds check that allows for a heap buffer overflow read. An attacker could exploit this vulnerability by submitting a crafted file containing OLE2 content to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to terminate the ClamAV scanning process, resulting in a DoS condition on the affected software. For a description of this vulnerability, see the . Cisco has released software updates that address this vulnerability. There are no workarounds that address this vulnerability.
0
Attacker Value
Unknown

CVE-2025-23672

Disclosure Date: January 22, 2025 (last updated January 23, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NotFound Instant Appointment allows Reflected XSS. This issue affects Instant Appointment: from n/a through 1.2.
0
Attacker Value
Unknown

CVE-2025-22719

Disclosure Date: January 21, 2025 (last updated January 22, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in E4J s.r.l. VikAppointments Services Booking Calendar allows Stored XSS. This issue affects VikAppointments Services Booking Calendar: from n/a through 1.2.16.
0
Attacker Value
Unknown

CVE-2025-21393

Disclosure Date: January 14, 2025 (last updated January 18, 2025)
Microsoft SharePoint Server Spoofing Vulnerability
Attacker Value
Unknown

CVE-2025-21348

Disclosure Date: January 14, 2025 (last updated January 22, 2025)
Microsoft SharePoint Server Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2025-21344

Disclosure Date: January 14, 2025 (last updated January 22, 2025)
Microsoft SharePoint Server Remote Code Execution Vulnerability
Attacker Value
Unknown

CVE-2024-13172

Disclosure Date: January 14, 2025 (last updated January 15, 2025)
Improper signature verification in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve remote code execution. Local user interaction is required.
0
Attacker Value
Unknown

CVE-2024-13171

Disclosure Date: January 14, 2025 (last updated January 15, 2025)
Insufficient filename validation in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve remote code execution. Local user interaction is required.
0
Attacker Value
Unknown

CVE-2024-13170

Disclosure Date: January 14, 2025 (last updated January 15, 2025)
An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.
0
Attacker Value
Unknown

CVE-2024-13169

Disclosure Date: January 14, 2025 (last updated January 15, 2025)
An out-of-bounds read in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a local authenticated attacker to escalate their privileges.
0