Show filters
714 Total Results
Displaying 61-70 of 714
Sort by:
Attacker Value
Unknown

CVE-2024-22102

Disclosure Date: July 02, 2024 (last updated July 06, 2024)
Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.6.0 allows local attackers to cause a Windows blue screen error.
Attacker Value
Unknown

CVE-2023-51778

Disclosure Date: July 02, 2024 (last updated July 06, 2024)
Out-of-Bounds Write vulnerability in Jungo WinDriver before 12.1.0 allows local attackers to cause a Windows blue screen error and Denial of Service (DoS).
Attacker Value
Unknown

CVE-2023-51777

Disclosure Date: July 02, 2024 (last updated July 06, 2024)
Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.1.0 allows local attackers to cause a Windows blue screen error.
Attacker Value
Unknown

CVE-2023-51776

Disclosure Date: July 02, 2024 (last updated July 06, 2024)
Improper privilege management in Jungo WinDriver before 12.1.0 allows local attackers to escalate privileges and execute arbitrary code.
Attacker Value
Unknown

CVE-2024-37371

Disclosure Date: June 28, 2024 (last updated September 19, 2024)
In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can cause invalid memory reads during GSS message token handling by sending message tokens with invalid length fields.
Attacker Value
Unknown

CVE-2024-37370

Disclosure Date: June 28, 2024 (last updated August 28, 2024)
In MIT Kerberos 5 (aka krb5) before 1.21.3, an attacker can modify the plaintext Extra Count field of a confidential GSS krb5 wrap token, causing the unwrapped token to appear truncated to the application.
Attacker Value
Unknown

CVE-2024-38526

Disclosure Date: June 26, 2024 (last updated June 26, 2024)
pdoc provides API Documentation for Python Projects. Documentation generated with `pdoc --math` linked to JavaScript files from polyfill.io. The polyfill.io CDN has been sold and now serves malicious code. This issue has been fixed in pdoc 14.5.1.
0
Attacker Value
Unknown

CVE-2024-35665

Disclosure Date: June 11, 2024 (last updated June 12, 2024)
Missing Authorization vulnerability in namithjawahar Insert Post Ads.This issue affects Insert Post Ads: from n/a through 1.3.2.
0
Attacker Value
Unknown

CVE-2024-37570

Disclosure Date: June 09, 2024 (last updated June 13, 2024)
On Mitel 6869i 4.5.0.41 devices, the Manual Firmware Update (upgrade.html) page does not perform sanitization on the username and path parameters (sent by an authenticated user) before appending flags to the busybox ftpget command. This leads to $() command execution.
Attacker Value
Unknown

CVE-2024-37569

Disclosure Date: June 09, 2024 (last updated June 13, 2024)
An issue was discovered on Mitel 6869i through 4.5.0.41 and 5.x through 5.0.0.1018 devices. A command injection vulnerability exists in the hostname parameter taken in by the provis.html endpoint. The provis.html endpoint performs no sanitization on the hostname parameter (sent by an authenticated user), which is subsequently written to disk. During boot, the hostname parameter is executed as part of a series of shell commands. Attackers can achieve remote code execution in the root context by placing shell metacharacters in the hostname parameter.