Show filters
1,462 Total Results
Displaying 71-80 of 1,462
Sort by:
Attacker Value
Unknown
CVE-2024-37398
Disclosure Date: November 13, 2024 (last updated November 19, 2024)
Insufficient validation in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.
0
Attacker Value
Unknown
CVE-2024-29211
Disclosure Date: November 13, 2024 (last updated November 15, 2024)
A race condition in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to modify sensitive configuration files.
0
Attacker Value
Unknown
CVE-2024-40592
Disclosure Date: November 12, 2024 (last updated November 15, 2024)
An improper verification of cryptographic signature vulnerability [CWE-347] in FortiClient MacOS version 7.4.0, version 7.2.4 and below, version 7.0.10 and below, version 6.4.10 and below may allow a local authenticated attacker to swap the installer with a malicious package via a race condition during the installation process.
0
Attacker Value
Unknown
CVE-2024-36513
Disclosure Date: November 12, 2024 (last updated November 15, 2024)
A privilege context switching error vulnerability [CWE-270] in FortiClient Windows version 7.2.4 and below, version 7.0.12 and below, 6.4 all versions may allow an authenticated user to escalate their privileges via lua auto patch scripts.
0
Attacker Value
Unknown
CVE-2024-36507
Disclosure Date: November 12, 2024 (last updated November 15, 2024)
A untrusted search path in Fortinet FortiClientWindows versions 7.4.0, versions 7.2.4 through 7.2.0, versions 7.0.12 through 7.0.0 allows an attacker to run arbitrary code via DLL hijacking and social engineering.
0
Attacker Value
Unknown
CVE-2024-9843
Disclosure Date: November 12, 2024 (last updated January 18, 2025)
A buffer over-read in Ivanti Secure Access Client before 22.7R4 allows a local unauthenticated attacker to cause a denial of service.
0
Attacker Value
Unknown
CVE-2024-9842
Disclosure Date: November 12, 2024 (last updated January 18, 2025)
Incorrect permissions in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to create arbitrary folders.
0
Attacker Value
Unknown
CVE-2024-8539
Disclosure Date: November 12, 2024 (last updated January 18, 2025)
Improper authorization in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker to modify sensitive configuration files.
0
Attacker Value
Unknown
CVE-2024-7571
Disclosure Date: November 12, 2024 (last updated January 18, 2025)
Incorrect permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.
0
Attacker Value
Unknown
CVE-2023-1932
Disclosure Date: November 07, 2024 (last updated November 07, 2024)
A flaw was found in hibernate-validator's 'isValid' method in the org.hibernate.validator.internal.constraintvalidators.hv.SafeHtmlValidator class, which can be bypassed by omitting the tag ending in a less-than character. Browsers may render an invalid html, allowing HTML injection or Cross-Site-Scripting (XSS) attacks.
0