Show filters
350 Total Results
Displaying 71-80 of 350
Sort by:
Attacker Value
Unknown

CVE-2023-45618

Disclosure Date: November 14, 2023 (last updated November 22, 2023)
There are arbitrary file deletion vulnerabilities in the AirWave client service accessed by PAPI (Aruba's access point management protocol). Successful exploitation of these vulnerabilities result in the ability to delete arbitrary files on the underlying operating system, which could lead to the ability to interrupt normal operation and impact the integrity of the access point.
Attacker Value
Unknown

CVE-2023-45617

Disclosure Date: November 14, 2023 (last updated November 22, 2023)
There are arbitrary file deletion vulnerabilities in the CLI service accessed by PAPI (Aruba's access point management protocol). Successful exploitation of these vulnerabilities result in the ability to delete arbitrary files on the underlying operating system, which could lead to the ability to interrupt normal operation and impact the integrity of the access point.
Attacker Value
Unknown

CVE-2023-45616

Disclosure Date: November 14, 2023 (last updated November 22, 2023)
There is a buffer overflow vulnerability in the underlying AirWave client service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of this vulnerability results in the ability to execute arbitrary code as a privileged user on the underlying operating system.
Attacker Value
Unknown

CVE-2023-45615

Disclosure Date: November 14, 2023 (last updated November 22, 2023)
There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.
Attacker Value
Unknown

CVE-2023-45614

Disclosure Date: November 14, 2023 (last updated November 22, 2023)
There are buffer overflow vulnerabilities in the underlying CLI service that could lead to unauthenticated remote code execution by sending specially crafted packets destined to the PAPI (Aruba's access point management protocol) UDP port (8211). Successful exploitation of these vulnerabilities result in the ability to execute arbitrary code as a privileged user on the underlying operating system.
Attacker Value
Unknown

CVE-2023-44243

Disclosure Date: October 06, 2023 (last updated October 11, 2023)
Cross-Site Request Forgery (CSRF) vulnerability in Dylan Blokhuis Instant CSS plugin <= 1.2.1 versions.
Attacker Value
Unknown

CVE-2023-4879

Disclosure Date: September 10, 2023 (last updated October 08, 2023)
Cross-site Scripting (XSS) - Stored in GitHub repository instantsoft/icms2 prior to 2.16.1.-git.
Attacker Value
Unknown

CVE-2023-4878

Disclosure Date: September 10, 2023 (last updated October 08, 2023)
Server-Side Request Forgery (SSRF) in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
Attacker Value
Unknown

CVE-2023-4704

Disclosure Date: September 01, 2023 (last updated October 08, 2023)
External Control of System or Configuration Setting in GitHub repository instantsoft/icms2 prior to 2.16.1-git.
Attacker Value
Unknown

CVE-2023-4655

Disclosure Date: August 31, 2023 (last updated October 08, 2023)
Cross-site Scripting (XSS) - Reflected in GitHub repository instantsoft/icms2 prior to 2.16.1.