Show filters
546 Total Results
Displaying 81-90 of 546
Sort by:
Attacker Value
Unknown

CVE-2024-37164

Disclosure Date: June 13, 2024 (last updated January 22, 2025)
Computer Vision Annotation Tool (CVAT) is an interactive video and image annotation tool for computer vision. CVAT allows users to supply custom endpoint URLs for cloud storages based on Amazon S3 and Azure Blob Storage. Starting in version 2.1.0 and prior to version 2.14.3, an attacker with a CVAT account can exploit this feature by specifying URLs whose host part is an intranet IP address or an internal domain name. By doing this, the attacker may be able to probe the network that the CVAT backend runs in for HTTP(S) servers. In addition, if there is a web server on this network that is sufficiently API-compatible with an Amazon S3 or Azure Blob Storage endpoint, and either allows anonymous access, or allows authentication with credentials that are known by the attacker, then the attacker may be able to create a cloud storage linked to this server. They may then be able to list files on the server; extract files from the server, if these files are of a type that CVAT supports readin…
Attacker Value
Unknown

CVE-2024-23360

Disclosure Date: June 03, 2024 (last updated January 13, 2025)
Memory corruption while creating a LPAC client as LPAC engine was allowed to access GPU registers.
Attacker Value
Unknown

CVE-2023-43556

Disclosure Date: June 03, 2024 (last updated January 28, 2025)
Memory corruption in Hypervisor when platform information mentioned is not aligned.
Attacker Value
Unknown

CVE-2023-43555

Disclosure Date: June 03, 2024 (last updated January 28, 2025)
Information disclosure in Video while parsing mp2 clip with invalid section length.
Attacker Value
Unknown

CVE-2023-43551

Disclosure Date: June 03, 2024 (last updated January 28, 2025)
Cryptographic issue while performing attach with a LTE network, a rogue base station can skip the authentication phase and immediately send the Security Mode Command.
Attacker Value
Unknown

CVE-2023-43542

Disclosure Date: June 03, 2024 (last updated January 28, 2025)
Memory corruption while copying a keyblob`s material when the key material`s size is not accurately checked.
0
Attacker Value
Unknown

CVE-2023-43538

Disclosure Date: June 03, 2024 (last updated January 28, 2025)
Memory corruption in TZ Secure OS while Tunnel Invoke Manager initialization.
Attacker Value
Unknown

CVE-2024-4820

Disclosure Date: May 14, 2024 (last updated February 12, 2025)
A vulnerability was found in SourceCodester Online Computer and Laptop Store 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /classes/SystemSettings.php?f=update_settings. The manipulation leads to unrestricted upload. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-263941 was assigned to this vulnerability.
Attacker Value
Unknown

CVE-2024-4798

Disclosure Date: May 14, 2024 (last updated February 12, 2025)
A vulnerability, which was classified as critical, has been found in SourceCodester Online Computer and Laptop Store 1.0. Affected by this issue is some unknown functionality of the file /admin/maintenance/manage_brand.php. The manipulation of the argument id leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. VDB-263918 is the identifier assigned to this vulnerability.
Attacker Value
Unknown

CVE-2024-21477

Disclosure Date: May 06, 2024 (last updated January 16, 2025)
Transient DOS while parsing a protected 802.11az Fine Time Measurement (FTM) frame.
0