Show filters
726 Total Results
Displaying 81-90 of 726
Sort by:
Attacker Value
Unknown
CVE-2024-0173
Disclosure Date: March 13, 2024 (last updated February 26, 2025)
Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper parameter initialization vulnerability. A local low privileged attacker could potentially exploit this vulnerability to read the contents of non-SMM stack memory.
0
Attacker Value
Unknown
CVE-2024-0163
Disclosure Date: March 13, 2024 (last updated February 26, 2025)
Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain a TOCTOU race condition vulnerability. A local low privileged attacker could potentially exploit this vulnerability to gain access to otherwise unauthorized resources.
0
Attacker Value
Unknown
CVE-2024-0162
Disclosure Date: March 13, 2024 (last updated February 26, 2025)
Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an Improper SMM communication buffer verification vulnerability. A local low privileged attacker could potentially exploit this vulnerability leading to out-of-bound read/writes to SMRAM.
0
Attacker Value
Unknown
CVE-2024-0154
Disclosure Date: March 13, 2024 (last updated February 26, 2025)
Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an improper parameter initialization vulnerability. A local low privileged attacker could potentially exploit this vulnerability to read the contents of non-SMM stack memory.
0
Attacker Value
Unknown
CVE-2024-0161
Disclosure Date: March 13, 2024 (last updated February 26, 2025)
Dell PowerEdge Server BIOS and Dell Precision Rack BIOS contain an Improper SMM communication buffer verification vulnerability. A local low privileged attacker could potentially exploit this vulnerability leading to arbitrary writes to SMRAM.
0
Attacker Value
Unknown
CVE-2023-5457
Disclosure Date: March 05, 2024 (last updated February 26, 2025)
A CWE-1269 “Product Released in Non-Release Configuration” vulnerability in the Django web framework used by the web application (due to the “debug” configuration parameter set to “True”) allows a remote unauthenticated attacker to access critical information and have other unspecified impacts to the confidentiality, integrity, and availability of the application. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.
0
Attacker Value
Unknown
CVE-2023-45600
Disclosure Date: March 05, 2024 (last updated February 26, 2025)
A CWE-613 “Insufficient Session Expiration” vulnerability in the web application, due to the session cookie “sessionid” lasting two weeks, facilitates session hijacking attacks against victims. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.
0
Attacker Value
Unknown
CVE-2023-45599
Disclosure Date: March 05, 2024 (last updated February 26, 2025)
A CWE-646 “Reliance on File Name or Extension of Externally-Supplied File” vulnerability in the “iec61850” functionality of the web application allows a remote authenticated attacker to upload any arbitrary type of file into the device. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.
0
Attacker Value
Unknown
CVE-2023-45598
Disclosure Date: March 05, 2024 (last updated February 26, 2025)
A CWE-425 “Direct Request ('Forced Browsing')” vulnerability in the “measure” functionality of the web application allows a remote unauthenticated attacker to access confidential measure information. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.
0
Attacker Value
Unknown
CVE-2023-45597
Disclosure Date: March 05, 2024 (last updated February 26, 2025)
A CWE-1236 “Improper Neutralization of Formula Elements in a CSV File” vulnerability in the “file_configuration” functionality of the web application (concerning the function “export_file”) allows a remote authenticated attacker to inject arbitrary formulas inside generated CSV files. This issue affects: AiLux imx6 bundle below version imx6_1.0.7-2.
0