Show filters
423 Total Results
Displaying 81-90 of 423
Sort by:
Attacker Value
Unknown

CVE-2024-38649

Disclosure Date: November 13, 2024 (last updated November 23, 2024)
An out-of-bounds write in IPsec of Ivanti Connect Secure before version 22.7R2.1(Not Applicable to 9.1Rx) allows a remote unauthenticated attacker to cause a denial of service.
0
Attacker Value
Unknown

CVE-2024-37400

Disclosure Date: November 13, 2024 (last updated November 13, 2024)
An out of bounds read in Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to trigger an infinite loop, causing a denial of service.
0
Attacker Value
Unknown

CVE-2024-37398

Disclosure Date: November 13, 2024 (last updated November 19, 2024)
Insufficient validation in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.
Attacker Value
Unknown

CVE-2024-37376

Disclosure Date: November 13, 2024 (last updated November 13, 2024)
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
0
Attacker Value
Unknown

CVE-2024-34787

Disclosure Date: November 13, 2024 (last updated November 13, 2024)
Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a local unauthenticated attacker to achieve code execution. User interaction is required.
0
Attacker Value
Unknown

CVE-2024-34784

Disclosure Date: November 13, 2024 (last updated November 13, 2024)
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
0
Attacker Value
Unknown

CVE-2024-34782

Disclosure Date: November 13, 2024 (last updated November 13, 2024)
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
0
Attacker Value
Unknown

CVE-2024-34781

Disclosure Date: November 13, 2024 (last updated November 13, 2024)
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
0
Attacker Value
Unknown

CVE-2024-34780

Disclosure Date: November 13, 2024 (last updated November 13, 2024)
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
0
Attacker Value
Unknown

CVE-2024-32847

Disclosure Date: November 13, 2024 (last updated November 13, 2024)
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
0