Show filters
13,173 Total Results
Displaying 881-890 of 10,000
Refine your search criteria for more targeted results.
Sort by:
Attacker Value
Unknown

CVE-2024-20012

Disclosure Date: February 05, 2024 (last updated February 09, 2024)
In keyInstall, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08358566; Issue ID: ALPS08358566.
Attacker Value
Unknown

CVE-2024-20010

Disclosure Date: February 05, 2024 (last updated February 09, 2024)
In keyInstall, there is a possible escalation of privilege due to type confusion. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08358560; Issue ID: ALPS08358560.
Attacker Value
Unknown

CVE-2024-20006

Disclosure Date: February 05, 2024 (last updated February 09, 2024)
In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08477148; Issue ID: ALPS08477148.
Attacker Value
Unknown

CVE-2024-20002

Disclosure Date: February 05, 2024 (last updated February 09, 2024)
In TVAPI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03961715; Issue ID: DTV03961715.
Attacker Value
Unknown

CVE-2024-20001

Disclosure Date: February 05, 2024 (last updated February 09, 2024)
In TVAPI, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: DTV03961601; Issue ID: DTV03961601.
Attacker Value
Unknown

CVE-2021-46903

Disclosure Date: February 04, 2024 (last updated February 13, 2024)
An issue was discovered in LTOS-Web-Interface in Meinberg LANTIME-Firmware before 6.24.029 MBGID-9343 and 7 before 7.04.008 MBGID-6303. An admin can delete required user accounts (in violation of expected access control).
Attacker Value
Unknown

CVE-2021-46902

Disclosure Date: February 04, 2024 (last updated February 13, 2024)
An issue was discovered in LTOS-Web-Interface in Meinberg LANTIME-Firmware before 6.24.029 MBGID-9343 and 7 before 7.04.008 MBGID-6303. Path validation is mishandled, and thus an admin can read or delete files in violation of expected access controls.
Attacker Value
Unknown

CVE-2023-33851

Disclosure Date: February 04, 2024 (last updated February 13, 2024)
IBM PowerVM Hypervisor FW950.00 through FW950.90, FW1020.00 through FW1020.40, and FW1030.00 through FW1030.30 could reveal sensitive partition data to a system administrator. IBM X-Force ID: 257135.
Attacker Value
Unknown

CVE-2024-23824

Disclosure Date: February 02, 2024 (last updated February 10, 2024)
mailcow is a dockerized email package, with multiple containers linked in one bridged network. The application is vulnerable to pixel flood attack, once the payload has been successfully uploaded in the logo the application goes slow and doesn't respond in the admin page. It is tested on the versions 2023-12a and prior and patched in version 2024-01.
Attacker Value
Unknown

CVE-2024-22107

Disclosure Date: February 02, 2024 (last updated February 10, 2024)
An issue was discovered in GTB Central Console 15.17.1-30814.NG. The method systemSettingsDnsDataAction at /opt/webapp/src/AppBundle/Controller/React/SystemSettingsController.php is vulnerable to command injection via the /old/react/v1/api/system/dns/data endpoint. An authenticated attacker can abuse it to inject an arbitrary command and compromise the platform.