Show filters
235 Total Results
Displaying 1-10 of 235
Sort by:
Attacker Value
Unknown
CVE-2023-23560
Disclosure Date: January 23, 2023 (last updated October 08, 2023)
In certain Lexmark products through 2023-01-12, SSRF can occur because of a lack of input validation.
1
Attacker Value
Unknown
CVE-2024-41594
Disclosure Date: October 03, 2024 (last updated October 09, 2024)
An issue in DrayTek Vigor310 devices through 4.3.2.6 allows an attacker to obtain sensitive information because the httpd server of the Vigor management UI uses a static string for seeding the PRNG of OpenSSL.
0
Attacker Value
Unknown
CVE-2024-41593
Disclosure Date: October 03, 2024 (last updated October 09, 2024)
DrayTek Vigor310 devices through 4.3.2.6 allow a remote attacker to execute arbitrary code via the function ft_payload_dns(), because a byte sign-extension operation occurs for the length argument of a _memcpy call, leading to a heap-based Buffer Overflow.
0
Attacker Value
Unknown
CVE-2024-41591
Disclosure Date: October 03, 2024 (last updated October 09, 2024)
DrayTek Vigor3910 devices through 4.3.2.6 allow unauthenticated DOM-based reflected XSS.
0
Attacker Value
Unknown
CVE-2024-41587
Disclosure Date: October 03, 2024 (last updated October 08, 2024)
Stored XSS, by authenticated users, is caused by poor sanitization of the Login Page Greeting message in DrayTek Vigor310 devices through 4.3.2.6.
0
Attacker Value
Unknown
CVE-2023-20591
Disclosure Date: August 13, 2024 (last updated December 18, 2024)
Improper re-initialization of IOMMU during the DRTM event
may permit an untrusted platform configuration to persist, allowing an attacker
to read or modify hypervisor memory, potentially resulting in loss of
confidentiality, integrity, and availability.
0
Attacker Value
Unknown
CVE-2023-20584
Disclosure Date: August 13, 2024 (last updated December 18, 2024)
IOMMU improperly handles certain special address
ranges with invalid device table entries (DTEs), which may allow an attacker
with privileges and a compromised Hypervisor to
induce DTE faults to bypass RMP checks in SEV-SNP, potentially leading to a
loss of guest integrity.
0
Attacker Value
Unknown
CVE-2023-20578
Disclosure Date: August 13, 2024 (last updated October 03, 2024)
A TOCTOU (Time-Of-Check-Time-Of-Use) in SMM may allow
an attacker with ring0 privileges and access to the
BIOS menu or UEFI shell to modify the communications buffer potentially
resulting in arbitrary code execution.
0
Attacker Value
Unknown
CVE-2021-26344
Disclosure Date: August 13, 2024 (last updated December 18, 2024)
An out of bounds memory write when processing the AMD
PSP1 Configuration Block (APCB) could allow an attacker with access the ability
to modify the BIOS image, and the ability to sign the resulting image, to
potentially modify the APCB block resulting in arbitrary code execution.
0
Attacker Value
Unknown
CVE-2024-21980
Disclosure Date: August 05, 2024 (last updated December 21, 2024)
Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to potentially overwrite a guest's memory or UMC seed resulting in loss of confidentiality and integrity.
0