Show filters
69 Total Results
Displaying 1-10 of 69
Sort by:
Attacker Value
Very High
CVE-2016-4437
Disclosure Date: June 07, 2016 (last updated July 25, 2024)
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attackers to execute arbitrary code or bypass intended access restrictions via an unspecified request parameter.
3
Attacker Value
Unknown
CVE-2021-36323
Disclosure Date: November 01, 2021 (last updated February 23, 2025)
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user may potentially exploit this vulnerability by using an SMI to gain arbitrary code execution in SMRAM.
1
Attacker Value
Unknown
CVE-2024-39584
Disclosure Date: August 28, 2024 (last updated December 21, 2024)
Dell Client Platform BIOS contains a Use of Default Cryptographic Key Vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Secure Boot bypass and arbitrary code execution.
0
Attacker Value
Unknown
CVE-2024-8105
Disclosure Date: August 26, 2024 (last updated August 27, 2024)
A vulnerability related to the use an insecure Platform Key (PK) has been discovered. An attacker with the compromised PK private key can create malicious UEFI software that is signed with a trusted key that has been compromised.
0
Attacker Value
Unknown
CVE-2024-32860
Disclosure Date: June 13, 2024 (last updated August 17, 2024)
Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
0
Attacker Value
Unknown
CVE-2024-32859
Disclosure Date: June 13, 2024 (last updated September 20, 2024)
Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
0
Attacker Value
Unknown
CVE-2024-32858
Disclosure Date: June 13, 2024 (last updated September 25, 2024)
Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
0
Attacker Value
Unknown
CVE-2024-32856
Disclosure Date: June 13, 2024 (last updated September 25, 2024)
Dell Client Platform BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
0
Attacker Value
Unknown
CVE-2023-32475
Disclosure Date: June 07, 2024 (last updated October 30, 2024)
Dell BIOS contains a missing support for integrity check vulnerability. An attacker with physical access to the system could potentially bypass security mechanisms to run arbitrary code on the system.
0
Attacker Value
Unknown
CVE-2024-27905
Disclosure Date: February 27, 2024 (last updated February 14, 2025)
** UNSUPPORTED WHEN ASSIGNED ** Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Aurora.
An endpoint exposing internals to unauthenticated users can be used as a "padding oracle" allowing an anonymous attacker to construct a valid authentication cookie. Potentially this could be combined with vulnerabilities in other components to achieve remote code execution.
As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.
NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
0