Show filters
67 Total Results
Displaying 1-10 of 67
Sort by:
Attacker Value
Unknown
CVE-2021-3599
Disclosure Date: November 12, 2021 (last updated February 23, 2025)
A potential vulnerability in the SMI callback function used to access flash device in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.
1
Attacker Value
Unknown
CVE-2024-10345
Disclosure Date: November 11, 2024 (last updated February 27, 2025)
In Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the shutdown function was identified. Reported by Karol Więsek.
0
Attacker Value
Unknown
CVE-2024-10344
Disclosure Date: November 11, 2024 (last updated February 27, 2025)
In Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the refuse function was identified. Reported by Karol Więsek.
0
Attacker Value
Unknown
CVE-2024-10314
Disclosure Date: November 11, 2024 (last updated February 27, 2025)
In Helix Core versions prior to 2024.2, an unauthenticated remote Denial of Service (DoS) via the auto-generation function was identified. Reported by Karol Więsek.
0
Attacker Value
Unknown
CVE-2024-8067
Disclosure Date: September 25, 2024 (last updated February 26, 2025)
In versions of Helix Core prior to 2024.1 Patch 2 (2024.1/2655224) a Windows ANSI API Unicode "best fit" argument injection was identified.
0
Attacker Value
Unknown
CVE-2024-22281
Disclosure Date: August 20, 2024 (last updated February 26, 2025)
** UNSUPPORTED WHEN ASSIGNED ** The Apache Helix Front (UI) component contained a hard-coded secret, allowing an attacker to spoof sessions by generating their own fake cookies.
This issue affects Apache Helix Front (UI): all versions.
As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users.
NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
0
Attacker Value
Unknown
CVE-2024-3995
Disclosure Date: June 28, 2024 (last updated February 26, 2025)
In Helix ALM versions prior to 2024.2.0, a local command injection was identified. Reported by Bryan Riggins.
0
Attacker Value
Unknown
CVE-2024-0325
Disclosure Date: February 01, 2024 (last updated February 26, 2025)
In Helix Sync versions prior to 2024.1, a local command injection was identified. Reported by Bryan Riggins.
0
Attacker Value
Unknown
CVE-2023-5759
Disclosure Date: November 08, 2023 (last updated February 25, 2025)
In Helix Core versions prior to 2023.2, an unauthenticated remote Denial of Service (DoS) via the buffer was identified. Reported by Jason Geffner.
0
Attacker Value
Unknown
CVE-2023-45849
Disclosure Date: November 08, 2023 (last updated February 25, 2025)
An arbitrary code execution which results in privilege escalation was discovered in Helix Core versions prior to 2023.2. Reported by Jason Geffner.
0