Show filters
24 Total Results
Displaying 1-10 of 24
Sort by:
Attacker Value
Unknown
CVE-2023-44487
Disclosure Date: October 10, 2023 (last updated June 28, 2024)
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
1
Attacker Value
Unknown
CVE-2024-21786
Disclosure Date: November 21, 2024 (last updated January 12, 2025)
An OS command injection vulnerability exists in the web interface configuration upload functionality of MC Technologies MC LR Router 2.10.5. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2024-7580
Disclosure Date: August 07, 2024 (last updated August 08, 2024)
A vulnerability was found in Alien Technology ALR-F800 up to 19.10.24.00. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/system.html. The manipulation of the argument uploadedFile with the input ;whoami leads to os command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2024-7579
Disclosure Date: August 07, 2024 (last updated August 29, 2024)
A vulnerability was found in Alien Technology ALR-F800 up to 19.10.24.00. It has been declared as critical. Affected by this vulnerability is the function popen of the file /var/www/cgi-bin/upgrade.cgi of the component File Name Handler. The manipulation of the argument uploadedFile leads to os command injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2024-7578
Disclosure Date: August 07, 2024 (last updated August 29, 2024)
A vulnerability was found in Alien Technology ALR-F800 up to 19.10.24.00. It has been classified as critical. Affected is an unknown function of the file /var/www/cmd.php. The manipulation of the argument cmd leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
0
Attacker Value
Unknown
CVE-2023-30768
Disclosure Date: May 12, 2023 (last updated October 08, 2023)
Improper access control in the Intel(R) Server Board S2600WTT belonging to the Intel(R) Server Board S2600WT Family with the BIOS version 0016 may allow a privileged user to potentially enable escalation of privilege via local access.
0
Attacker Value
Unknown
CVE-2023-26070
Disclosure Date: April 10, 2023 (last updated October 08, 2023)
Certain Lexmark devices through 2023-02-19 mishandle Input Validation (issue 4 of 4).
0
Attacker Value
Unknown
CVE-2023-26066
Disclosure Date: April 10, 2023 (last updated October 08, 2023)
Certain Lexmark devices through 2023-02-19 have Improper Validation of an Array Index.
0
Attacker Value
Unknown
CVE-2023-26065
Disclosure Date: April 10, 2023 (last updated October 08, 2023)
Certain Lexmark devices through 2023-02-19 have an Integer Overflow.
0
Attacker Value
Unknown
CVE-2023-26064
Disclosure Date: April 10, 2023 (last updated October 08, 2023)
Certain Lexmark devices through 2023-02-19 have an Out-of-bounds Write.
0