Show filters
64 Total Results
Displaying 1-10 of 64
Sort by:
Attacker Value
Unknown
CVE-2021-3599
Disclosure Date: November 12, 2021 (last updated October 07, 2023)
A potential vulnerability in the SMI callback function used to access flash device in some ThinkPad models may allow an attacker with local access and elevated privileges to execute arbitrary code.
1
Attacker Value
Unknown
CVE-2024-0112
Disclosure Date: February 12, 2025 (last updated February 12, 2025)
NVIDIA Jetson AGX Orin™ and NVIDIA IGX Orin software contain a vulnerability where an attacker can cause an improper input validation issue by escalating certain permissions to a limited degree. A successful exploit of this vulnerability might lead to code execution, denial of service, data corruption, information disclosure, or escalation of privilege.
0
Attacker Value
Unknown
CVE-2024-53984
Disclosure Date: December 02, 2024 (last updated December 21, 2024)
Nanopb is a small code-size Protocol Buffers implementation. When the compile time option PB_ENABLE_MALLOC is enabled, the message contains at least one field with FT_POINTER field type, custom stream callback is used with unknown stream length. and the pb_decode_ex() function is used with flag PB_DECODE_DELIMITED, then the pb_decode_ex() function does not automatically call pb_release(), like is done for other failure cases. This could lead to memory leak and potential denial-of-service. This vulnerability is fixed in 0.4.9.1.
0
Attacker Value
Unknown
CVE-2024-44460
Disclosure Date: September 12, 2024 (last updated September 19, 2024)
An invalid read size in Nanomq v0.21.9 allows attackers to cause a Denial of Service (DoS).
0
Attacker Value
Unknown
CVE-2024-45678
Disclosure Date: September 03, 2024 (last updated September 13, 2024)
Yubico YubiKey 5 Series devices with firmware before 5.7.0 and YubiHSM 2 devices with firmware before 2.4.0 allow an ECDSA secret-key extraction attack (that requires physical access and expensive equipment) in which an electromagnetic side channel is present because of a non-constant-time modular inversion for the Extended Euclidean Algorithm, aka the EUCLEAK issue. Other uses of an Infineon cryptographic library may also be affected.
0
Attacker Value
Unknown
CVE-2024-5742
Disclosure Date: June 12, 2024 (last updated November 12, 2024)
A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing, a file it saves to an emergency file with the permissions of the running user provides a window of opportunity for attackers to escalate privileges through a malicious symlink.
0
Attacker Value
Unknown
CVE-2024-36400
Disclosure Date: June 04, 2024 (last updated June 11, 2024)
nano-id is a unique string ID generator for Rust. Affected versions of the nano-id crate incorrectly generated IDs using a reduced character set in the `nano_id::base62` and `nano_id::base58` functions. Specifically, the `base62` function used a character set of 32 symbols instead of the intended 62 symbols, and the `base58` function used a character set of 16 symbols instead of the intended 58 symbols. Additionally, the `nano_id::gen` macro is also affected when a custom character set that is not a power of 2 in size is specified. It should be noted that `nano_id::base64` is not affected by this vulnerability. This can result in a significant reduction in entropy, making the generated IDs predictable and vulnerable to brute-force attacks when the IDs are used in security-sensitive contexts such as session tokens or unique identifiers. The vulnerability is fixed in 0.4.0.
0
Attacker Value
Unknown
CVE-2023-50121
Disclosure Date: January 06, 2024 (last updated January 13, 2024)
Autel EVO NANO drone flight control firmware version 1.6.5 is vulnerable to denial of service (DoS).
0
Attacker Value
Unknown
CVE-2023-47335
Disclosure Date: November 16, 2023 (last updated November 30, 2023)
Insecure permissions in the setNFZEnable function of Autel Robotics EVO Nano drone v1.6.5 allows attackers to breach the geo-fence and fly into no-fly zones.
0
Attacker Value
Unknown
CVE-2022-4574
Disclosure Date: October 30, 2023 (last updated November 08, 2023)
An SMI handler input validation vulnerability in the BIOS of some ThinkPad models could allow an attacker with local access and elevated privileges to execute arbitrary code.
0