Show filters
75 Total Results
Displaying 1-10 of 75
Sort by:
Attacker Value
Unknown
CVE-2024-43805
Disclosure Date: August 28, 2024 (last updated February 26, 2025)
jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. This vulnerability depends on user interaction by opening a malicious notebook with Markdown cells, or Markdown file using JupyterLab preview feature. A malicious user can access any data that the attacked user has access to as well as perform arbitrary requests acting as the attacked user. JupyterLab v3.6.8, v4.2.5 and Jupyter Notebook v7.2.2 have been patched to resolve this issue. Users are advised to upgrade. There is no workaround for the underlying DOM Clobbering susceptibility. However, select plugins can be disabled on deployments which cannot update in a timely fashion to minimise the risk. These are: 1. `@jupyterlab/mathjax-extension:plugin` - users will loose ability to preview mathematical equations. 2. `@jupyterlab/markdownviewer-extension:plugin` - users will loose ability to open Markdown previews. 3. `@jupyterlab/mathjax2-extension:plugin` (if…
0
Attacker Value
Unknown
CVE-2023-5912
Disclosure Date: April 05, 2024 (last updated February 26, 2025)
A potential memory leakage vulnerability was reported in some Lenovo Notebook products that may allow a local attacker with elevated privileges to write to NVRAM variables.
0
Attacker Value
Unknown
CVE-2024-22421
Disclosure Date: January 19, 2024 (last updated February 26, 2025)
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. Users of JupyterLab who click on a malicious link may get their `Authorization` and `XSRFToken` tokens exposed to a third party when running an older `jupyter-server` version. JupyterLab versions 4.1.0b2, 4.0.11, and 3.6.7 are patched. No workaround has been identified, however users should ensure to upgrade `jupyter-server` to version 2.7.2 or newer which includes a redirect vulnerability fix.
0
Attacker Value
Unknown
CVE-2024-22420
Disclosure Date: January 19, 2024 (last updated February 26, 2025)
JupyterLab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook and Architecture. This vulnerability depends on user interaction by opening a malicious Markdown file using JupyterLab preview feature. A malicious user can access any data that the attacked user has access to as well as perform arbitrary requests acting as the attacked user. JupyterLab version 4.0.11 has been patched. Users are advised to upgrade. Users unable to upgrade should disable the table of contents extension.
0
Attacker Value
Unknown
CVE-2023-51277
Disclosure Date: January 05, 2024 (last updated January 12, 2024)
nbviewer-app (aka Jupyter Notebook Viewer) before 0.1.6 has the get-task-allow entitlement for release builds.
0
Attacker Value
Unknown
CVE-2022-31639
Disclosure Date: June 13, 2023 (last updated February 25, 2025)
Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.
0
Attacker Value
Unknown
CVE-2022-31638
Disclosure Date: June 13, 2023 (last updated February 25, 2025)
Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.
0
Attacker Value
Unknown
CVE-2022-31637
Disclosure Date: June 13, 2023 (last updated February 25, 2025)
Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.
0
Attacker Value
Unknown
CVE-2022-31636
Disclosure Date: June 13, 2023 (last updated February 25, 2025)
Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.
0
Attacker Value
Unknown
CVE-2022-31635
Disclosure Date: June 13, 2023 (last updated February 25, 2025)
Potential time-of-check to time-of-use (TOCTOU) vulnerabilities have been identified in the BIOS for certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure.
0