Show filters
296 Total Results
Displaying 1-10 of 296
Sort by:
Attacker Value
Unknown

CVE-2023-4608

Disclosure Date: October 25, 2023 (last updated November 08, 2023)
An authenticated XCC user with elevated privileges can perform blind SQL injection in limited cases through a crafted API command.  This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.
Attacker Value
Unknown

CVE-2023-4607

Disclosure Date: October 25, 2023 (last updated November 08, 2023)
An authenticated XCC user can change permissions for any user through a crafted API command.
Attacker Value
Unknown

CVE-2023-4606

Disclosure Date: October 25, 2023 (last updated November 08, 2023)
An authenticated XCC user with Read-Only permission can change a different user’s password through a crafted API command.   This affects ThinkSystem v2 and v3 servers with XCC; ThinkSystem v1 servers are not affected.
Attacker Value
Unknown

CVE-2023-28538

Disclosure Date: September 05, 2023 (last updated October 08, 2023)
Memory corruption in WIN Product while invoking WinAcpi update driver in the UEFI region.
Attacker Value
Unknown

CVE-2023-28537

Disclosure Date: August 08, 2023 (last updated October 08, 2023)
Memory corruption while allocating memory in COmxApeDec module in Audio.
Attacker Value
Unknown

CVE-2023-22666

Disclosure Date: August 08, 2023 (last updated October 08, 2023)
Memory Corruption in Audio while playing amrwbplus clips with modified content.
Attacker Value
Unknown

CVE-2023-21652

Disclosure Date: August 08, 2023 (last updated October 08, 2023)
Cryptographic issue in HLOS as derived keys used to encrypt/decrypt information is present on stack after use.
Attacker Value
Unknown

CVE-2023-21651

Disclosure Date: August 08, 2023 (last updated October 08, 2023)
Memory Corruption in Core due to incorrect type conversion or cast in secure_io_read/write function in TEE.
Attacker Value
Unknown

CVE-2023-21626

Disclosure Date: August 08, 2023 (last updated October 08, 2023)
Cryptographic issue in HLOS due to improper authentication while performing key velocity checks using more than one key.
Attacker Value
Unknown

CVE-2022-40510

Disclosure Date: August 08, 2023 (last updated October 08, 2023)
Memory corruption due to buffer copy without checking size of input in Audio while voice call with EVS vocoder.