Show filters
37 Total Results
Displaying 1-10 of 37
Sort by:
Attacker Value
Unknown

CVE-2025-0617

Disclosure Date: January 29, 2025 (last updated January 29, 2025)
An attacker with access to an HX 10.0.0 and previous versions, may send specially-crafted data to the HX console. The malicious detection would then trigger file parsing containing exponential entity expansions in the consumer process thus causing a Denial of Service.
0
Attacker Value
Unknown

CVE-2024-5955

Disclosure Date: December 20, 2024 (last updated December 21, 2024)
Cross-site scripting vulnerability in Trellix ePolicy Orchestrator prior to ePO 5.10 Service Pack 1 Update 3 allows a remote authenticated attacker to craft requests causing arbitrary content to be injected into the response when accessing the epolicy Orchestrator.
0
Attacker Value
Unknown

CVE-2024-9679

Disclosure Date: December 16, 2024 (last updated December 18, 2024)
A Hardcoded Cryptographic key vulnerability existed in DLP Extension 11.11.1.3 which allowed the decryption of previously encrypted user credentials.
0
Attacker Value
Unknown

CVE-2024-9678

Disclosure Date: December 16, 2024 (last updated December 18, 2024)
An SQL Injection vulnerability existed in DLP Extension 11.11.1.3. The vulnerability allowed an attacker to perform arbitrary SQL queries potentially leading to command execution.
0
Attacker Value
Unknown

CVE-2024-11482

Disclosure Date: November 29, 2024 (last updated December 21, 2024)
A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API and enables remote code execution through command injection, executed as the root user.
0
Attacker Value
Unknown

CVE-2024-11481

Disclosure Date: November 29, 2024 (last updated December 21, 2024)
A vulnerability in ESM 11.6.10 allows unauthenticated access to the internal Snowservice API. This leads to improper handling of path traversal, insecure forwarding to an AJP backend without adequate validation, and lack of authentication for accessing internal API endpoints.
0
Attacker Value
Unknown

CVE-2024-5957

Disclosure Date: September 05, 2024 (last updated September 07, 2024)
This vulnerability allows unauthenticated remote attackers to bypass authentication and gain APIs access of the Manager.
Attacker Value
Unknown

CVE-2024-5956

Disclosure Date: September 05, 2024 (last updated September 07, 2024)
This vulnerability allows unauthenticated remote attackers to bypass authentication and gain partial data access to the vulnerable Trellix IPS Manager with garbage data in response mostly
Attacker Value
Unknown

CVE-2024-7608

Disclosure Date: August 27, 2024 (last updated August 28, 2024)
An authenticated user can access the restricted files from NX, EX, FX, AX, IVX and CMS using path traversal.
0
Attacker Value
Unknown

CVE-2024-5731

Disclosure Date: June 14, 2024 (last updated June 15, 2024)
A vulnerability in the IPS Manager, Central Manager, and Local Manager communication workflow allows an attacker to control the destination of a request by manipulating the parameter, thereby leveraging sensitive information.
0