Kategori: NIST-Güvenlik Açıkları

CVE-2023-25600

An issue was discovered in InsydeH2O. A malicious operating system can tamper with a runtime-writable EFI variable, leading to out-of-bounds memory reads and a denial…

Devamını oku

CVE-2023-22277

Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code…

Devamını oku

CVE-2022-26838

Path traversal vulnerability in Importing Mobile Device Data of Cybozu Remote Service 3.1.2 allows a remote authenticated attacker to cause a denial-of-service (DoS) condition. Zafiyet…

Devamını oku

CVE-2022-34453

Dell XtremIO X2 XMS versions prior to 6-4-1.11 contain an improper access control vulnerability. A remote read only user could potentially exploit this vulnerability to…

Devamını oku

CVE-2023-22314

Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code…

Devamını oku

CVE-2023-22317

Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code…

Devamını oku

CVE-2023-21411

User provided input is not sanitized in the “Settings > Access Controlâ€� configuration interface allowing for arbitrary code execution. Zafiyet ile ilgili Genel Bilgi, Etki…

Devamını oku

CVE-2023-21412

User provided input is not sanitized on the AXIS License Plate Verifier specific “search.cgiâ€� allowing for SQL injections. Zafiyet ile ilgili Genel Bilgi, Etki ve…

Devamını oku

CVE-2023-21407

A broken access control was found allowing for privileged escalation of the operator account to gain administrator privileges. Zafiyet ile ilgili Genel Bilgi, Etki ve…

Devamını oku