Low · CVSS 3.9
Insufficient input validation in the SMU may
allow an attacker to corrupt SMU SRAM potentially leading to a loss of
integrity or denial of service.
Published May 9, 2023 · Updated Jan 28, 2025
High · CVSS 7.5
Insufficient input validation in the SMU may
enable a privileged attacker to write beyond the intended bounds of a shared
memory buffer potentially leading to a loss of integrity.
Published May 9, 2023 · Updated Jan 28, 2025
High · CVSS 7.5
Improper validation of DRAM addresses in SMU may
allow an attacker to overwrite sensitive memory locations within the ASP
potentially resulting in a denial of service.
Published May 9, 2023 · Updated Jan 28, 2025
High · CVSS 8.8
Insufficient syscall input validation in the ASP
Bootloader may allow a privileged attacker to execute arbitrary DMA copies,
which can lead to code execution.
Published May 9, 2023 · Updated Jan 28, 2025
Medium · CVSS 6.8
Improper input validation in ABL may enable an
attacker with physical access, to perform arbitrary memory overwrites,
potentially leading to a loss of integrity and code execution.
Published May 9, 2023 · Updated Jan 28, 2025
Medium · CVSS 5.5
Insufficient bounds checking in ASP may allow an
attacker to issue a system call from a compromised ABL which may cause
arbitrary memory values to be initialized to zero, potentially leading to a
loss of integrity.
Published May 9, 2023 · Updated Jan 28, 2025
High · CVSS 7.4
A TOCTOU in ASP bootloader may allow an attacker
to tamper with the SPI ROM following data read to memory potentially resulting
in S3 data corruption and information disclosure.
Published May 9, 2023 · Updated Jan 28, 2025
High · CVSS 8.2
Certain size values in firmware binary headers
could trigger out of bounds reads during signature validation, leading to
denial of service or potentially limited leakage of information about
out-of-bounds memory contents.
Published May 9, 2023 · Updated Jan 28, 2025
Medium · CVSS 5.5
A compromised or malicious ABL or UApp could
send a SHA256 system call to the bootloader, which may result in exposure of
ASP memory to userspace, potentially leading to information disclosure.
Published May 9, 2023 · Updated Jan 28, 2025
High · CVSS 7.5
Insufficient validation in parsing Owner's
Certificate Authority (OCA) certificates in SEV (AMD Secure Encrypted Virtualization)
and SEV-ES user application can lead to a host crash potentially resulting in
denial of service.
Published May 9, 2023 · Updated Jan 28, 2025
High · CVSS 7.5
Insufficient bounds checking in ASP (AMD Secure
Processor) may allow for an out of bounds read in SMI (System Management
Interface) mailbox checksum calculation triggering a data abort, resulting in a
potential denial of service.
Published May 9, 2023 · Updated Jan 28, 2025
Critical · CVSS 9.1
Failure to validate the length fields of the ASP
(AMD Secure Processor) sensor fusion hub headers may allow an attacker with a
malicious Uapp or ABL to map the ASP sensor fusion hub region and overwrite
data structures leading to a potential loss of confidentiality and integrity.
Published May 9, 2023 · Updated Jan 28, 2025
High · CVSS 7.5
Failure to unmap certain SysHub mappings in
error paths of the ASP (AMD Secure Processor) bootloader may allow an attacker
with a malicious bootloader to exhaust the SysHub resources resulting in a
potential denial of service.
Published May 9, 2023 · Updated Jan 28, 2025
Critical · CVSS 9.1
Insufficient validation of inputs in
SVC_MAP_USER_STACK in the ASP (AMD Secure Processor) bootloader may allow an
attacker with a malicious Uapp or ABL to send malformed or invalid syscall to
the bootloader resulting in a potential denial of service and loss of
integrity.
Published May 9, 2023 · Updated Jan 28, 2025
High · CVSS 8.8
Insufficient input validation in ABL may enable
a privileged attacker to corrupt ASP memory, potentially resulting in a loss of
integrity or code execution.
Published May 9, 2023 · Updated Jan 28, 2025
Medium · CVSS 5.9
Time-of-check Time-of-use (TOCTOU) in the
BIOS2PSP command may allow an attacker with a malicious BIOS to create a race
condition causing the ASP bootloader to perform out-of-bounds SRAM reads upon
an S3 resume event potentially leading to a denial of service.
Published May 9, 2023 · Updated Jan 28, 2025
High · CVSS 7.5
Insufficient bounds checking in ASP (AMD Secure
Processor) may allow for an out of bounds read in SMI (System Management
Interface) mailbox checksum calculation triggering a data abort, resulting in a
potential denial of service.
Published May 9, 2023 · Updated Jan 28, 2025
High · CVSS 7.5
Buffer Overflow vulnerability found in En3rgy WebcamServer v.0.5.2 allows a remote attacker to cause a denial of service via the WebcamServer.exe file.
Published May 10, 2023 · Updated Jan 28, 2025
Medium · CVSS 6.1
Improper syscall input validation in AMD TEE
(Trusted Execution Environment) may allow an attacker with physical access and
control of a Uapp that runs under the bootloader to reveal the contents of the
ASP (AMD Secure Processor) bootloader accessible memory to a serial port,
resulting in a potential loss of integrity.
Published May 9, 2023 · Updated Jan 27, 2025
Critical · CVSS 9.8
A malicious or compromised UApp or ABL can send
a malformed system call to the bootloader, which may result in an out-of-bounds
memory access that may potentially lead to an attacker leaking sensitive
information or achieving code execution.
Published May 9, 2023 · Updated Jan 27, 2025
High · CVSS 7.5
Insufficient input validation in ASP may allow
an attacker with a compromised SMM to induce out-of-bounds memory reads within
the ASP, potentially leading to a denial of service.
Published May 9, 2023 · Updated Jan 27, 2025
High · CVSS 8.8
File Upload vulnerability in PHPOK 5.7.140 allows remote attackers to run arbitrary code and gain escalated privileges via crafted zip file upload.
Published May 11, 2023 · Updated Jan 27, 2025
Critical · CVSS 9.8
Product: AndroidVersions: Android SoCAndroid ID: A-273754094
Published May 15, 2023 · Updated Jan 24, 2025
Unknown · CVSS Not scored
An issue was discovered in hledger before 1.23. A Stored Cross-Site Scripting (XSS) vulnerability exists in toBloodhoundJson that allows an attacker to execute JavaScript by encoding user-controlled values in a payload with base64 and parsing them with the atob function.
Published May 21, 2023 · Updated Jan 21, 2025
High · CVSS 7.6
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use a newline character to bypass the sanitization of the `spec.rules[].http.paths[].path` field of an Ingress object (in the `networking.k8s.io` or `extensions` API group) to obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has access to all secrets in the cluster.
Published May 24, 2023 · Updated Jan 16, 2025
High · CVSS 7.8
Windows workloads can run as ContainerAdministrator even when those workloads set the runAsNonRoot option to true.
Published May 24, 2023 · Updated Jan 16, 2025
High · CVSS 7.5
The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability.
Published May 26, 2023 · Updated Jan 16, 2025
High · CVSS 7.5
The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability.
Published May 26, 2023 · Updated Jan 16, 2025
High · CVSS 7.5
The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability.
Published May 26, 2023 · Updated Jan 16, 2025
High · CVSS 7.5
The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability.
Published May 26, 2023 · Updated Jan 16, 2025
High · CVSS 7.5
The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability.
Published May 26, 2023 · Updated Jan 16, 2025
High · CVSS 7.5
The video framework has memory overwriting caused by addition overflow. Successful exploitation of this vulnerability may affect availability.
Published May 26, 2023 · Updated Jan 16, 2025
Critical · CVSS 9.8
Lack of length check vulnerability in the HW_KEYMASTER module. Successful exploitation of this vulnerability may cause out-of-bounds read.
Published May 26, 2023 · Updated Jan 15, 2025
High · CVSS 7.5
A directory traversal vulnerability on Mercury MAC1200R devices allows attackers to read arbitrary files via a web-static/ URL.
Published May 29, 2023 · Updated Jan 14, 2025
Low · CVSS 3.7
An issue was discovered in Citadel through webcit-932. A meddler-in-the-middle attacker can fixate their own session during the cleartext phase before a STARTTLS command (a violation of "The STARTTLS command is only valid in non-authenticated state." in RFC2595). This potentially allows an attacker to cause a victim's e-mail messages to be stored into an attacker's IMAP mailbox, but depends on details of the victim's client behavior.
Published May 29, 2023 · Updated Jan 14, 2025
Medium · CVSS 5.5
A vulnerability was found in ITRS Group monitor-ninja up to 2021.11.1. It has been rated as critical. Affected by this issue is some unknown functionality of the file modules/reports/models/scheduled_reports.php. The manipulation leads to sql injection. Upgrading to version 2021.11.30 is able to address this issue. The name of the patch is 6da9080faec9bca1ca5342386c0421dca0a6c0cc. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-230084.
Published May 28, 2023 · Updated Jan 13, 2025
High · CVSS 7.5
SQL Injection vulnerability found in Fighting Cock Information System v.1.0 allows a remote attacker to obtain sensitive information via the edit_breed.php parameter.
Published May 31, 2023 · Updated Jan 10, 2025
Critical · CVSS 9.8
Multiple models of the Uniview IP Camera (e.g., IPC_G6103 B6103.16.10.B25.201218, IPC_G61, IPC21, IPC23, IPC32, IPC36, IPC62, and IPC_HCMN) offer an undocumented UDP service on port 7788 that allows a remote unauthenticated attacker to overflow an internal buffer and achieve code execution. By using this buffer overflow, a remote attacker can start the telnetd service. This service has a hardcoded default username and password (root/123456). Although it has a restrictive shell, this can be easily bypassed via the built-in ECHO shell command.
Published May 31, 2023 · Updated Jan 10, 2025
Medium · CVSS 4.3
IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the attacker can then obtain the cookie value by snooping the traffic. IBM X-Force ID: 196640.
Published May 3, 2024 · Updated Dec 5, 2024
High · CVSS 8.8
Visual Studio Remote Code Execution Vulnerability
Published May 11, 2021 · Updated Nov 19, 2024
High · CVSS 7
Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the application. A successful exploit could allow the attacker to execute arbitrary code on an affected device with SYSTEM privileges. To exploit these vulnerabilities, the attacker must have valid credentials on the Windows system. For more information about these vulnerabilities, see the Details section of this advisory.
Published May 6, 2021 · Updated Nov 8, 2024
High · CVSS 7
Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the application. A successful exploit could allow the attacker to execute arbitrary code on an affected device with SYSTEM privileges. To exploit these vulnerabilities, the attacker must have valid credentials on the Windows system. For more information about these vulnerabilities, see the Details section of this advisory.
Published May 6, 2021 · Updated Nov 8, 2024
High · CVSS 7
Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the application. A successful exploit could allow the attacker to execute arbitrary code on an affected device with SYSTEM privileges. To exploit these vulnerabilities, the attacker must have valid credentials on the Windows system. For more information about these vulnerabilities, see the Details section of this advisory.
Published May 6, 2021 · Updated Nov 8, 2024
Medium · CVSS 5.5
A vulnerability in Cisco Wide Area Application Services (WAAS) Software could allow an authenticated, local attacker to gain access to sensitive information on an affected device. The vulnerability is due to improper input validation and authorization of specific commands that a user can execute within the CLI. An attacker could exploit this vulnerability by authenticating to an affected device and issuing a specific set of commands. A successful exploit could allow the attacker to read arbitrary files that they originally did not have permissions to access.
Published May 6, 2021 · Updated Nov 8, 2024
Medium · CVSS 6.7
A vulnerability in the user account management system of Cisco AsyncOS for Cisco Content Security Management Appliance (SMA) could allow an authenticated, local attacker to elevate their privileges to root. This vulnerability is due to a procedural flaw in the password generation algorithm. An attacker could exploit this vulnerability by enabling specific Administrator-only features and connecting to the appliance through the CLI with elevated privileges. A successful exploit could allow the attacker to execute arbitrary commands as root and access the underlying operating system. To exploit this vulnerability, the attacker must have valid Administrator credentials.
Published May 6, 2021 · Updated Nov 8, 2024
Critical · CVSS 9.8
Multiple vulnerabilities in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to execute arbitrary code or gain access to sensitive information, or allow an authenticated, local attacker to gain escalated privileges or gain unauthorized access to the application. For more information about these vulnerabilities, see the Details section of this advisory.
Published May 6, 2021 · Updated Nov 8, 2024
Medium · CVSS 5.3
A vulnerability in the Java Management Extensions (JMX) component of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to cause a denial of service (DoS) condition on an affected system. This vulnerability is due to an unsecured TCP/IP port. An attacker could exploit this vulnerability by accessing the port and restarting the JMX process. A successful exploit could allow the attacker to cause a DoS condition on an affected system.
Published May 6, 2021 · Updated Nov 8, 2024
Medium · CVSS 5.3
A vulnerability in Cisco SD-WAN vManage Software could allow an unauthenticated, remote attacker to enumerate user accounts. This vulnerability is due to the improper handling of HTTP headers. An attacker could exploit this vulnerability by sending authenticated requests to an affected system. A successful exploit could allow the attacker to compare the HTTP responses that are returned by the affected system to determine which accounts are valid user accounts.
Published May 6, 2021 · Updated Nov 8, 2024
Medium · CVSS 4.7
A vulnerability in the web-based management interface of Cisco AsyncOS for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit this vulnerability by persuading a user to retrieve a crafted file that contains malicious payload and upload it to the affected device. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information.
Published May 6, 2021 · Updated Nov 8, 2024
High · CVSS 7
Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the application. A successful exploit could allow the attacker to execute arbitrary code on an affected device with SYSTEM privileges. To exploit these vulnerabilities, the attacker must have valid credentials on the Windows system. For more information about these vulnerabilities, see the Details section of this advisory.
Published May 6, 2021 · Updated Nov 8, 2024