| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| On some hardware revisions where VP9 decoding is hardware-accelerated, the frame size is not programmed correctly into the decoder hardware which can lead to an invalid memory access by the decoder. |
| Download Center fails to properly validate the file path submitted by a user, An attacker can exploit this vulnerability to gain unauthorized access to sensitive files or directories without appropriate permission restrictions. Download Center on ADM 4.0 and above will be affected. Affected products and versions include: Download Center 1.1.5.r1280 and below. |
| Buffer overwrite in the WLAN host driver by leveraging a compromised WLAN FW |
| EZ Sync service fails to adequately handle user input, allowing an attacker to navigate beyond the intended directory structure and delete files. Affected products and versions include: ADM 4.0.6.REG2, 4.1.0 and below as well as ADM 4.2.1.RGE2 and below. |
| In multiple functions that process 802.11 frames, out-of-bounds reads can occur due to insufficient validation. |
| In JetBrains TeamCity before 2023.05 bypass of permission checks allowing to perform admin actions was possible |
| A race condition exists in a driver potentially leading to a use-after-free condition. |
| Wrong configuration in Touch Pal application can collect user behavior data without awareness by the user. |
| An image with a version lower than the fuse version may potentially be booted lead to improper authentication. |
|
Dell NetWorker 19.6.1.2, contains an OS command injection Vulnerability in the NetWorker client. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application. This is a high severity vulnerability as the exploitation allows an attacker to take complete control of a system, so Dell recommends customers to upgrade at the earliest opportunity.
|
| In JetBrains TeamCity before 2023.05 improper permission checks allowed users without appropriate permissions to edit Build Configuration settings via REST API |
| In JetBrains TeamCity before 2023.05 stored XSS in the Show Connection page was possible |
| In JetBrains TeamCity before 2023.05 possible XSS in the Plugin Vendor URL was possible |
| In JetBrains TeamCity before 2023.05 parameters of the "password" type from build dependencies could be logged in some cases |
| In JetBrains TeamCity before 2023.05 open redirect during oAuth configuration was possible |
| In JetBrains TeamCity before 2023.05 stored XSS in the NuGet feed page was possible |
| In JetBrains TeamCity before 2023.05 reflected XSS in the Subscriptions page was possible |
| In JetBrains TeamCity before 2023.05 a specific endpoint was vulnerable to brute force attacks |
| In JetBrains TeamCity before 2023.05 authentication checks were missing – 2FA was not checked for some sensitive account actions |
| In JetBrains TeamCity before 2023.05 stored XSS in GitLab Connection page was possible |