Medium - CVE-2023-50956 - IBM Storage Defender - Resiliency Service 2.0.0...
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9 could allow a privileged user to obtain highly sensitive user credentials from secret keys that are stored in clear text.
NA - CVE-2024-12371 - A device takeover vulnerability exists in the...
A device takeover vulnerability exists in the Rockwell Automation Power Monitor 1000. This vulnerability allows configuration of a new Policyholder user without any authentication via API....
NA - CVE-2024-12372 - A denial-of-service and possible remote code...
A denial-of-service and possible remote code execution vulnerability exists in the Rockwell Automation Power Monitor 1000. The vulnerability results in corruption of the heap memory which may...
NA - CVE-2024-12373 - A denial-of-service vulnerability exists in the...
A denial-of-service vulnerability exists in the Rockwell Automation Power Monitor 1000. The vulnerability results in a buffer-overflow, potentially causing denial-of-service.
Medium - CVE-2024-47119 - IBM Storage Defender - Resiliency Service 2.0.0...
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9 does not properly validate a certificate which could allow an attacker to spoof a trusted entity by interfering in the communication...
NA - CVE-2024-47810 - A use-after-free vulnerability exists in the...
A use-after-free vulnerability exists in the way Foxit Reader 2024.3.0.26795 handles a 3D page object. A specially crafted Javascript code inside a malicious PDF document can trigger this...
NA - CVE-2024-49576 - A use-after-free vulnerability exists in the...
A use-after-free vulnerability exists in the way Foxit Reader 2024.3.0.26795 handles a checkbox CBF_Widget object. A specially crafted Javascript code inside a malicious PDF document can trigger...
Medium - CVE-2024-52361 - IBM Storage Defender - Resiliency Service 2.0.0...
IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.9 stores user credentials in plain text which can be read by an authenticated user with access to the pod.
Medium - CVE-2024-25042 - IBM Cognos Analytics 11.2.0 through 11.2.4 and...
IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 is potentially vulnerable to Cross Site Scripting (XSS). A remote attacker could execute malicious commands due to improper...