CVE-2023-36846 - Juniper Networks Junos OS sérülékenysége
Hiányzó hitelesítés a kritikus funkcióhoz: A szoftver nem végez semmilyen hitelesítést olyan funkcionalitáshoz, amely bizonyítható felhasználói azonosítót igényel, vagy jelentős mennyiségű erőforrást fogyaszt.
CVE-2023-36845 - Juniper Networks Junos OS sérülékenysége
PHP külső változó módosítása: A PHP-alkalmazás nem védekezik megfelelően a külső forrásból származó változók, például a lekérdezési paraméterek vagy a cookie-k módosítása ellen. Ez számos olyan gyenge pontnak teheti ki az alkalmazást, amelyek...
CVE-2023-36844 - Juniper Networks Junos OS sérülékenysége
PHP külső változó módosítása: A PHP-alkalmazás nem védekezik megfelelően a külső forrásból származó változók, például a lekérdezési paraméterek vagy a cookie-k módosítása ellen. Ez számos olyan gyenge pontnak teheti ki az alkalmazást, amelyek...
A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent, Virtual Appliance installation type, could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient input...
A vulnerability in the CLI of Cisco ThousandEyes Enterprise Agent, Virtual Appliance installation type, could allow an authenticated, local attacker to elevate privileges to root on an affected device. This vulnerability is due to insufficient input...
A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability...
Date: August 23, 2023 Revision Date Changes 1.0 August 23, 2023 Initial release The CVE-ID tracking this issue: CVE-2023-24548 CVSSv3.1 Base Score: 5.3 (CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H) Common Weakness Enumeration: CWE-120 Buffer Copy...
Date: August 23, 2023 Revision Date Changes 1.0 August 23, 2023 Initial release The CVE-ID tracking this issue: CVE-2023-3646 CVSSv3.1 Base Score: 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H) Common Weakness Enumeration: CWE-125 Out-of-bounds...
ClamAV AutoIt Module Denial of Service Vulnerability
A vulnerability in the AutoIt module of ClamAV could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to a logic error in the memory management of an affected...
A vulnerability in the web-based management interface of Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an authenticated, remote attacker to conduct...