7.3

CVSS3.1

CVE-2024-11346 - Access of Resource Using Incompatible Type in Postscript interpreter

: Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Lexmark International CX, XC, CS, et. Al. (Postscript interpreter modules) allows Resource Injection.This issue affects CX, XC, CS, et. Al.: from 001.001:0 through 081.231, from *.*.P001 through *.*.P233, from *.*.P001โ€ฆ

๐Ÿ“… Published: Feb. 13, 2025, 6:54 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.3

CVSS3.1

CVE-2024-11344 - Type confusion vulnerability in the Postscript interpreter in various Lexmark devices

A type confusion vulnerability has been identified in the Postscript interpreter in various Lexmark devices. The vulnerability can be leveraged by an attacker to execute arbitrary code.

๐Ÿ“… Published: Feb. 13, 2025, 6:51 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2025-1127 - Combination Path Traversal and Concurrent Execution vulnerability exists within the embedded web seโ€ฆ

The vulnerability can be leveraged by an attacker to execute arbitrary code as an unprivileged user and/or modify the contents of any data on the filesystem.

๐Ÿ“… Published: Feb. 13, 2025, 6:49 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.3

CVSS3.1

CVE-2024-11345 - Heap-based memory vulnerability in the Postscript interpreter in various Lexmark devices

A heap-based memory vulnerability has been identified in the Postscript interpreter in various Lexmark devices. The vulnerability can be leveraged by an attacker to execute arbitrary code.

๐Ÿ“… Published: Feb. 13, 2025, 6:46 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.5

CVSS3.1

CVE-2025-24889 - Path traversal in sd-log Qubes virtual machine

The SecureDrop Client is a desktop application for journalists to communicate with sources and work with submissions on the SecureDrop Workstation. Prior to versions 0.14.1 and 1.0.1, an attacker who has already gained code execution in a virtual machine on the SecureDrop Workstation could gain codโ€ฆ

๐Ÿ“… Published: Feb. 13, 2025, 5:34 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS3.1

CVE-2025-24888 - Path traversal in SecureDrop Client API.download_reply()

The SecureDrop Client is a desktop application for journalists to communicate with sources and work with submissions on the SecureDrop Workstation. Prior to version 0.14.1, a malicious SecureDrop Server could obtain code execution on the SecureDrop Client virtual machine (`sd-app`). SecureDrop Servโ€ฆ

๐Ÿ“… Published: Feb. 13, 2025, 5:32 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7

CVSS3.1

CVE-2025-22480 -

Dell SupportAssist OS Recovery versions prior to 5.5.13.1 contain a symbolic link attack vulnerability. A low-privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary file deletion and Elevation of Privileges.

๐Ÿ“… Published: Feb. 13, 2025, 4:04 p.m. ๐Ÿ”„ Last Modified: Sept. 24, 2025, 2:45 p.m.

7.6

CVSS3.1

CVE-2024-12013 -

A CWE-1392 โ€œUse of Default Credentialsโ€ was discovered affecting the 130.8005 TCP/IP Gateway running firmware version 12h. The device exposes an FTP server with default and easy-to-guess admin credentials. A remote attacker capable of interacting with the FTP server could gain access and perform chโ€ฆ

๐Ÿ“… Published: Feb. 13, 2025, 4:03 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.7

CVSS3.1

CVE-2024-12012 -

A CWE-598 โ€œUse of GET Request Method with Sensitive Query Stringsโ€ was discovered affecting the 130.8005 TCP/IP Gateway running firmware version 12h. Both the SHA-1 hash of the password as well as the session tokens are included as part of the URL and therefore exposed to information leakage scenarโ€ฆ

๐Ÿ“… Published: Feb. 13, 2025, 4:01 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.6

CVSS3.1

CVE-2024-12011 -

A CWE-126 โ€œBuffer Over-readโ€ was discovered affecting the 130.8005 TCP/IP Gateway running firmware version 12h. The information disclosure can be triggered by leveraging a memory leak affecting the web server. A remote unauthenticated attacker can exploit this vulnerability in order to leak valid aโ€ฆ

๐Ÿ“… Published: Feb. 13, 2025, 3:59 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 345342
Page 6354 of 34,535
ยซ previous page ยป next page
Filters