7
CVE-2024-9841 - OpenText ArcSight Management Center and ArcSight Platform Stored XSS
A Reflected Cross-Site Scripting (XSS) vulnerability has been identified in OpenText ArcSight Management Center and ArcSight Platform. The vulnerability could be remotely exploited.
9.1
CVE-2024-45763 -
Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. This iβ¦
9
CVE-2024-45764 -
Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) a Missing Critical Step in Authentication vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Protection mechanism bypass. This is a critical severity vulnerability so Deβ¦
8.1
CVE-2024-10220 - Arbitrary command execution through gitRepo volume
The Kubernetes kubelet component allows arbitrary command execution via specially crafted gitRepo volumes.This issue affects kubelet: through 1.28.11, from 1.29.0 through 1.29.6, from 1.30.0 through 1.30.2.
9.1
CVE-2024-45765 -
Dell Enterprise SONiC OS, version(s) 4.1.x, 4.2.x, contain(s) an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Command execution. This iβ¦
4.9
CVE-2024-50378 - Apache Airflow: Secrets not masked in UI when sensitive variables are set via Airflow cli
Airflow versions before 2.10.3 have a vulnerability that allows authenticated users with audit log access to see sensitive values in audit logs which they should not see.Β When sensitive variables were set via airflow CLI, values of those variables appeared in the audit log and were stored unencryptβ¦
7
CVE-2024-50592 - Local Privilege Escalation via Race Condition
An attacker with local access the to medical office computer can escalate his Windows user privileges to "NT AUTHORITY\SYSTEM" by exploiting a race condition in the Elefant Update Service during the repair or update process.Β When using the repair function, the service queries the server for a lβ¦
7.8
CVE-2024-50593 - Hardcoded Service Password
An attacker with local access to the medical office computer can access restricted functions of the Elefant Service tool by using a hard-coded "Hotline" password in the Elefant service binary, which is shipped with the software.
7.8
CVE-2024-50591 - Local Privilege Escalation via Command Injection
An attacker with local access the to medical office computer can escalate his Windows user privileges to "NT AUTHORITY\SYSTEM" by exploiting a command injection vulnerability in the Elefant Update Service. The command injection can be exploited by communicating with the Elefant Update Service wβ¦
7.8
CVE-2024-50590 - Local Privilege Escalation via Weak Service Binary Permissions
Attackers with local access to the medical office computer can escalate their Windows user privileges to "NT AUTHORITY\SYSTEM" by overwriting one of two Elefant service binaries with weak permissions.Β The default installation directory of Elefant is "C:\Elefant1" which is writable for all users.β¦