5.3
CVE-2024-28762 - IBM Db2 denial of service
IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.5, 11.1, and 11.5 is vulnerable to denial of service with a specially crafted query under certain conditions. IBM X-Force ID: 285246.
7.8
CVE-2024-0865 -
CWE-798: Use of hard-coded credentials vulnerability exists that could cause local privilege escalation when logged in as a non-administrative user.
6.1
CVE-2024-5559 -
CWE-327: Use of a Broken or Risky Cryptographic Algorithm vulnerability exists that could cause denial of service, device reboot, or an attacker gaining full control of the relay when a specially crafted reset token is entered into the front panel of the device.
7.8
CVE-2024-2747 -
CWE-428: Unquoted search path or element vulnerability exists in Easergy Studio, which could cause privilege escalation when a valid user replaces a trusted file name on the system and reboots the machine.
0.0
CVE-2024-2230 -
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
5.4
CVE-2024-37040 -
CWE-120: Buffer Copy without Checking Size of Input (โClassic Buffer Overflowโ) vulnerability exists that could allow a user with access to the deviceโs web interface to cause a fault on the device when sending a malformed HTTP request.
5.9
CVE-2024-37039 -
CWE-252: Unchecked Return Value vulnerability exists that could cause denial of service of the device when an attacker sends a specially crafted HTTP request.
7.5
CVE-2024-37038 -
CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated user with access to the deviceโs web interface to perform unauthorized file and firmware uploads when crafting custom web requests.
8.1
CVE-2024-37037 -
CWE-22: Improper Limitation of a Pathname to a Restricted Directory (โPath Traversalโ) vulnerability exists that could allow an authenticated user with access to the deviceโs web interface to corrupt files and impact device functionality when sending a crafted HTTP request.
9.8
CVE-2024-37036 -
CWE-787: Out-of-bounds Write vulnerability exists that could result in an authentication bypass when sending a malformed POST request and particular configuration parameters are set.