unSafe.sh - 不安全
我的收藏
今日热榜
公众号文章
导航
Github CVE
Github Tools
编码/解码
文件传输
Twitter Bot
Telegram Bot
Search
Rss
黑夜模式
增加标签
Tags (allow clear + 0 threshold)
Choose a tag...
Please select a valid tag.
Live-Hack-CVE/CVE-2021-26346
Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in the L2 directory table in SPI flash resulting in a potential denial of service. CVE project by @Sn0wAlice
Create: 2023-01-11 19:13:13 +0000 UTC Push: 2023-01-11 19:13:16 +0000 UTC |
Live-Hack-CVE/CVE-2021-26343
Insufficient validation in ASP BIOS and DRTM commands may allow malicious supervisor x86 software to disclose the contents of sensitive memory which may result in information disclosure. CVE project by @Sn0wAlice
Create: 2023-01-11 19:13:08 +0000 UTC Push: 2023-01-11 19:13:11 +0000 UTC |
Live-Hack-CVE/CVE-2021-26316
Failure to validate the communication buffer and communication service in the BIOS may allow an attacker to tamper with the buffer resulting in potential SMM (System Management Mode) arbitrary code execution. CVE project by @Sn0wAlice
Create: 2023-01-11 19:13:03 +0000 UTC Push: 2023-01-11 19:13:07 +0000 UTC |
Live-Hack-CVE/CVE-2023-22885
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none. CVE project by @Sn0wAlice
Create: 2023-01-11 19:12:59 +0000 UTC Push: 2023-01-11 19:13:02 +0000 UTC |
Live-Hack-CVE/CVE-2023-20532
Insufficient input validation in the SMU may allow an attacker to improperly lock resources, potentially resulting in a denial of service. CVE project by @Sn0wAlice
Create: 2023-01-11 19:12:54 +0000 UTC Push: 2023-01-11 19:12:57 +0000 UTC |
Live-Hack-CVE/CVE-2023-20531
Insufficient bound checks in the SMU may allow an attacker to update the SRAM from/to address space to an invalid value potentially resulting in a denial of service. CVE project by @Sn0wAlice
Create: 2023-01-11 19:12:49 +0000 UTC Push: 2023-01-11 19:12:53 +0000 UTC |
Live-Hack-CVE/CVE-2023-20530
Insufficient input validation of BIOS mailbox messages in SMU may result in out-of-bounds memory reads potentially resulting in a denial of service. CVE project by @Sn0wAlice
Create: 2023-01-11 19:12:46 +0000 UTC Push: 2023-01-11 19:12:48 +0000 UTC |
Live-Hack-CVE/CVE-2023-20529
Insufficient bound checks in the SMU may allow an attacker to update the from/to address space to an invalid value potentially resulting in a denial of service. CVE project by @Sn0wAlice
Create: 2023-01-11 19:12:42 +0000 UTC Push: 2023-01-11 19:12:44 +0000 UTC |
Live-Hack-CVE/CVE-2023-20528
Insufficient input validation in the SMU may allow a physical attacker to exfiltrate SMU memory contents over the I2C bus potentially leading to a loss of confidentiality. CVE project by @Sn0wAlice
Create: 2023-01-11 19:12:37 +0000 UTC Push: 2023-01-11 19:12:41 +0000 UTC |
Live-Hack-CVE/CVE-2023-20527
Improper syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory out-of-bounds, potentially leading to a denial-of-service. CVE project by @Sn0wAlice
Create: 2023-01-11 19:12:33 +0000 UTC Push: 2023-01-11 19:12:36 +0000 UTC |
Live-Hack-CVE/CVE-2023-20525
Insufficient syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory outside the bounds of a mapped register potentially leading to a denial of service. CVE project by @Sn0wAlice
Create: 2023-01-11 19:12:28 +0000 UTC Push: 2023-01-11 19:12:31 +0000 UTC |
Live-Hack-CVE/CVE-2023-20523
TOCTOU in the ASP may allow a physical attacker to write beyond the buffer bounds, potentially leading to a loss of integrity or denial of service. CVE project by @Sn0wAlice
Create: 2023-01-11 19:12:23 +0000 UTC Push: 2023-01-11 19:12:26 +0000 UTC |
Live-Hack-CVE/CVE-2023-0161
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate is unused by its CNA. Notes: none. CVE project by @Sn0wAlice
Create: 2023-01-11 19:12:18 +0000 UTC Push: 2023-01-11 19:12:22 +0000 UTC |
Live-Hack-CVE/CVE-2022-23814
Failure to validate addresses provided by software to BIOS commands may result in a potential loss of integrity of guest memory in a confidential compute environment. CVE project by @Sn0wAlice
Create: 2023-01-11 19:12:14 +0000 UTC Push: 2023-01-11 19:12:17 +0000 UTC |
Live-Hack-CVE/CVE-2022-23813
The software interfaces to ASP and SMU may not enforce the SNP memory security policy resulting in a potential loss of integrity of guest memory in a confidential compute environment. CVE project by @Sn0wAlice
Create: 2023-01-11 19:12:09 +0000 UTC Push: 2023-01-11 19:12:12 +0000 UTC |
Live-Hack-CVE/CVE-2021-46767
Insufficient input validation in the ASP may allow an attacker with physical access, unauthorized write access to memory potentially leading to a loss of integrity or denial of service. CVE project by @Sn0wAlice
Create: 2023-01-11 19:12:04 +0000 UTC Push: 2023-01-11 19:12:08 +0000 UTC |
Live-Hack-CVE/CVE-2023-22952
In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation. CVE project by @Sn0wAlice
Create: 2023-01-11 19:12:00 +0000 UTC Push: 2023-01-11 19:12:03 +0000 UTC |
Live-Hack-CVE/CVE-2022-34440
Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability. An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerability to login to the system to gain admin privileges. CVE project by @Sn0wAlice
Create: 2023-01-11 19:11:56 +0000 UTC Push: 2023-01-11 19:11:59 +0000 UTC |
Live-Hack-CVE/CVE-2022-34441
Dell EMC SCG Policy Manager, versions from 5.10 to 5.12, contain(s) a contain a Hard-coded Cryptographic Key vulnerability. An attacker with the knowledge of the hard-coded sensitive information, could potentially exploit this vulnerability to login to the system to gain admin privileges. CVE project by @Sn0wAlice
Create: 2023-01-11 19:11:51 +0000 UTC Push: 2023-01-11 19:11:55 +0000 UTC |
Live-Hack-CVE/CVE-2022-34330
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.2.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 22 CVE project by @Sn0wAlice
Create: 2023-01-11 14:52:53 +0000 UTC Push: 2023-01-11 14:52:56 +0000 UTC |
Previous
835
836
837
838
839
840
841
842
Next