Search Results (8277 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2023-28086 1 Hp 1 Oneview 2025-02-03 5.5 Medium
An HPE OneView appliance dump may expose proxy credential settings
CVE-2023-26567 1 Sangoma 1 Freepbx Linux 7 2025-02-03 8.1 High
Sangoma FreePBX 1805 through 2302 (when obtained as a ,.ISO file) places AMPDBUSER, AMPDBPASS, AMPMGRUSER, and AMPMGRPASS in the list of global variables. This exposes cleartext authentication credentials for the Asterisk Database (MariaDB/MySQL) and Asterisk Manager Interface. For example, an attacker can make a /ari/asterisk/variable?variable=AMPDBPASS API call.
CVE-2023-28090 1 Hp 1 Oneview 2025-02-03 5.5 Medium
An HPE OneView appliance dump may expose SNMPv3 read credentials
CVE-2023-28089 1 Hp 1 Oneview 2025-02-03 7.1 High
An HPE OneView appliance dump may expose FTP credentials for c7000 Interconnect Modules
CVE-2023-28088 1 Hp 1 Oneview 2025-02-03 7.8 High
An HPE OneView appliance dump may expose SAN switch administrative credentials
CVE-2023-28084 2 Hp, Hpe 2 Oneview, Oneview Global Dashboard 2025-02-03 5.5 Medium
HPE OneView and HPE OneView Global Dashboard appliance dumps may expose authentication tokens
CVE-2024-37060 1 Lfprojects 1 Mlflow 2025-02-03 8.8 High
Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.27.0 or newer, enabling a maliciously crafted Recipe to execute arbitrary code on an end user’s system when run.
CVE-2024-37059 1 Lfprojects 1 Mlflow 2025-02-03 8.8 High
Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.5.0 or newer, enabling a maliciously uploaded PyTorch model to run arbitrary code on an end user’s system when interacted with.
CVE-2024-37058 1 Lfprojects 1 Mlflow 2025-02-03 8.8 High
Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.5.0 or newer, enabling a maliciously uploaded Langchain AgentExecutor model to run arbitrary code on an end user’s system when interacted with.
CVE-2024-37057 1 Lfprojects 1 Mlflow 2025-02-03 8.8 High
Deserialization of untrusted data can occur in versions of the MLflow platform running version 2.0.0rc0 or newer, enabling a maliciously uploaded Tensorflow model to run arbitrary code on an end user’s system when interacted with.
CVE-2024-37056 1 Lfprojects 1 Mlflow 2025-02-03 8.8 High
Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.23.0 or newer, enabling a maliciously uploaded LightGBM scikit-learn model to run arbitrary code on an end user’s system when interacted with.
CVE-2024-37055 1 Lfprojects 1 Mlflow 2025-02-03 8.8 High
Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.24.0 or newer, enabling a maliciously uploaded pmdarima model to run arbitrary code on an end user’s system when interacted with.
CVE-2024-37054 1 Lfprojects 1 Mlflow 2025-02-03 8.8 High
Deserialization of untrusted data can occur in versions of the MLflow platform running version 0.9.0 or newer, enabling a maliciously uploaded PyFunc model to run arbitrary code on an end user’s system when interacted with.
CVE-2024-37053 1 Lfprojects 1 Mlflow 2025-02-03 8.8 High
Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling a maliciously uploaded scikit-learn model to run arbitrary code on an end user’s system when interacted with.
CVE-2024-37052 1 Lfprojects 1 Mlflow 2025-02-03 8.8 High
Deserialization of untrusted data can occur in versions of the MLflow platform running version 1.1.0 or newer, enabling a maliciously uploaded scikit-learn model to run arbitrary code on an end user’s system when interacted with.
CVE-2022-38730 1 Docker 1 Desktop 2025-01-31 6.3 Medium
Docker Desktop for Windows before 4.6 allows attackers to overwrite any file through the windowscontainers/start dockerBackendV2 API by controlling the data-root field inside the DaemonJSON field in the WindowsContainerStartRequest class. This allows exploiting a symlink vulnerability in ..\dataRoot\network\files\local-kv.db because of a TOCTOU race condition.
CVE-2022-34292 1 Docker 1 Desktop 2025-01-31 7.1 High
Docker Desktop for Windows before 4.6.0 allows attackers to overwrite any file through a symlink attack on the hyperv/create dockerBackendV2 API by controlling the DataFolder parameter for DockerDesktop.vhdx, a similar issue to CVE-2022-31647.
CVE-2022-31647 1 Docker 1 Desktop 2025-01-31 7.1 High
Docker Desktop before 4.6.0 on Windows allows attackers to delete any file through the hyperv/destroy dockerBackendV2 API via a symlink in the DataFolder parameter, a different vulnerability than CVE-2022-26659.
CVE-2024-40679 1 Ibm 1 Db2 2025-01-31 5.5 Medium
IBM Db2 for Linux, UNIX and Windows (includes Db2 Connect Server) 11.5 is vulnerable to an information disclosure vulnerability as sensitive information may be included in a log file under specific conditions.
CVE-2025-24794 2025-01-31 6.7 Medium
The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. The OCSP response cache uses pickle as the serialization format, potentially leading to local privilege escalation. This vulnerability affects versions 2.7.12 through 3.13.0. Snowflake fixed the issue in version 3.13.1.