Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2024-02-17 CVE-2024-20905 Unspecified vulnerability in Oracle JD Edwards Enterpriseone Tools
Vulnerability in the JD Edwards EnterpriseOne Tools product of Oracle JD Edwards (component: Enterprise Infrastructure SEC).
network
low complexity
oracle
2.7
2024-02-16 CVE-2024-1591 Unspecified vulnerability in Beyondtrust Privilege Management for Windows
Prior to version 24.1, a local authenticated attacker can view Sysvol when Privilege Management for Windows is configured to use a GPO policy.
local
low complexity
beyondtrust
3.3
2024-02-16 CVE-2024-23591 Unspecified vulnerability in Lenovo Thinksystem Sr670 V2 Firmware 2.60Tgbt42H/U8E118M
ThinkSystem SR670V2 servers manufactured from approximately June 2021 to July 2023 were left in Manufacturing Mode which could allow an attacker with privileged logical access to the host or physical access to server internals to modify or disable Intel Boot Guard firmware integrity, SPS security, and other SPS configuration setting. The server’s NIST SP 800-193-compliant Platform Firmware Resiliency (PFR) security subsystem significantly mitigates this issue.
local
low complexity
lenovo
2.3
2024-02-16 CVE-2023-40122 Unspecified vulnerability in Google Android
In applyCustomDescription of SaveUi.java, there is a possible way to view other user's images due to a confused deputy.
local
low complexity
google
3.3
2024-02-16 CVE-2024-0037 Missing Authorization vulnerability in Google Android
In applyCustomDescription of SaveUi.java, there is a possible way to view images belonging to a different user due to a missing permission check.
local
low complexity
google CWE-862
3.3
2024-02-14 CVE-2023-26591 Unchecked Return Value vulnerability in Intel Thunderbolt DCH Driver 1.41.1054.0/72
Unchecked return value in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an unauthenticated user to potentially enable denial of service via physical access.
high complexity
intel CWE-252
2.0
2024-02-14 CVE-2023-26592 Deserialization of Untrusted Data vulnerability in Intel Thunderbolt DCH Driver 1.41.1054.0/72
Deserialization of untrusted data in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable a denial of service via local access.
local
low complexity
intel CWE-502
3.8
2024-02-14 CVE-2023-26596 Unspecified vulnerability in Intel Thunderbolt DCH Driver 1.41.1054.0/72
Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable denial of service via local access.
local
high complexity
intel
2.5
2024-02-14 CVE-2023-27300 Unspecified vulnerability in Intel Thunderbolt DCH Driver 1.41.1054.0/72
Improper buffer restrictions in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable information disclosure via local access.
local
low complexity
intel
3.8
2024-02-14 CVE-2023-27303 Unspecified vulnerability in Intel Thunderbolt DCH Driver 1.41.1054.0/72
Improper access control in some Intel(R) Thunderbolt(TM) DCH drivers for Windows before version 88 may allow an authenticated user to potentially enable information disclosure via local access.
local
low complexity
intel
3.8