Filtered by vendor Ivanti
Subscriptions
Total
320 CVE
CVE | Vendors | Products | Updated | CVSS v3.1 |
---|---|---|---|---|
CVE-2024-39710 | 1 Ivanti | 2 Connect Secure, Policy Secure | 2024-11-13 | N/A |
Argument injection in Ivanti Connect Secure before version 22.7R2 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution. | ||||
CVE-2024-38649 | 1 Ivanti | 1 Connect Secure | 2024-11-13 | N/A |
An out-of-bounds write in IPsec of Ivanti Connect Secure before version 22.7R2.1 allows a remote unauthenticated attacker to cause a denial of service. | ||||
CVE-2024-37400 | 1 Ivanti | 1 Connect Secure | 2024-11-13 | N/A |
An out of bounds read in Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to trigger an infinite loop, causing a denial of service. | ||||
CVE-2024-9420 | 1 Ivanti | 2 Connect Secure, Policy Secure | 2024-11-13 | 8.8 High |
A use-after-free in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker to achieve remote code execution. | ||||
CVE-2024-11005 | 1 Ivanti | 2 Connect Secure, Policy Secure | 2024-11-13 | 9.1 Critical |
Command injection in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution. | ||||
CVE-2024-50331 | 1 Ivanti | 1 Avalanche | 2024-11-13 | 7.5 High |
An out-of-bounds read vulnerability in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to leak sensitive information in memory. | ||||
CVE-2024-11006 | 1 Ivanti | 2 Connect Secure, Policy Secure | 2024-11-13 | 9.1 Critical |
Command injection in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution. | ||||
CVE-2024-8539 | 1 Ivanti | 1 Secure Access Client | 2024-11-13 | 7.1 High |
Improper authorization in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker to modify sensitive configuration files. | ||||
CVE-2024-9843 | 1 Ivanti | 1 Secure Access Client | 2024-11-13 | 5 Medium |
A buffer over-read in Ivanti Secure Access Client before 22.7R4 allows a local unauthenticated attacker to cause a denial of service. | ||||
CVE-2024-39712 | 1 Ivanti | 2 Connect Secure, Policy Secure | 2024-11-13 | N/A |
Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution. | ||||
CVE-2024-38655 | 1 Ivanti | 2 Connect Secure, Policy Secure | 2024-11-13 | N/A |
Argument injection in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution. | ||||
CVE-2024-29824 | 1 Ivanti | 1 Endpoint Manager | 2024-11-05 | 8.8 High |
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code. | ||||
CVE-2024-9167 | 1 Ivanti | 1 Velocity License Server | 2024-11-04 | 7.8 High |
Under specific circumstances, insecure permissions in Ivanti Velocity License Server before version 5.2 allows a local authenticated attacker to achieve local privilege escalation. | ||||
CVE-2024-36130 | 1 Ivanti | 1 Endpoint Manager Mobile | 2024-10-24 | 9.8 Critical |
An insufficient authorization vulnerability in web component of EPMM prior to 12.1.0.1 allows an unauthorized attacker within the network to execute arbitrary commands on the underlying operating system of the appliance. | ||||
CVE-2023-35077 | 2 Ivanti, Microsoft | 2 Endpoint Manager, Windows | 2024-10-24 | 7.5 High |
An out-of-bounds write vulnerability on windows operating systems causes the Ivanti AntiVirus Product to crash. Update to Ivanti AV Product version 7.9.1.285 or above. | ||||
CVE-2024-29821 | 1 Ivanti | 1 Desktop \& Server Management | 2024-10-21 | N/A |
Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified attack vector. | ||||
CVE-2024-29213 | 1 Ivanti | 1 Desktop \& Server Management | 2024-10-21 | N/A |
Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified attack vector. | ||||
CVE-2024-37404 | 1 Ivanti | 2 Connect Secure, Policy Secure | 2024-10-21 | N/A |
Improper Input Validation in the admin portal of Ivanti Connect Secure before 22.7R2.1 and 9.1R18.9, or Ivanti Policy Secure before 22.7R1.1 allows a remote authenticated attacker to achieve remote code execution. | ||||
CVE-2023-41474 | 1 Ivanti | 1 Avalanche | 2024-10-18 | 6.5 Medium |
Directory Traversal vulnerability in Ivanti Avalanche 6.3.4.153 allows a remote authenticated attacker to obtain sensitive information via the javax.faces.resource component. | ||||
CVE-2024-7612 | 1 Ivanti | 1 Endpoint Manager Mobile | 2024-10-17 | 8.8 High |
Insecure permissions in Ivanti EPMM before 12.1.0.4 allow a local authenticated attacker to modify sensitive application components. |