VYPR

Vendor CVEs

Intel

All CVEs

2,357 total · sorted by risk
  • CVE-2021-44228CriKEVDec 10, 2021
    risk 0.94cvss 10.0epss 1.00

    Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log…

  • CVE-2021-45046CriKEVDec 14, 2021
    risk 0.87cvss 9.0epss 1.00

    It was found that the fix to address CVE-2021-44228 in Apache Log4j 2.15.0 was incomplete in certain non-default configurations. This could allows attackers with control over Thread Context Map (MDC) input data when the logging configuration uses a non-default Pattern Layout…

  • CVE-2017-5689CriKEVMay 2, 2017
    risk 0.86cvss 9.8epss 0.92

    An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged local attacker could provision manageability features gaining unprivileged…

  • CVE-2015-2291HigKEVAug 9, 2017
    risk 0.72cvss 7.8epss 0.09

    (1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges via a crafted (a) 0x80862013, (b) 0x8086200B, (c)…

  • CVE-2024-22476CriMay 16, 2024
    risk 0.68cvss 10.0epss 0.36

    Improper input validation in some Intel(R) Neural Compressor software before version 2.5.0 may allow an unauthenticated user to potentially enable escalation of privilege via remote access.

  • CVE-2023-31273CriNov 14, 2023
    risk 0.65cvss 10.0epss 0.01

    Protection mechanism failure in some Intel DCM software before version 5.2 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

  • CVE-2021-39296CriSep 9, 2021
    risk 0.65cvss 10.0epss 0.03

    In OpenBMC 2.9, crafted IPMI messages allow an attacker to bypass authentication and gain full control of the system.

  • CVE-2016-8027CriMar 14, 2017
    risk 0.65cvss 10.0epss 0.06

    SQL injection vulnerability in core services in Intel Security McAfee ePolicy Orchestrator (ePO) 5.3.2 and earlier and 5.1.3 and earlier allows attackers to alter a SQL query, which can result in disclosure of information within the database or impersonation of an agent without…

  • CVE-2024-26853CriApr 17, 2024
    risk 0.64cvss 9.8epss 0.01

    In the Linux kernel, the following vulnerability has been resolved: igc: avoid returning frame twice in XDP_REDIRECT When a frame can not be transmitted in XDP_REDIRECT (e.g. due to a full queue), it is necessary to free it by calling xdp_return_frame_rx_napi. However, this…

  • CVE-2023-4344CriAug 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Broadcom RAID Controller web interface is vulnerable to insufficient randomness due to improper use of ssl.rnd to setup CIM connection

  • CVE-2023-4342CriAug 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP strict-transport-security policy

  • CVE-2023-4341CriAug 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Broadcom RAID Controller is vulnerable to Privilege escalation to root due to creation of insecure folders by Web GUI

  • CVE-2023-4340CriAug 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Broadcom RAID Controller is vulnerable to Privilege escalation by taking advantage of the Session prints in the log file

  • CVE-2023-4338CriAug 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not provide X-Content-Type-Options Headers

  • CVE-2023-4337CriAug 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Broadcom RAID Controller web interface is vulnerable to improper session handling of managed servers on Gateway installation

  • CVE-2023-4336CriAug 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safeguard cookies with Secure attribute

  • CVE-2023-4329CriAug 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Broadcom RAID Controller web interface is vulnerable due to insecure default of HTTP configuration that does not safeguard SESSIONID cookie with SameSite attribute

  • CVE-2023-4325CriAug 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Broadcom RAID Controller web interface is vulnerable due to usage of Libcurl with LSA has known vulnerabilities

  • CVE-2023-4324CriAug 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Broadcom RAID Controller web interface is vulnerable due to insecure defaults of lacking HTTP Content-Security-Policy headers

  • CVE-2023-4323CriAug 15, 2023
    risk 0.64cvss 9.8epss 0.01

    Broadcom RAID Controller web interface is vulnerable to improper session management of active sessions on Gateway setup

  • CVE-2022-30601CriAug 18, 2022
    risk 0.64cvss 9.8epss 0.01

    Insufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may allow an unauthenticated user to potentially enable information disclosure and escalation of privilege via network access.

  • CVE-2022-25899CriAug 18, 2022
    risk 0.64cvss 9.8epss 0.01

    Authentication bypass for the Open AMT Cloud Toolkit software maintained by Intel(R) before versions 2.0.2 and 2.2.2 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

  • CVE-2022-22730CriAug 18, 2022
    risk 0.64cvss 9.8epss 0.01

    Improper authentication in the Intel(R) Edge Insights for Industrial software before version 2.6.1 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

  • CVE-2022-32292CriAug 3, 2022
    risk 0.64cvss 9.8epss 0.03

    In ConnMan through 1.41, remote attackers able to send HTTP requests to the gweb component are able to exploit a heap-based buffer overflow in received_data to execute code.

  • CVE-2021-33833CriJun 9, 2021
    risk 0.64cvss 9.8epss 0.03

    ConnMan (aka Connection Manager) 1.30 through 1.39 has a stack-based buffer overflow in uncompress in dnsproxy.c via NAME, RDATA, or RDLENGTH (for A or AAAA).

  • CVE-2020-12338CriNov 13, 2020
    risk 0.64cvss 9.8epss 0.02

    Insufficient control flow management in the Open WebRTC Toolkit before version 4.3.1 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

  • CVE-2020-12315CriNov 12, 2020
    risk 0.64cvss 9.8epss 0.02

    Path traversal in the Intel(R) EMA before version 1.3.3 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

  • CVE-2020-8752CriNov 12, 2020
    risk 0.64cvss 9.8epss 0.02

    Out-of-bounds write in IPv6 subsystem for Intel(R) AMT, Intel(R) ISM versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 14.0.45 may allow an unauthenticated user to potentially enable escalation of privileges via network access.

  • CVE-2020-11486CriOct 29, 2020
    risk 0.64cvss 9.8epss 0.03

    NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30, contain a vulnerability in the AMI BMC firmware in which software allows an attacker to upload or transfer files that can be automatically processed within the product's environment, which may lead to…

  • CVE-2020-11483CriOct 29, 2020
    risk 0.64cvss 9.8epss 0.01

    NVIDIA DGX servers, all DGX-1 with BMC firmware versions prior to 3.38.30 and all DGX-2 with BMC firmware versions prior to 1.06.06, contains a vulnerability in the AMI BMC firmware in which the firmware includes hard-coded credentials, which may lead to elevation of privileges…

  • CVE-2020-8758CriSep 10, 2020
    risk 0.64cvss 9.8epss 0.02

    Improper buffer restrictions in network subsystem in provisioned Intel(R) AMT and Intel(R) ISM versions before 11.8.79, 11.12.79, 11.22.79, 12.0.68 and 14.0.39 may allow an unauthenticated user to potentially enable escalation of privilege via network access. On un-provisioned…

  • CVE-2020-0595CriJun 15, 2020
    risk 0.64cvss 9.8epss 0.03

    Use after free in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

  • CVE-2020-0594CriJun 15, 2020
    risk 0.64cvss 9.8epss 0.04

    Out-of-bounds read in IPv6 subsystem in Intel(R) AMT and Intel(R) ISM versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

  • CVE-2019-11131CriDec 18, 2019
    risk 0.64cvss 9.8epss 0.02

    Logic issue in subsystem in Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

  • CVE-2019-11107CriDec 18, 2019
    risk 0.64cvss 9.8epss 0.02

    Insufficient input validation in the subsystem for Intel(R) AMT before version 12.0.45 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

  • CVE-2019-11171CriNov 14, 2019
    risk 0.64cvss 9.8epss 0.02

    Heap corruption in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable information disclosure, escalation of privilege and/or denial of service via network access.

  • CVE-2019-11119CriJun 13, 2019
    risk 0.64cvss 9.8epss 0.02

    Insufficient session validation in the service API for Intel(R) RWC3 version 4.186 and before may allow an unauthenticated user to potentially enable escalation of privilege via network access.

  • CVE-2019-0172CriMay 17, 2019
    risk 0.64cvss 9.8epss 0.02

    A logic issue in Intel Unite(R) Client for Android prior to version 4.0 may allow a remote attacker to potentially enable escalation of privilege via network access.

  • CVE-2019-0153CriMay 17, 2019
    risk 0.64cvss 9.8epss 0.02

    Buffer overflow in subsystem in Intel(R) CSME 12.0.0 through 12.0.34 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

  • CVE-2019-0101CriFeb 18, 2019
    risk 0.64cvss 9.8epss 0.02

    Authentication bypass in the Intel Unite(R) solution versions 3.2 through 3.3 may allow an unauthenticated user to potentially enable escalation of privilege to the Intel Unite(R) Solution administrative portal via network access.

  • CVE-2018-12171CriSep 12, 2018
    risk 0.64cvss 9.8epss 0.02

    Privilege escalation in Intel Baseboard Management Controller (BMC) firmware before version 1.43.91f76955 may allow an unprivileged user to potentially execute arbitrary code or perform denial of service over the network.

  • CVE-2018-3641CriApr 3, 2018
    risk 0.64cvss 9.8epss 0.01

    Escalation of privilege in all versions of the Intel Remote Keyboard allows a network attacker to inject keystrokes as a local user.

  • CVE-2017-5719CriNov 21, 2017
    risk 0.64cvss 9.8epss 0.02

    A vulnerability in the Intel Deep Learning Training Tool Beta 1 allows a network attacker to remotely execute code as a local user.

  • CVE-2017-12865CriAug 29, 2017
    risk 0.64cvss 9.8epss 0.06

    Stack-based buffer overflow in "dnsproxy.c" in connman 1.34 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted response query string passed to the "name" variable.

  • CVE-2018-3679CriSep 12, 2018
    risk 0.62cvss 9.6epss 0.01

    Escalation of privilege in Reference UI in Intel Data Center Manager SDK 5.0 and before may allow an unauthorized remote unauthenticated user to potentially execute code via administrator privileges.

  • CVE-2026-20794CriMay 12, 2026
    risk 0.60cvss epss 0.00

    Buffer overflow for the Intel(R) Data Center Graphics Driver for VMware ESXi software before version 2.0.2 within Ring 1: Device Drivers may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable local…

  • CVE-2022-23097CriJan 28, 2022
    risk 0.59cvss 9.1epss 0.02

    An issue was discovered in the DNS proxy in Connman through 1.40. forward_dns_reply mishandles a strnlen call, leading to an out-of-bounds read.

  • CVE-2022-23096CriJan 28, 2022
    risk 0.59cvss 9.1epss 0.03

    An issue was discovered in the DNS proxy in Connman through 1.40. The TCP server reply implementation lacks a check for the presence of sufficient Header Data, leading to an out-of-bounds read.

  • CVE-2020-8747CriNov 12, 2020
    risk 0.59cvss 9.1epss 0.02

    Out-of-bounds read in subsystem for Intel(R) AMT versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70 and 14.0.45 may allow an unauthenticated user to potentially enable information disclosure and/or denial of service via network access.

  • CVE-2019-11168CriNov 14, 2019
    risk 0.59cvss 9.1epss 0.01

    Insufficient session validation in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable information disclosure and/or denial of service via network access.

Page 1 of 48