CVE-2023-41474
- EPSS 73.34%
- Published 25.01.2024 20:15:36
- Last modified 12.06.2025 15:15:32
Directory Traversal vulnerability in Ivanti Avalanche 6.3.4.153 allows a remote authenticated attacker to obtain sensitive information via the javax.faces.resource component.
CVE-2023-46804
- EPSS 0.63%
- Published 19.12.2023 16:15:12
- Last modified 21.11.2024 08:29:20
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS).
CVE-2023-46261
- EPSS 1.89%
- Published 19.12.2023 16:15:11
- Last modified 21.11.2024 08:28:11
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
CVE-2023-46262
- EPSS 50.23%
- Published 19.12.2023 16:15:11
- Last modified 21.11.2024 08:28:11
An unauthenticated attacked could send a specifically crafted web request causing a Server-Side Request Forgery (SSRF) in Ivanti Avalanche Remote Control server.
CVE-2023-46263
- EPSS 78.85%
- Published 19.12.2023 16:15:11
- Last modified 21.11.2024 08:28:11
An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remote code execution.
CVE-2023-46264
- EPSS 65.08%
- Published 19.12.2023 16:15:11
- Last modified 21.11.2024 08:28:12
An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remove code execution.
CVE-2023-46265
- EPSS 1.7%
- Published 19.12.2023 16:15:11
- Last modified 21.11.2024 08:28:12
An unauthenticated could abuse a XXE vulnerability in the Smart Device Server to leak data or perform a Server-Side Request Forgery (SSRF).
CVE-2023-46266
- EPSS 0.93%
- Published 19.12.2023 16:15:11
- Last modified 21.11.2024 08:28:12
An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack.
CVE-2023-46803
- EPSS 0.63%
- Published 19.12.2023 16:15:11
- Last modified 21.11.2024 08:29:20
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS).
CVE-2023-46224
- EPSS 3.25%
- Published 19.12.2023 16:15:10
- Last modified 21.11.2024 08:28:06
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.