← Back

Dell

dell

1,518 CVEs • 3,654 products

Products (3,654)

Click to collapse
Toggle

CVEs (1,518)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dell
346Alienware M15 R6 Firmware
Alienware M15 R7 FirmwareAlienware M16 R1 Firmware+343 more
Dec 19, 2024
Aug 28, 2024
N/A· v4
7.3 HIGH· v3
N/A· v2
Dell Dock Firmware and Dell Client Platform contain an Improper Link Resolution vulnerability during installation resulting in arbitrary folder deletion, which could lead to Privilege Escalation or Denial of Service.
1Dell
1Power Manager
Nov 26, 2024
Aug 22, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Dell Power Manager (DPM), versions 3.15.0 and prior, contains an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code exe...Show more
Dell Power Manager (DPM), versions 3.15.0 and prior, contains an Incorrect Privilege Assignment vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution and Elevation of privileges.Show less
1Dell
1Repository Manager
Aug 23, 2024
Aug 21, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Dell Repository Manager version 3.4.2 and earlier, contain a Local Privilege Escalation Vulnerability in Installation module. A local low privileged attacker may potentially exploit this vulnerability leading to the exec...Show more
Dell Repository Manager version 3.4.2 and earlier, contain a Local Privilege Escalation Vulnerability in Installation module. A local low privileged attacker may potentially exploit this vulnerability leading to the execution of arbitrary executable on the operating system with high privileges using the existing vulnerability in operating system. Exploitation may lead to unavailability of the service.Show less
1Dell
1Supportassist For Home Pcs
Nov 25, 2024
Aug 21, 2024
N/A· v4
7.3 HIGH· v3
N/A· v2
Dell SupportAssist for Home PCs Installer exe version 4.0.3 contains a privilege escalation vulnerability in the installer. A local low-privileged authenticated attacker could potentially exploit this vulnerability, lead...Show more
Dell SupportAssist for Home PCs Installer exe version 4.0.3 contains a privilege escalation vulnerability in the installer. A local low-privileged authenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary executables on the operating system with elevated privileges.Show less
1Dell
20Dnr 202l Firmware
Dnr 322l FirmwareDnr 326 Firmware+17 more
Aug 20, 2024
Aug 19, 2024
5.3 MEDIUM· v4
9.8 CRITICAL· v3
6.5 MEDIUM· v2
A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-...Show more
A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20240814 and classified as critical. Affected by this issue is the function cgi_audio_search/cgi_create_playlist/cgi_get_album_all_tracks/cgi_get_alltracks_editlist/cgi_get_artist_all_album/cgi_get_genre_all_tracks/cgi_get_tracks_list/cgi_set_airplay_content/cgi_write_playlist of the file /cgi-bin/myMusic.cgi. The manipulation leads to command injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: This vulnerability only affects products that are no longer supported by the maintainer. NOTE: Vendor was contacted early and confirmed that the product is end-of-life. It should be retired and replaced.Show less
1Dell
41Embedded Box Pc 5000 Firmware
Latitude 12 Rugged Extreme 7214 FirmwareLatitude 13 3380 Firmware+38 more
Sep 18, 2024
Aug 14, 2024
N/A· v4
6.7 MEDIUM· v3
N/A· v2
Dell BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
1Dell
3Alienware Update
Command UpdateUpdate
Aug 19, 2024
Aug 6, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Dell Command | Update, Dell Update, and Alienware Update UWP, versions prior to 5.4, contain an Exposed Dangerous Method or Function vulnerability. An unauthenticated attacker with remote access could potentially exploit...Show more
Dell Command | Update, Dell Update, and Alienware Update UWP, versions prior to 5.4, contain an Exposed Dangerous Method or Function vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to denial of service.Show less
1Dell
1Cloudlink
Sep 5, 2024
Aug 2, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
CloudLink, versions 7.1.x and 8.x, contain an Improper check or handling of Exceptional Conditions Vulnerability in Cluster Component. A highly privileged malicious user with remote access could potentially exploit this...Show more
CloudLink, versions 7.1.x and 8.x, contain an Improper check or handling of Exceptional Conditions Vulnerability in Cluster Component. A highly privileged malicious user with remote access could potentially exploit this vulnerability, leading to execute unauthorized actions and retrieve sensitive information from the database.Show less
1Dell
1Emc Idrac Service Module
Aug 2, 2024
Aug 1, 2024
N/A· v4
4.4 MEDIUM· v3
N/A· v2
Dell iDRAC Service Module version 5.3.0.0 and prior, contain a Out of bound Write Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service event.
1Dell
1Emc Idrac Service Module
Aug 2, 2024
Aug 1, 2024
N/A· v4
4.4 MEDIUM· v3
N/A· v2
Dell iDRAC Service Module version 5.3.0.0 and prior contains Out of bound write Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service (partial) event.
1Dell
1Emc Idrac Service Module
Aug 2, 2024
Aug 1, 2024
N/A· v4
4.4 MEDIUM· v3
N/A· v2
Dell iDRAC Service Module version 5.3.0.0 and prior, contain a Out of bound Read Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service event.
1Dell
1Insightiq
Aug 23, 2024
Aug 1, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Dell InsightIQ, Verion 5.0.0, contains a use of a broken or risky cryptographic algorithm vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability, leading to information disclosure.
1Dell
1Emc Idrac Service Module
Aug 2, 2024
Aug 1, 2024
N/A· v4
4.4 MEDIUM· v3
N/A· v2
Dell iDRAC Service Module version 5.3.0.0 and prior, contain a Out of bound Write Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service event.
1Dell
1Emc Idrac Service Module
Aug 2, 2024
Aug 1, 2024
N/A· v4
4.4 MEDIUM· v3
N/A· v2
Dell iDRAC Service Module version 5.3.0.0 and prior, contain an Out of bound Read Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service event.
1Dell
1Dm5500 Firmware
Nov 22, 2024
Jul 31, 2024
N/A· v4
4.4 MEDIUM· v3
N/A· v2
DM5500 5.16.0.0, contains an information disclosure vulnerability. A local attacker with high privileges could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker m...Show more
DM5500 5.16.0.0, contains an information disclosure vulnerability. A local attacker with high privileges could potentially exploit this vulnerability, leading to the disclosure of certain user credentials. The attacker may be able to use the exposed credentials to access the vulnerable application with privileges of the compromised account.Show less
1Dell
1Peripheral Manager
Aug 8, 2024
Jul 31, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Dell Peripheral Manager, versions prior to 1.7.6, contain an uncontrolled search path element vulnerability. An attacker could potentially exploit this vulnerability through preloading malicious DLL or symbolic link expl...Show more
Dell Peripheral Manager, versions prior to 1.7.6, contain an uncontrolled search path element vulnerability. An attacker could potentially exploit this vulnerability through preloading malicious DLL or symbolic link exploitation, leading to arbitrary code execution and escalation of privilegeShow less
1Dell
1Inventory Collector
Aug 13, 2024
Jul 31, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Dell Inventory Collector, versions prior to 12.3.0.6 contains a Path Traversal vulnerability. A local authenticated malicious user could potentially exploit this vulnerability, leading to arbitrary code execution on the...Show more
Dell Inventory Collector, versions prior to 12.3.0.6 contains a Path Traversal vulnerability. A local authenticated malicious user could potentially exploit this vulnerability, leading to arbitrary code execution on the system.Show less
1Dell
1Peripheral Manager
Aug 27, 2024
Jul 31, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Dell Peripheral Manager, versions prior to 1.7.6, contain an uncontrolled search path element vulnerability. An attacker could potentially exploit this vulnerability through preloading malicious DLL or symbolic link expl...Show more
Dell Peripheral Manager, versions prior to 1.7.6, contain an uncontrolled search path element vulnerability. An attacker could potentially exploit this vulnerability through preloading malicious DLL or symbolic link exploitation, leading to arbitrary code execution and escalation of privilegeShow less
1Dell
1Peripheral Manager
Aug 8, 2024
Jul 31, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Dell Peripheral Manager, versions prior to 1.7.6, contain an uncontrolled search path element vulnerability. An attacker could potentially exploit this vulnerability through preloading malicious DLL or symbolic link exp...Show more
Dell Peripheral Manager, versions prior to 1.7.6, contain an uncontrolled search path element vulnerability. An attacker could potentially exploit this vulnerability through preloading malicious DLL or symbolic link exploitation, leading to arbitrary code execution and escalation of privilegeShow less
1Dell
2Bsafe Crypto C Micro Edition
Bsafe Micro Edition Suite
Aug 20, 2024
Jul 31, 2024
N/A· v4
7.1 HIGH· v3
N/A· v2
Dell BSAFE Crypto-C Micro Edition, version 4.1.5, and Dell BSAFE Micro Edition Suite, versions 4.0 through 4.6.1 and version 5.0, contains an Out-of-bounds Read vulnerability. An unauthenticated attacker with local acces...Show more
Dell BSAFE Crypto-C Micro Edition, version 4.1.5, and Dell BSAFE Micro Edition Suite, versions 4.0 through 4.6.1 and version 5.0, contains an Out-of-bounds Read vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Information exposure.Show less