1281
|
- |
|
-
|
-
|
BigFix Patch Download Plug-ins are affected by an insecure package which is susceptible to XML injection attacks. This allows an attacker to exploit this vulnerability by injecting malicious XML con…
|
-
|
CVE-2024-42185
|
2025-01-23 12:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1282
|
- |
|
-
|
-
|
BigFix Patch Download Plug-ins are affected by insecure support for file URI scheme. It could allow a malicious operator to attempt to download files using the file:// URI scheme.
|
-
|
CVE-2024-42184
|
2025-01-23 12:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1283
|
6.4 |
MEDIUM
Network
|
-
|
-
|
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alt…
|
CWE-79
Cross-site Scripting
|
CVE-2023-50309
|
2025-01-23 12:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1284
|
4.6 |
MEDIUM
Network
|
-
|
-
|
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering t…
|
CWE-79
Cross-site Scripting
|
CVE-2023-32340
|
2025-01-23 12:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1285
|
- |
|
-
|
-
|
BigFix Patch Download Plug-ins are affected by an arbitrary file download vulnerability. It could allow a malicious operator to download files from arbitrary URLs without any proper validation or al…
|
-
|
CVE-2024-42183
|
2025-01-23 11:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1286
|
- |
|
-
|
-
|
BigFix Patch Download Plug-ins are affected by Server-Side Request Forgery (SSRF) vulnerability. It may allow the application to download files from an internally hosted server on localhost.
|
-
|
CVE-2024-42182
|
2025-01-23 10:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1287
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
btrfs: avoid NULL pointer dereference if no valid extent tree
[BUG]
Syzbot reported a crash with the following call trace:
BTR…
|
CWE-476
NULL Pointer Dereference
|
CVE-2025-21658
|
2025-01-23 08:02 |
2025-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1288
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
iio: adc: ti-ads1298: Add NULL check in ads1298_init
devm_kasprintf() can return a NULL pointer on failure. A check on the
return…
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-57944
|
2025-01-23 08:02 |
2025-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1289
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
net/sctp: Prevent autoclose integer overflow in sctp_association_init()
While by default max_autoclose equals to INT_MAX / HZ, on…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2024-57938
|
2025-01-23 08:01 |
2025-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1290
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Avada Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 3.11.11 due to insufficient input sanitization an…
|
CWE-79
Cross-site Scripting
|
CVE-2024-12477
|
2025-01-23 07:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|