1531
|
4.7 |
MEDIUM
Local
|
-
|
-
|
A vulnerability exists in the bind-propagation option of the Dockerfile RUN --mount instruction. The system does not properly validate the input passed to this option, allowing users to pass arbitrar…
|
CWE-20
Improper Input Validation
|
CVE-2024-9407
|
2024-11-13 03:15 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1532
|
5.4 |
MEDIUM
Network
|
-
|
-
|
A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file paths due to improper validation in the containers/common Go library. This flaw a…
|
CWE-59
Link Following
|
CVE-2024-9341
|
2024-11-13 03:15 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1533
|
4.4 |
MEDIUM
Local
|
-
|
-
|
A vulnerability was found in Performance Co-Pilot (PCP). This flaw can only be exploited if an attacker has access to a compromised PCP system account. The issue is related to the pmpost tool, which …
|
CWE-59
Link Following
|
CVE-2024-45770
|
2024-11-13 03:15 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1534
|
5.5 |
MEDIUM
Local
|
-
|
-
|
A vulnerability was found in Performance Co-Pilot (PCP). This flaw allows an attacker to send specially crafted data to the system, which could cause the program to misbehave or crash.
|
-
|
CVE-2024-45769
|
2024-11-13 03:15 |
2024-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1535
|
6.7 |
MEDIUM
Local
|
gnu redhat
|
nano enterprise_linux
|
A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing, a file it saves to an emergency file with the pe…
|
CWE-59
Link Following
|
CVE-2024-5742
|
2024-11-13 03:15 |
2024-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1536
|
- |
|
-
|
-
|
A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA…
|
CWE-208
Information Exposure Through Timing Discrepancy
|
CVE-2024-2236
|
2024-11-13 03:15 |
2024-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1537
|
5.3 |
MEDIUM
Network
latchset redhat fedoraproject
|
jwcrypto enterprise_linux enterprise_linux_for_power_little_endian enterprise_linux_for_ibm_z_systems fedora enterprise_linux_for_arm_64
|
A vulnerability was found in JWCrypto. This flaw allows an attacker to cause a denial of service (DoS) attack and possible password brute-force and dictionary attacks to be more resource-intensive. T…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2023-6681
|
2024-11-13 03:15 |
2024-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1538
|
- |
|
-
|
-
|
UsersController.php in Run.codes 1.5.2 and older has a reset password race condition vulnerability.
|
-
|
CVE-2024-48322
|
2024-11-13 02:35 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1539
|
- |
|
-
|
-
|
The DS allvideo.downloader.browser (aka Fast Video Downloader: Browser) application through 1.6-RC1 for Android allows an attacker to execute arbitrary JavaScript code via the allvideo.downloader.bro…
|
-
|
CVE-2024-46965
|
2024-11-13 02:35 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1540
|
- |
|
-
|
-
|
EnGenius EWS356-FIT devices through 1.1.30 allow blind OS command injection. This allows an attacker to execute arbitrary OS commands via shell metacharacters to the Ping and Speed Test utilities.
|
-
|
CVE-2024-36061
|
2024-11-13 02:35 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|