1481
|
- |
|
-
|
-
|
A Server-Side Request Forgery (SSRF) vulnerability in the /Cover/Show route (showAction in CoverController.php) in Open Library Foundation VuFind 2.4 through 9.1 before 9.1.1 allows remote attackers …
|
-
|
CVE-2024-25737
|
2024-11-13 04:35 |
2024-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1482
|
- |
|
-
|
-
|
In certain cases the JIT incorrectly optimized MSubstr operations, which led to out-of-bounds reads. This vulnerability affects Firefox < 125.
|
-
|
CVE-2024-3855
|
2024-11-13 04:35 |
2024-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1483
|
- |
|
-
|
-
|
HTTP/2 CONTINUATION DoS attack can cause Apache Traffic Server to consume more resources on the server. Version from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.3 are affected.
Users can set a new …
|
CWE-20
Improper Input Validation
|
CVE-2024-31309
|
2024-11-13 04:35 |
2024-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1484
|
- |
|
-
|
-
|
In GNU tar before 1.35, mishandled extension attributes in a PAX archive can lead to an application crash in xheader.c.
|
-
|
CVE-2023-39804
|
2024-11-13 04:35 |
2024-03-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1485
|
- |
|
-
|
-
|
There is a PHP file inclusion vulnerability in the template configuration of eyoucms v1.6.4, allowing attackers to execute code or system commands through a carefully crafted malicious payload.
|
-
|
CVE-2023-42286
|
2024-11-13 04:35 |
2024-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1486
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
jfs: fix array-index-out-of-bounds in dbAdjTree
Currently there is a bound check missing in the dbAdjTree while
accessing the dmt…
|
-
|
CVE-2023-52601
|
2024-11-13 04:35 |
2024-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1487
|
4.7 |
MEDIUM
Local
|
-
|
-
|
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Security). Supported versions that are affected are Oracle Java S…
|
-
|
CVE-2024-20945
|
2024-11-13 04:35 |
2024-02-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1488
|
7.8 |
HIGH
Local
|
workbooth_project
|
workbooth
|
Vulnerability in Distro Linux Workbooth v2.5 that allows to escalate privileges to the root user by manipulating the network configuration script.
|
NVD-CWE-noinfo
|
CVE-2024-9576
|
2024-11-13 04:34 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1489
|
7.5 |
HIGH
Network
finrota
|
finrota
|
Cleartext Storage of Sensitive Information vulnerability in Finrota Netahsilat allows Retrieve Embedded Sensitive Data.This issue solved in versions 1.21.10, 1.23.01, 1.23.08, 1.23.11 and 1.24.03.
|
CWE-202 CWE-311 CWE-312
Exposure of Sensitive Information Through Data Queries Missing Encryption of Sensitive Data Cleartext Storage of Sensitive Information
|
CVE-2024-6400
|
2024-11-13 04:32 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1490
|
6.5 |
MEDIUM
Adjacent
|
zephyrproject
|
zephyr
|
In utf8_trunc in zephyr/lib/utils/utf8.c, last_byte_p can point to one byte before the string pointer if the string is empty.
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2024-6443
|
2024-11-13 04:29 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|