851
|
7.8 |
HIGH
Local
|
artifex debian suse
|
ghostscript debian_linux linux_enterprise_high_performance_computing linux_enterprise_server linux_enterprise_server_for_sap
|
An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code execution.
|
CWE-125
Out-of-bounds Read
|
CVE-2024-46956
|
2024-11-15 05:39 |
2024-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
852
|
6.7 |
MEDIUM
Local
|
fortinet
|
forticlient
|
An improper verification of cryptographic signature vulnerability [CWE-347] in FortiClient MacOS version 7.4.0, version 7.2.4 and below, version 7.0.10 and below, version 6.4.10 and below may allow a…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2024-40592
|
2024-11-15 05:37 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
853
|
8.8 |
HIGH
Local
|
fortinet
|
forticlient
|
A privilege context switching error vulnerability [CWE-270] in FortiClient Windows version 7.2.4 and below, version 7.0.12 and below, 6.4 all versions may allow an authenticated user to escalate thei…
|
CWE-270
Privilege Context Switching Error
|
CVE-2024-36513
|
2024-11-15 05:35 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
854
|
6.1 |
MEDIUM
Network
|
ibm
|
cics_tx
|
IBM CICS TX Standard is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functiona…
|
CWE-79
Cross-site Scripting
|
CVE-2024-41745
|
2024-11-15 05:35 |
2024-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
855
|
- |
|
-
|
-
|
An issue in the API endpoint /AccountMaster/GetCurrentUserInfo of INROAD before v202402060 allows attackers to access sensitive information via a crafted payload to the UserNameOrPhoneNumber paramete…
|
-
|
CVE-2024-46635
|
2024-11-15 05:35 |
2024-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
856
|
- |
|
-
|
-
|
An issue in Fireboltt Dream Wristphone BSW202_FB_AAC_v2.0_20240110-20240110-1956 allows attackers to cause a Denial of Service (DoS) via a crafted deauth frame.
|
-
|
CVE-2024-30656
|
2024-11-15 05:35 |
2024-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
857
|
- |
|
-
|
-
|
Open Redirect vulnerability in Corezoid Process Engine v6.5.0 allows attackers to redirect to arbitrary websites via appending a crafted link to /login/ in the login page URL.
|
-
|
CVE-2024-27592
|
2024-11-15 05:35 |
2024-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
858
|
- |
|
-
|
-
|
Out-of-bounds write vulnerability in the RSMC module.
Impact: Successful exploitation of this vulnerability will affect availability.
|
-
|
CVE-2023-52385
|
2024-11-15 05:35 |
2024-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
859
|
- |
|
-
|
-
|
Vulnerability of improper permission control in the window management module.
Impact: Successful exploitation of this vulnerability will affect availability and confidentiality.
|
-
|
CVE-2023-52713
|
2024-11-15 05:35 |
2024-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
860
|
- |
|
-
|
-
|
Chilkat before v9.5.0.98, allows attackers to obtain sensitive information via predictable PRNG in ChilkatRand::randomBytes function.
|
-
|
CVE-2024-26329
|
2024-11-15 05:35 |
2024-04-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|