111
|
7.5 |
HIGH
Network
toshibatec sharp
|
e-studio1058_firmware e-studio1208_firmware e-studio908_firmware bp-90c70_firmware bp-90c80_firmware bp-70c65_firmware bp-70c55_firmware bp-70c45_firmware bp-70c36_firmware
|
Sharp and Toshiba Tec MFPs provide the web page to download data, where query parameters in HTTP requests are improperly processed and resulting in an Out-of-bounds Read vulnerability.
Crafted HTTP …
Update
|
CWE-125
Out-of-bounds Read
|
CVE-2024-45829
|
2024-11-6 04:38 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
112
|
7.8 |
HIGH
Local
|
polkit_project redhat canonical suse oracle siemens starwindsoftware
|
polkit enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_for_scientific_computing enterprise_linux_server enterprise_linux_for_power_little_endian enterprise_li…
|
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as privileged users accor…
Update
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2021-4034
|
2024-11-6 04:38 |
2022-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
113
|
5.3 |
MEDIUM
Network
toshibatec sharp
|
e-studio1058_firmware e-studio1208_firmware e-studio908_firmware bp-90c70_firmware bp-90c80_firmware bp-70c65_firmware bp-70c55_firmware bp-70c45_firmware bp-70c36_firmware
|
Sharp and Toshiba Tec MFPs improperly process URI data in HTTP PUT requests resulting in a path Traversal vulnerability.
Unintended internal files may be retrieved when processing crafted HTTP reque…
Update
|
CWE-22
Path Traversal
|
CVE-2024-45842
|
2024-11-6 04:37 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
114
|
- |
|
-
|
-
|
The Elliptic package 6.5.7 for Node.js, in its for ECDSA implementation, does not correctly verify valid signatures if the hash contains at least four leading 0 bytes and when the order of the ellipt…
Update
|
-
|
CVE-2024-48948
|
2024-11-6 04:36 |
2024-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
115
|
- |
|
-
|
-
|
The Photo Gallery by 10Web WordPress plugin before 1.8.28 does not properly sanitise and escape some of its Gallery settings, which could allow high privilege users such as admin to perform Stored C…
Update
|
-
|
CVE-2024-5968
|
2024-11-6 04:36 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
116
|
- |
|
-
|
-
|
Cross Site Scripting vulnerability in D-Link DAP products DAP-2230, DAP-2310, DAP-2330, DAP-2360, DAP-2553, DAP-2590, DAP-2690, DAP-2695, DAP-3520, DAP-3662 allows a remote attacker to execute arbitr…
Update
|
-
|
CVE-2024-28436
|
2024-11-6 04:36 |
2024-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
117
|
- |
|
-
|
-
|
Tenda FH1203 v2.0.1.6 firmware has a stack overflow vulnerability via the PPW parameter in the fromWizardHandle function.
Update
|
-
|
CVE-2024-32299
|
2024-11-6 04:36 |
2024-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
118
|
- |
|
-
|
-
|
The Kerlink firewall in ChirpStack chirpstack-mqtt-forwarder before 4.2.1 and chirpstack-gateway-bridge before 4.0.11 wrongly accepts certain TCP packets when a connection is not in the ESTABLISHED s…
Update
|
-
|
CVE-2024-29862
|
2024-11-6 04:36 |
2024-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
119
|
9.8 |
CRITICAL
Network
toshibatec sharp
|
e-studio1058_firmware e-studio1208_firmware e-studio908_firmware bp-90c70_firmware bp-90c80_firmware bp-70c65_firmware bp-70c55_firmware bp-70c45_firmware bp-70c36_firmware
|
Sharp and Toshiba Tec MFPs improperly process HTTP authentication requests, resulting in an authentication bypass vulnerability.
Update
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2024-47406
|
2024-11-6 04:36 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
120
|
8.1 |
HIGH
Network
|
toshibatec sharp
|
e-studio1058_firmware e-studio1208_firmware e-studio908_firmware bp-90c70_firmware bp-90c80_firmware bp-70c65_firmware bp-70c55_firmware bp-70c45_firmware bp-70c36_firmware
|
Sharp and Toshiba Tec MFPs provide configuration related APIs. They are expected to be called by administrative users only, but insufficiently restricted.
A non-administrative user may execute some …
Update
|
NVD-CWE-Other
|
CVE-2024-47005
|
2024-11-6 04:36 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|