2281
|
- |
|
-
|
-
|
A timing-based side-channel flaw was found in libgcrypt's RSA implementation. This issue may allow a remote attacker to initiate a Bleichenbacher-style attack, which can lead to the decryption of RSA…
|
CWE-208
Information Exposure Through Timing Discrepancy
|
CVE-2024-2236
|
2024-11-13 03:15 |
2024-03-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2282
|
5.3 |
MEDIUM
Network
latchset redhat fedoraproject
|
jwcrypto enterprise_linux enterprise_linux_for_power_little_endian enterprise_linux_for_ibm_z_systems fedora enterprise_linux_for_arm_64
|
A vulnerability was found in JWCrypto. This flaw allows an attacker to cause a denial of service (DoS) attack and possible password brute-force and dictionary attacks to be more resource-intensive. T…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2023-6681
|
2024-11-13 03:15 |
2024-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
2283
|
- |
|
-
|
-
|
UsersController.php in Run.codes 1.5.2 and older has a reset password race condition vulnerability.
|
-
|
CVE-2024-48322
|
2024-11-13 02:35 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2284
|
- |
|
-
|
-
|
The DS allvideo.downloader.browser (aka Fast Video Downloader: Browser) application through 1.6-RC1 for Android allows an attacker to execute arbitrary JavaScript code via the allvideo.downloader.bro…
|
-
|
CVE-2024-46965
|
2024-11-13 02:35 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2285
|
- |
|
-
|
-
|
EnGenius EWS356-FIT devices through 1.1.30 allow blind OS command injection. This allows an attacker to execute arbitrary OS commands via shell metacharacters to the Ping and Speed Test utilities.
|
-
|
CVE-2024-36061
|
2024-11-13 02:35 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2286
|
- |
|
-
|
-
|
An XML External Entity (XXE) vulnerability in the component DocumentBuilderFactory of powertac-server v1.9.0 allows attackers to access sensitive information or execute arbitrary code via supplying a…
|
-
|
CVE-2024-51135
|
2024-11-13 02:35 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2287
|
- |
|
-
|
-
|
The boa httpd of Trendnet TEW-820AP 1.01.B01 has a stack overflow vulnerability in /boafrm/formIPv6Addr, /boafrm/formIpv6Setup, /boafrm/formDnsv6. The reason is that the check of ipv6 address is not …
|
-
|
CVE-2024-50667
|
2024-11-13 02:35 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2288
|
9.8 |
CRITICAL
Network
gl-inet
|
mt6000_firmware a1300_firmware x300b_firmware ax1800_firmware axt1800_firmware mt2500_firmware mt3000_firmware x3000_firmware xe3000_firmware xe300_firmware e750_firmwar…
|
GL-iNet products AR750/AR750S/AR300M/AR300M16/MT300N-V2/B1300/MT1300/SFT1200/X750 v4.3.11, MT3000/MT2500/AXT1800/AX1800/A1300/X300B v4.5.16, XE300 v4.3.16, E750 v4.3.12, AP1300/S1300 v4.3.13, and XE3…
|
CWE-22
Path Traversal
|
CVE-2024-39226
|
2024-11-13 02:35 |
2024-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
2289
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
of: module: prevent NULL pointer dereference in vsnprintf()
In of_modalias(), we can get passed the str and len parameters which …
|
-
|
CVE-2024-35878
|
2024-11-13 02:35 |
2024-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2290
|
- |
|
-
|
-
|
The O-RAN E2T I-Release buildPrometheusList function can have a NULL pointer dereference because peerInfo can be NULL.
|
-
|
CVE-2024-34044
|
2024-11-13 02:35 |
2024-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|