1941
|
5.9 |
MEDIUM
Network
|
apple
|
macos visionos iphone_os ipados
|
This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2, iPadOS 17.7.3, visionOS 2.2. An attacker in a p…
|
NVD-CWE-noinfo
|
CVE-2024-54492
|
2024-12-20 00:36 |
2024-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1942
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
This issue was addressed by enabling hardened runtime. This issue is fixed in macOS Sequoia 15.2. A local attacker may gain access to user's Keychain items.
|
NVD-CWE-noinfo
|
CVE-2024-54490
|
2024-12-20 00:27 |
2024-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1943
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. An app may be able to access user-sensitive data.
|
NVD-CWE-noinfo
|
CVE-2024-54476
|
2024-12-20 00:26 |
2024-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1944
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
This issue was addressed with additional entitlement checks. This issue is fixed in macOS Sonoma 14.7.1, macOS Ventura 13.7.1. A malicious application may be able to leak a user's credentials.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2024-54471
|
2024-12-20 00:25 |
2024-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1945
|
9.8 |
CRITICAL
Network
gstreamer_project
|
gstreamer
|
GStreamer is a library for constructing graphs of media-handling components. The program attempts to reallocate the memory pointed to by stream->samples to accommodate stream->n_samples + samples_cou…
|
CWE-787 CWE-190
Out-of-bounds Write Integer Overflow or Wraparound
|
CVE-2024-47537
|
2024-12-20 00:20 |
2024-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1946
|
- |
|
-
|
-
|
Improper neutralization of input in Nagvis before version 1.9.42 which can lead to XSS
|
-
|
CVE-2024-47093
|
2024-12-20 00:15 |
2024-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1947
|
8.8 |
HIGH
Network
|
-
|
-
|
A flaw was found in the MustGather.managed.openshift.io Custom Defined Resource (CRD) of OpenShift Dedicated. A non-privileged user on the cluster can create a MustGather object with a specially craf…
|
CWE-20
Improper Input Validation
|
CVE-2024-25131
|
2024-12-20 00:15 |
2024-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1948
|
- |
|
-
|
-
|
A vulnerability, which was classified as critical, was found in X1a0He Adobe Downloader up to 1.3.1 on macOS. Affected is the function shouldAcceptNewConnection of the file com.x1a0he.macOS.Adobe-Dow…
|
CWE-266 CWE-269
Incorrect Privilege Assignment Improper Privilege Management
|
CVE-2024-12786
|
2024-12-20 00:15 |
2024-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1949
|
- |
|
-
|
-
|
A vulnerability was found in itsourcecode Vehicle Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file sendmail.php. The man…
|
CWE-89 CWE-74
SQL Injection Injection
|
CVE-2024-12785
|
2024-12-20 00:15 |
2024-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1950
|
5.5 |
MEDIUM
Local
|
fabulatech
|
usb_over_network
|
A vulnerability, which was classified as problematic, was found in FabulaTech USB over Network 6.0.6.1. This affects the function 0x220448 in the library ftusbbus2.sys of the component IOCT Handler. …
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-12656
|
2024-12-20 00:11 |
2024-12-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|