2611
|
7.8 |
HIGH
Local
|
apple
|
watchos tvos macos ipados iphone_os
|
A logic issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.3, watchOS 11.2, tvOS 18.2, macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.…
|
NVD-CWE-noinfo
|
CVE-2024-44225
|
2024-12-19 03:33 |
2024-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2612
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
A configuration issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.2. An app may be able to modify protected parts of the file system.
|
NVD-CWE-noinfo
|
CVE-2024-44243
|
2024-12-19 03:32 |
2024-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2613
|
9.8 |
CRITICAL
Network
apple
|
ipados iphone_os
|
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1. An attacker may be able to cause unexpected system termination or arbitrary code execution in DCP…
|
NVD-CWE-noinfo
|
CVE-2024-44242
|
2024-12-19 03:32 |
2024-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
2614
|
7.1 |
HIGH
Local
|
apple
|
visionos macos ipados iphone_os
|
The issue was addressed with improved memory handling. This issue is fixed in iPadOS 17.7.3, visionOS 2.2, macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2, macOS Sonoma 14.7.2. An app may be able to cau…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-44245
|
2024-12-19 03:16 |
2024-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2615
|
5.3 |
MEDIUM
Network
apple
|
safari macos ipados iphone_os
|
The issue was addressed with improved routing of Safari-originated requests. This issue is fixed in macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2, Safari 18.2, iPadOS 17.7.3. On a device with Private …
|
NVD-CWE-noinfo
|
CVE-2024-44246
|
2024-12-19 03:08 |
2024-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
2616
|
5.3 |
MEDIUM
Network
apple
|
macos
|
An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. An encrypted volume may be accessed by a dif…
|
CWE-862
Missing Authorization
|
CVE-2024-54466
|
2024-12-19 02:59 |
2024-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
2617
|
6.8 |
MEDIUM
Adjacent
|
-
|
-
|
IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3
could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a spec…
|
CWE-601
Open Redirect
|
CVE-2024-45082
|
2024-12-19 02:15 |
2024-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2618
|
5.4 |
MEDIUM
Adjacent
|
-
|
-
|
IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the v…
|
CWE-80
Basic XSS
|
CVE-2024-41752
|
2024-12-19 02:15 |
2024-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2619
|
5.4 |
MEDIUM
Network
|
-
|
-
|
IBM Cognos Analytics 11.2.0 through 11.2.4 and 12.0.0 through 12.0.3
is potentially vulnerable to Cross Site Scripting (XSS). A remote attacker could execute malicious commands due to improper va…
|
CWE-79
Cross-site Scripting
|
CVE-2024-25042
|
2024-12-19 02:15 |
2024-12-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2620
|
- |
|
-
|
-
|
Databricks JDBC Driver before 2.6.40 could potentially allow remote code execution (RCE) by triggering a JNDI injection via a JDBC URL parameter. The vulnerability is rooted in the improper handling …
|
-
|
CVE-2024-49194
|
2024-12-19 02:15 |
2024-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|