|
312871
|
- |
|
-
|
-
|
Loftware Spectrum before 4.6 HF13 Deserializes Untrusted Data.
|
-
|
CVE-2023-37227
|
2024-09-11 02:35 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312872
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
media: dvb-usb-v2: af9035: Fix null-ptr-deref in af9035_i2c_master_xfer
In af9035_i2c_master_xfer, msg is controlled by user. Whe…
|
CWE-476
NULL Pointer Dereference
|
CVE-2023-52915
|
2024-09-11 02:12 |
2024-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312873
|
7.5 |
HIGH
Network
|
dlink
|
dir-823g_firmware
|
D-Link DIR-823G v1.0.2B05_20181207 is vulnerable to Information Disclosure. The device allows unauthorized configuration file downloads, and the downloaded configuration files contain plaintext user …
|
CWE-862
Missing Authorization
|
CVE-2024-44408
|
2024-09-11 02:01 |
2024-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312874
|
9.8 |
CRITICAL
Network
|
dlink
|
di-8100g_firmware
|
D-Link DI-8100G 17.12.20A1 is vulnerable to Command Injection via msp_info.htm.
|
CWE-77
Command Injection
|
CVE-2024-44402
|
2024-09-11 01:58 |
2024-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312875
|
7.1 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
netfilter: flowtable: validate vlan header
Ensure there is sufficient room to access the protocol field of the
VLAN header, valid…
|
CWE-908
Use of Uninitialized Resource
|
CVE-2024-44983
|
2024-09-11 01:57 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312876
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm/xe: Free job before xe_exec_queue_put
Free job depends on job->vm being valid, the last xe_exec_queue_put can
destroy the VM.…
|
CWE-416
Use After Free
|
CVE-2024-44978
|
2024-09-11 01:51 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312877
|
8.6 |
HIGH
Network
|
fogproject
|
fogproject
|
FOG is a cloning/imaging/rescue suite/inventory management system. FOG Server 1.5.10.41.2 can leak AD username and password when registering a computer. This vulnerability is fixed in 1.5.10.41.3 an…
|
CWE-77
Command Injection
|
CVE-2024-42348
|
2024-09-11 01:49 |
2024-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312878
|
5.3 |
MEDIUM
Network
|
fogproject
|
fogproject
|
FOG is a cloning/imaging/rescue suite/inventory management system. FOG Server 1.5.10.41.4 and earlier can leak authorized and rejected logins via logs stored directly on the root of the web server. F…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2024-42349
|
2024-09-11 01:44 |
2024-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312879
|
9.8 |
CRITICAL
Network
|
horizoncloud
|
caterease
|
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform a Traffic Injection attack due to improper verifi…
|
NVD-CWE-Other
|
CVE-2024-38886
|
2024-09-11 01:40 |
2024-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312880
|
9.8 |
CRITICAL
Network
|
horizoncloud
|
caterease
|
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows a remote attacker to perform SQL Injection due to improper neutralization of s…
|
CWE-89
SQL Injection
|
CVE-2024-38889
|
2024-09-11 01:38 |
2024-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|