|
312931
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
netfilter: ctnetlink: use helper function to calculate expect ID
Delete expectation path is missing a call to the nf_expect_get_i…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2024-44944
|
2024-09-10 17:15 |
2024-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312932
|
5.5 |
MEDIUM
Local
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
-
|
CVE-2024-43898
|
2024-09-10 17:15 |
2024-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312933
|
- |
|
-
|
-
|
OS command injection vulnerability exists in BUFFALO wireless LAN routers and wireless LAN repeaters. If a user logs in to the management page and sends a specially crafted request to the affected pr…
|
-
|
CVE-2024-44072
|
2024-09-10 16:15 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312934
|
- |
|
-
|
-
|
The Starbox WordPress plugin before 3.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even …
|
-
|
CVE-2024-7955
|
2024-09-10 15:15 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312935
|
- |
|
-
|
-
|
The RFC enabled function module allows a low privileged user to perform denial of service on any user and also change or delete favourite nodes. By sending a crafted packet in the function module tar…
|
CWE-862
Missing Authorization
|
CVE-2024-45285
|
2024-09-10 14:15 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312936
|
- |
|
-
|
-
|
An authenticated attacker with high privilege can use functions of SLCM transactions to which access should be restricted. This may result in an escalation of privileges causing low impact on integri…
|
CWE-862
Missing Authorization
|
CVE-2024-45284
|
2024-09-10 14:15 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312937
|
- |
|
-
|
-
|
SAP NetWeaver AS for Java allows an authorized attacker to obtain sensitive information. The attacker could obtain the username and password when creating an RFC destination. After successful exploit…
|
CWE-256
Plaintext Storage of a Password
|
CVE-2024-45283
|
2024-09-10 14:15 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312938
|
- |
|
-
|
-
|
SAP BusinessObjects Business Intelligence Platform allows a high privilege user to run client desktop applications even if some of the DLLs are not digitally signed or if the signature is broken. The…
|
CWE-426
Untrusted Search Path
|
CVE-2024-45281
|
2024-09-10 14:15 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312939
|
- |
|
-
|
-
|
Due to insufficient encoding of user-controlled inputs, SAP NetWeaver AS Java allows malicious scripts to be executed in the login application. This has a limited impact on confidentiality and integr…
|
CWE-79
Cross-site Scripting
|
CVE-2024-45280
|
2024-09-10 14:15 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312940
|
- |
|
-
|
-
|
Due to insufficient input validation, CRM Blueprint Application Builder Panel of SAP NetWeaver Application Server for ABAP allows an unauthenticated attacker to craft a URL link which could embed a m…
|
CWE-79
Cross-site Scripting
|
CVE-2024-45279
|
2024-09-10 14:15 |
2024-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|