9052 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-32371
Software Genérico General
7.5
HIGH
EPSS
0.7%
2024 1 PoC

An issue in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a regular user account to escalate their privileges and gain administrative access by changing the type parameter from 1 to 0.

CVE-2024-37728
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
13.5%
2024 0 PoCs

Arbitrary File Read vulnerability in Xi'an Daxi Information Technology Co., Ltd OfficeWeb365 v.7.18.23.0 and v8.6.1.0 allows a remote attacker to obtain sensitive information via the "Pic/Indexes" interface

CVE-2024-42861
Software Genérico General
7.5
HIGH
EPSS
31.9%
2024 1 PoC

An issue in IEEE 802.1AS linuxptp v.4.2 and before allowing a remote attacker to cause a denial of service via a crafted Pdelay_Req message to the time synchronization function

CVE-2024-53027
Snapdragon General
7.5
HIGH
EPSS
0.3%
2024 CWE-120 1 PoC

Transient DOS may occur while processing the country IE.

CVE-2024-57699
Software Genérico General
7.5
HIGH
EPSS
0.0%
2024 1 PoC

A security issue was found in Netplex Json-smart 2.5.0 through 2.5.1. When loading a specially crafted JSON input, containing a large number of ’{’, a stack exhaustion can be trigger, which could allow an attacker to cause a Denial of Service (DoS). This issue exists because of an incomplete fix for CVE-2023-1370.

CVE-2024-21502
fastecdsa General
7.5
HIGH
EPSS
0.1%
2024 CWE-457 1 PoC

Versions of the package fastecdsa before 2.3.2 are vulnerable to Use of Uninitialized Variable on the stack, via the curvemath_mul function in src/curveMath.c, due to being used and interpreted as user-defined type. Depending on the variable's actual value it could be arbitrary free(), arbitrary realloc(), null pointer dereference and other. Since the stack can be controlled by the attacker, the vulnerability could be used to corrupt allocator structure, leading to possible heap exploitation. The attacker could cause denial of service by exploiting this vulnerability.

CVE-2024-35059
Software Genérico General
7.5
HIGH
EPSS
0.1%
2024 1 PoC

An issue in the Pickle Python library of NASA AIT-Core v2.5.2 allows attackers to execute arbitrary commands.

CVE-2024-11392
Transformers General
7.5
HIGH
EPSS
59.3%
2024 CWE-502 1 PoC

Hugging Face Transformers MobileViTV2 Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hugging Face Transformers. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of configuration files. The issue results from the lack of proper validation of user-supplied data, which can result in deserialization of untrusted data. An attacker can leverage this vul

CVE-2024-3852
Firefox General
7.5
HIGH
EPSS
1.0%
2024 1 PoC

GetBoundName could return the wrong version of an object when JIT optimizations were applied. This vulnerability affects Firefox < 125, Firefox ESR < 115.10, and Thunderbird < 115.10.

CVE-2024-37880
Software Genérico General
7.5
HIGH
EPSS
0.1%
2024 1 PoC

The Kyber reference implementation before 9b8d306, when compiled by LLVM Clang through 18.x with some common optimization options, has a timing side channel that allows attackers to recover an ML-KEM 512 secret key in minutes. This occurs because poly_frommsg in poly.c does not prevent Clang from emitting a vulnerable secret-dependent branch.

CVE-2024-33655
Software Genérico General
7.5
HIGH
EPSS
3.6%
2024 2 PoCs

The DNS protocol in RFC 1035 and updates allows remote attackers to cause a denial of service (resource consumption) by arranging for DNS queries to be accumulated for seconds, such that responses are later sent in a pulsing burst (which can be considered traffic amplification in some cases), aka the "DNSBomb" issue.

CVE-2024-54767
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
7.0%
2024 0 PoCs

An access control issue in the component /juis_boxinfo.xml of AVM FRITZ!Box 7530 AX v7.59 allows attackers to obtain sensitive information without authentication. NOTE: this is disputed by the Supplier because it cannot be reproduced, and the issue report focuses on an unintended configuration with direct Internet exposure.

CVE-2024-29511
Software Genérico General
7.5
HIGH
EPSS
0.5%
2024 2 PoCs

Artifex Ghostscript before 10.03.1, when Tesseract is used for OCR, has a directory traversal issue that allows arbitrary file reading (and writing of error messages to arbitrary files) via OCRLanguage. For example, exploitation can use debug_file /tmp/out and user_patterns_file /etc/passwd.

CVE-2024-24427
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

A reachable assertion in the amf_ue_set_suci function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet.

CVE-2024-47915
VaeMendis Ubooquity version 2.1.2 General
7.5
HIGH
EPSS
0.3%
2024 CWE-200 1 PoC

VaeMendis - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

CVE-2024-41996
Software Genérico General
7.5
HIGH
EPSS
0.6%
2024 3 PoCs

Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used, allows remote attackers (from the client side) to trigger unnecessarily expensive server-side DHE modular-exponentiation calculations. The client may cause asymmetric resource consumption. The basic attack scenario is that the client must claim that it can only communicate with DHE, and the server must be configured to allow DHE and validate the order of the public key.

CVE-2024-8751
SICK MSC800 General
7.5
HIGH
EPSS
0.1%
2024 CWE-306 1 PoC

A vulnerability in the MSC800 allows an unauthenticated attacker to modify the product’s IP address over Sopas ET. This can lead to Denial of Service. Users are recommended to upgrade both MSC800 and MSC800 LFT to version V4.26 and S2.93.20 respectively which fixes this issue.

CVE-2024-45432
Software Genérico General
7.5
HIGH
EPSS
0.1%
2024 1 PoC

OpenSynergy BlueSDK (aka Blue SDK) through 6.x mishandles a function call. The specific flaw exists within the BlueSDK Bluetooth stack. The issue results from an incorrect variable used as a function argument. An attacker can leverage this to cause unexpected behavior or obtain sensitive information.

CVE-2024-23766
Software Genérico General
7.5
HIGH
EPSS
0.3%
2024 1 PoC

An issue was discovered on HMS Anybus X-Gateway AB7832-F 3 devices. The gateway exposes a web interface on port 80. An unauthenticated GET request to a specific URL triggers the reboot of the Anybus gateway (or at least most of its modules). An attacker can use this feature to carry out a denial of service attack by continuously sending GET requests to that URL.

CVE-2024-41696
PRI WEB Portal Add-On for Priority ERP on prem General
7.5
HIGH
EPSS
0.4%
2024 CWE-200 1 PoC

Priority PRI WEB Portal Add-On for Priority ERP on prem - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor