3333 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-29978
Multiple MFPs (multifunction printers) General
5.9
MEDIUM
EPSS
0.3%
2024 CWE-256 3 PoCs

User passwords are decrypted and stored on memory before any user logged in. Those decrypted passwords can be retrieved from the coredump file. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

CVE-2024-25053
Cognos Analytics General
5.9
MEDIUM
EPSS
0.1%
2024 CWE-295 1 PoC

IBM Cognos Analytics 11.2.0, 11.2.1, 11.2.2, 11.2.3, 11.2.4, 12.0.0, 12.0.1, and 12.0.2 is vulnerable to improper certificate validation when using the IBM Planning Analytics Data Source Connection. This could allow an attacker to spoof a trusted entity by interfering in the communication path between IBM Planning Analytics server and IBM Cognos Analytics server. IBM X-Force ID: 283364.

CVE-2024-28065
Software Genérico General
5.9
MEDIUM
EPSS
0.0%
2024 2 PoCs

In Unify CP IP Phone firmware 1.10.4.3, files are not encrypted and contain sensitive information such as the root password hash.

CVE-2024-24454
HPE Athonet Core General
5.9
MEDIUM
EPSS
0.3%
2024 1 PoC

An invalid memory access when handling the ProtocolIE_ID field of E-RAB Modify Request messages in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial of Service (DoS) to the cellular network by repeatedly initiating connections and sending a crafted payload.

CVE-2024-24553
Bludit General
5.9
MEDIUM
EPSS
0.1%
2024 CWE-916 1 PoC

Bludit uses the SHA-1 hashing algorithm to compute password hashes. Thus, attackers could determine cleartext passwords with brute-force attacks due to the inherent speed of SHA-1. In addition, the salt that is computed by Bludit is generated with a non-cryptographically secure function.

CVE-2024-50383
Software Genérico General
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

Botan before 3.6.0, when certain GCC versions are used, has a compiler-induced secret-dependent operation in lib/utils/donna128.h in donna128 (used in Chacha-Poly1305 and x25519). An addition can be skipped if a carry is not set. This was observed for GCC 11.3.0 with -O2 on MIPS, and GCC on x86-i386. (Only 32-bit processors can be affected.)

CVE-2024-34596
SmartThings General
5.9
MEDIUM
EPSS
0.3%
2024 1 PoC

Improper authentication in SmartThings prior to version 1.8.17 allows remote attackers to bypass the expiration date for members set by the owner.

CVE-2024-56085
Software Genérico General
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

An issue was discovered in Logpoint before 7.5.0. Authenticated users can inject payloads while creating Search Template Dashboard. These are executed, leading to Server-Side Template Injection.

CVE-2024-20901
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper input validation in copying data to buffer cache in libsaped prior to SMR Jul-2024 Release 1 allows local attackers to write out-of-bounds memory.

CVE-2024-20854
Samsung Camera General
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper handling of insufficient privileges vulnerability in Samsung Camera prior to versions 12.1.0.31 in Android 12, 13.1.02.07 in Android 13, and 14.0.01.06 in Android 14 allows local attackers to access image data.

CVE-2024-3837
Chrome General
5.9
MEDIUM
EPSS
0.7%
2024 2 PoCs

Use after free in QUIC in Google Chrome prior to 124.0.6367.60 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)

CVE-2024-4775
Firefox General
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

An iterator stop condition was missing when handling WASM code in the built-in profiler, potentially leading to invalid memory access and undefined behavior. *Note:* This issue only affects the application when the profiler is running. This vulnerability affects Firefox < 126.

CVE-2024-24458
HPE Athonet Core General
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

An invalid memory access when handling the ENB Configuration Transfer messages containing invalid PLMN Identities in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial of Service (DoS) to the cellular network by repeatedly initiating connections and sending a crafted payload.

CVE-2024-21528
node-gettext General
5.9
MEDIUM
EPSS
0.1%
2024 CWE-1321 1 PoC

All versions of the package node-gettext are vulnerable to Prototype Pollution via the addTranslations() function in gettext.js due to improper user input sanitization.

CVE-2024-20846
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

Out-of-bounds write vulnerability while decoding hcr of libsavsac.so prior to SMR Apr-2024 Release 1 allows local attacker to execute arbitrary code.

CVE-2024-20852
SmartThings General
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper verification of intent by broadcast receiver vulnerability in SmartThings prior to version 1.8.13.22 allows local attackers to access testing configuration.

CVE-2024-34586
Samsung Mobile Devices General
5.9
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper access control in KnoxCustomManagerService prior to SMR Jul-2024 Release 1 allows local attackers to configure Knox privacy policy.

CVE-2024-24452
HPE Athonet Core General
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

An invalid memory access when handling the ProtocolIE_ID field of E-RAB Release Indication messages in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial of Service (DoS) to the cellular network by repeatedly initiating connections and sending a crafted payload.

CVE-2024-24455
HPE Athonet Core General
5.9
MEDIUM
EPSS
0.2%
2024 1 PoC

An invalid memory access when handling a UE Context Release message containing an invalid UE identifier in Athonet vEPC MME v11.4.0 allows attackers to cause a Denial of Service (DoS) to the cellular network by repeatedly initiating connections and sending a crafted payload.

CVE-2024-40774
iOS and iPadOS General
5.9
MEDIUM
EPSS
0.0%
2024 3 PoCs

A downgrade issue was addressed with additional code-signing restrictions. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, tvOS 17.6, watchOS 10.6. An app may be able to bypass Privacy preferences.