3333 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-24552
Bludit General
5.6
MEDIUM
EPSS
0.0%
2024 CWE-384 1 PoC

A session fixation vulnerability in Bludit allows an attacker to bypass the server's authentication if they can trick an administrator or any other user into authorizing a session ID of their choosing.

CVE-2024-35315
Software Genérico General
5.6
MEDIUM
EPSS
1.3%
2024 1 PoC

A vulnerability in the Desktop Client of Mitel MiCollab through 9.7.1.110, and MiVoice Business Solution Virtual Instance (MiVB SVI) 1.0.0.25, could allow an authenticated attacker to conduct a privilege escalation attack due to improper file validation. A successful exploit could allow an attacker to run arbitrary code with elevated privileges.

CVE-2024-20869
Samsung Internet General
5.5
MEDIUM
EPSS
0.0%
2024 1 PoC

Improper privilege management vulnerability in Samsung Internet prior to version 25.0.0.41 allows local attackers to bypass protection for cookies.

CVE-2024-38432
Tafnit v8 General
5.5
MEDIUM
EPSS
0.1%
2024 CWE-646 1 PoC

Matrix Tafnit v8 - CWE-646: Reliance on File Name or Extension of Externally-Supplied File

CVE-2024-2760
Bkav Home General
5.5
MEDIUM
EPSS
0.0%
2024 CWE-404 1 PoC

Bkav Home v7816, build 2403161130 is vulnerable to a Memory Information Leak vulnerability by triggering the 0x222240 IOCTL code of the BkavSDFlt.sys driver.

CVE-2024-34629
Samsung Notes General
5.5
MEDIUM
EPSS
0.2%
2024 1 PoC

Out-of-bounds read in applying binary with text common object in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

CVE-2024-40793
iOS and iPadOS General
5.5
MEDIUM
EPSS
0.0%
2024 4 PoCs

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, watchOS 10.6. An app may be able to access user-sensitive data.

CVE-2024-20867
Samsung Email General
5.5
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper privilege management vulnerability in Samsung Email prior to version 6.1.91.14 allows local attackers to access sensitive information.

CVE-2024-34631
Samsung Notes General
5.5
MEDIUM
EPSS
0.2%
2024 1 PoC

Out-of-bounds read in applying new binary in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

CVE-2024-40804
macOS General
5.5
MEDIUM
EPSS
0.1%
2024 1 PoC

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6. A malicious application may be able to access private information.

CVE-2024-36476
Linux General
5.5
MEDIUM
EPSS
0.0%
2024 1 PoC

In the Linux kernel, the following vulnerability has been resolved: RDMA/rtrs: Ensure 'ib_sge list' is accessible Move the declaration of the 'ib_sge list' variable outside the 'always_invalidate' block to ensure it remains accessible for use throughout the function. Previously, 'ib_sge list' was declared within the 'always_invalidate' block, limiting its accessibility, then caused a 'BUG: kernel NULL pointer dereference'[1]. ? __die_body.cold+0x19/0x27 ? page_fault_oops+0x15a/0x2d0 ? search_module_extables+0x19/0x60 ? search_bpf_extables+0x5f/0x80 ? exc_page_fault+0x7e/0x180 ? asm_ex

CVE-2024-23850
Software Genérico General
5.5
MEDIUM
EPSS
0.0%
2024 1 PoC

In btrfs_get_root_ref in fs/btrfs/disk-io.c in the Linux kernel through 6.7.1, there can be an assertion failure and crash because a subvolume can be read out too soon after its root item is inserted upon subvolume creation.

CVE-2024-20859
Samsung Mobile Devices General
5.5
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper access control vulnerability in FactoryCamera prior to SMR May-2024 Release 1 allows local attackers to take pictures without privilege.

CVE-2024-34628
Samsung Notes General
5.5
MEDIUM
EPSS
0.2%
2024 1 PoC

Out-of-bounds read in applying binary with path in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

CVE-2024-34627
Samsung Notes General
5.5
MEDIUM
EPSS
0.2%
2024 1 PoC

Out-of-bounds read in parsing implemention in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

CVE-2024-27872
macOS General
5.5
MEDIUM
EPSS
0.1%
2024 1 PoC

This issue was addressed with improved validation of symlinks. This issue is fixed in macOS Sonoma 14.6. An app may be able to access protected user data.

CVE-2024-40806
iOS and iPadOS General
5.5
MEDIUM
EPSS
0.0%
2024 4 PoCs

An out-of-bounds read issue was addressed with improved input validation. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing a maliciously crafted file may lead to unexpected app termination.

CVE-2024-47102
AIX General
5.5
MEDIUM
EPSS
0.0%
2024 CWE-863 1 PoC

IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1 could allow a non-privileged local user to exploit a vulnerability in the AIX perfstat kernel extension to cause a denial of service.

CVE-2024-49533
Acrobat Reader General
5.5
MEDIUM
EPSS
0.0%
2024 CWE-125 1 PoC

Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVE-2024-34625
Samsung Notes General
5.5
MEDIUM
EPSS
0.2%
2024 1 PoC

Out-of-bounds read in applying connection point in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.