3333 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-34625
Samsung Notes General
5.5
MEDIUM
EPSS
0.2%
2024 1 PoC

Out-of-bounds read in applying connection point in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

CVE-2024-2180
AntiLogger General
5.5
MEDIUM
EPSS
0.0%
2024 CWE-404 1 PoC

Zemana AntiLogger v2.74.204.664 is vulnerable to a Memory Information Leak vulnerability by triggering the 0x80002020 IOCTL code of the zam64.sys and zamguard64.sys drivers

CVE-2024-27871
iOS and iPadOS General
5.5
MEDIUM
EPSS
0.0%
2024 2 PoCs

A path handling issue was addressed with improved validation. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6. An app may be able to access protected user data.

CVE-2024-0020
Android General
5.5
MEDIUM
EPSS
0.0%
2024 1 PoC

In onActivityResult of NotificationSoundPreference.java, there is a possible way to hear audio files belonging to a different user due to a confused deputy. This could lead to local information disclosure across users of a device with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2024-34628
Samsung Notes General
5.5
MEDIUM
EPSS
0.2%
2024 1 PoC

Out-of-bounds read in applying binary with path in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

CVE-2024-2611
Firefox General
5.5
MEDIUM
EPSS
0.3%
2024 1 PoC

A missing delay on when pointer lock was used could have allowed a malicious page to trick a user into granting permissions. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

CVE-2024-0311
Skyhigh Client Proxy General
5.5
MEDIUM
EPSS
0.1%
2024 CWE-622 1 PoC

A malicious insider can bypass the existing policy of Skyhigh Client Proxy without a valid release code.

CVE-2024-40807
macOS General
5.5
MEDIUM
EPSS
0.0%
2024 2 PoCs

A logic issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. A shortcut may be able to use sensitive data with certain actions without prompting the user.

CVE-2024-56665
Linux General
5.5
MEDIUM
EPSS
0.0%
2024 1 PoC

In the Linux kernel, the following vulnerability has been resolved: bpf,perf: Fix invalid prog_array access in perf_event_detach_bpf_prog Syzbot reported [1] crash that happens for following tracing scenario: - create tracepoint perf event with attr.inherit=1, attach it to the process and set bpf program to it - attached process forks -> chid creates inherited event the new child event shares the parent's bpf program and tp_event (hence prog_array) which is global for tracepoint - exit both process and its child -> release both events - first perf_event_detach_bpf_prog

CVE-2024-3209
UPX General
5.5
MEDIUM
EPSS
0.4%
2024 CWE-122 1 PoC

A vulnerability was found in UPX up to 4.2.2. It has been rated as critical. This issue affects the function get_ne64 of the file bele.h. The manipulation leads to heap-based buffer overflow. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-259055. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-0312
Skyhigh Client Proxy General
5.5
MEDIUM
EPSS
0.0%
2024 CWE-622 1 PoC

A malicious insider can uninstall Skyhigh Client Proxy without a valid uninstall password.

CVE-2024-2982
FH1202 General
5.5
MEDIUM
EPSS
5.1%
2024 CWE-77 1 PoC

A vulnerability has been found in Tenda FH1202 1.2.0.14(408) and classified as critical. Affected by this vulnerability is the function formWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac leads to command injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-258151. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-34672
SamsungVideoPlayer General
5.5
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper input validation in SamsungVideoPlayer prior to versions 7.3.29.1 in Android 12, 7.3.36.1 in Android 13, and 7.3.41.230 in Android 14 allows local attackers to access video file of other users.

CVE-2024-37877
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2024 1 PoC

UERANSIM before 3.2.6 allows out-of-bounds read when a RLS packet is sent to gNodeB with malformed PDU length. This occurs in function readOctetString in src/utils/octet_view.cpp and in function DecodeRlsMessage in src/lib/rls/rls_pdu.cpp

CVE-2024-56702
Linux General
5.5
MEDIUM
EPSS
0.0%
2024 1 PoC

In the Linux kernel, the following vulnerability has been resolved: bpf: Mark raw_tp arguments with PTR_MAYBE_NULL Arguments to a raw tracepoint are tagged as trusted, which carries the semantics that the pointer will be non-NULL. However, in certain cases, a raw tracepoint argument may end up being NULL. More context about this issue is available in [0]. Thus, there is a discrepancy between the reality, that raw_tp arguments can actually be NULL, and the verifier's knowledge, that they are never NULL, causing explicit NULL checks to be deleted, and accesses to such pointers potentially cr

CVE-2024-8270
Rocket.Chat Desktop General
5.5
MEDIUM
EPSS
0.1%
2024 CWE-863 1 PoC

The macOS Rocket.Chat application is affected by a vulnerability that allows bypassing Transparency, Consent, and Control (TCC) policies, enabling the exploitation or abuse of permissions specified in its entitlements (e.g., microphone, camera, automation, network client). Since Rocket.Chat was not signed with the Hardened Runtime nor set to enforce Library Validation, it is vulnerable to DYLIB injection attacks, which can lead to unauthorized actions or escalation of permissions. Consequently, an attacker gains capabilities that are not permitted by default under the Sandbox and its applicat

CVE-2024-20824
Galaxy Store General
5.5
MEDIUM
EPSS
0.0%
2024 1 PoC

Implicit intent hijacking vulnerability in VoiceSearch of Galaxy Store prior to version 4.5.63.6 allows local attackers to access sensitive information via implicit intent.

CVE-2024-36424
Software Genérico General
5.5
MEDIUM
EPSS
0.6%
2024 1 PoC

K7RKScan.sys in K7 Ultimate Security before 17.0.2019 allows local users to cause a denial of service (BSOD) because of a NULL pointer dereference.

CVE-2024-40827
macOS General
5.5
MEDIUM
EPSS
0.0%
2024 2 PoCs

The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. An app may be able to overwrite arbitrary files.

CVE-2024-49404
Samsung Video Player General
5.5
MEDIUM
EPSS
0.2%
2024 1 PoC

Improper Access Control in Samsung Video Player prior to versions 7.3.29.1 in Android 12, 7.3.36.1 in Android 13, and 7.3.41.230 in Android 14 allows physical attackers to access video file of other users.