3333 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-25270
Software Genérico General
4.3
MEDIUM
EPSS
0.2%
2024 1 PoC

An issue in Mirapolis LMS 4.6.XX allows authenticated users to exploit an Insecure Direct Object Reference (IDOR) vulnerability by manipulating the ID parameter and increment STEP parameter, leading to the exposure of sensitive user data.

CVE-2024-23298
Xcode General
4.3
MEDIUM
EPSS
1.5%
2024 1 PoC

A logic issue was addressed with improved state management. This issue is fixed in Xcode 15.3. An app may bypass Gatekeeper checks.

CVE-2024-5690
Firefox General
4.3
MEDIUM
EPSS
5.9%
2024 1 PoC

By monitoring the time certain operations take, an attacker could have guessed which external protocol handlers were functional on a user's system. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.

CVE-2024-1402
Mattermost General
4.3
MEDIUM
EPSS
0.4%
2024 CWE-400 1 PoC

Mattermost fails to check if a custom emoji reaction exists when sending it to a post and to limit the amount of custom emojis allowed to be added in a post, allowing an attacker sending a huge amount of non-existent custom emojis in a post to crash the mobile app of a user seeing the post and to crash the server due to overloading when clients attempt to retrive the aforementioned post. 

CVE-2024-37386
Software Genérico General
4.2
MEDIUM
EPSS
0.0%
2024 1 PoC

An issue was discovered in Stormshield Network Security (SNS) 4.0.0 through 4.3.25, 4.4.0 through 4.7.5, and 4.8.0. Certain manipulations allow restarting in single-user mode despite the activation of secure boot. The following versions fix this: 4.3.27, 4.7.6, and 4.8.2.

CVE-2024-20873
Samsung Mobile Devices General
4.2
MEDIUM
EPSS
0.1%
2024 1 PoC

Improper input validation vulnerability in caminfo driver prior to SMR Jun-2024 Release 1 allows local privileged attackers to write out-of-bounds memory.

CVE-2024-5835
Chrome General
4.2
MEDIUM
EPSS
0.1%
2024 1 PoC

Heap buffer overflow in Tab Groups in Google Chrome prior to 126.0.6478.54 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

CVE-2024-41597
Software Genérico General
4.2
MEDIUM
EPSS
0.3%
2024 1 PoC

Cross Site Request Forgery vulnerability in ProcessWire v.3.0.229 allows a remote attacker to execute arbitrary code via a crafted HTML file to the comments functionality.

CVE-2024-20842
Samsung Mobile Devices General
4.2
MEDIUM
EPSS
0.0%
2024 1 PoC

Improper Input Validation vulnerability in handling apdu of libsec-ril prior to SMR Apr-2024 Release 1 allows local privileged attackers to write out-of-bounds memory.

CVE-2024-34398
Software Genérico General
4.2
MEDIUM
EPSS
0.1%
2024 1 PoC

An issue was discovered in BMC Remedy Mid Tier 7.6.04. The web application allows stored HTML Injection by authenticated remote attackers.

CVE-2024-39767
Mattermost General
4.2
MEDIUM
EPSS
0.1%
2024 CWE-287 1 PoC

Mattermost Mobile Apps versions <=2.16.0 fail to validate that the push notifications received for a server actually came from this serve that which allows a malicious server to send push notifications with another server’s diagnostic ID or server URL and have them show up in mobile apps as that server’s push notifications.

CVE-2024-45678
Software Genérico General
4.2
MEDIUM
EPSS
0.2%
2024 1 PoC

Yubico YubiKey 5 Series devices with firmware before 5.7.0 and YubiHSM 2 devices with firmware before 2.4.0 allow an ECDSA secret-key extraction attack (that requires physical access and expensive equipment) in which an electromagnetic side channel is present because of a non-constant-time modular inversion for the Extended Euclidean Algorithm, aka the EUCLEAK issue. Other uses of an Infineon cryptographic library may also be affected.

CVE-2024-41162
Mattermost General
4.1
MEDIUM
EPSS
0.1%
2024 CWE-284 1 PoC

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5 and 9.8.x <= 9.8.1 fail to disallow the modification of local channels by a remote, when shared channels are enabled, which allows a malicious remote to make an arbitrary local channel read-only.

CVE-2024-34673
Samsung Mobile Devices General
4.1
MEDIUM
EPSS
0.0%
2024 1 PoC

Improper Input Validation in IpcProtocol in Modem prior to SMR Nov-2024 Release 1 allows local attackers to cause Denial-of-Service.

CVE-2024-52935
Graphics DDK General
4.1
MEDIUM
EPSS
0.1%
2024 CWE-823 1 PoC

Kernel software installed and running inside a Guest VM may exploit memory shared with the GPU Firmware to write data outside the Guest's virtualised GPU memory.

CVE-2024-20833
Samsung Mobile Devices General
4.1
MEDIUM
EPSS
0.0%
2024 1 PoC

Use after free vulnerability in pub_crypto_recv_msg prior to SMR Mar-2024 Release 1 due to race condition allows local attackers with system privilege to cause memory corruption.

CVE-2024-34664
Samsung Mobile Devices General
4.1
MEDIUM
EPSS
0.0%
2024 1 PoC

Improper check for exception conditions in Knox Guard prior to SMR Oct-2024 Release 1 allows physical attackers to bypass Knox Guard in a multi-user environment.

CVE-2024-31843
Software Genérico General
4.1
MEDIUM
EPSS
0.1%
2024 1 PoC

An issue was discovered in Italtel Embrace 1.6.4. The Web application does not properly check the parameters sent as input before they are processed on the server side. This allows authenticated users to execute commands on the Operating System.

CVE-2024-20899
Samsung Mobile Devices General
4.0
MEDIUM
EPSS
0.1%
2024 1 PoC

Use of implicit intent for sensitive communication in RCS function in IMS service prior to SMR Jul-2024 Release 1 allows local attackers to get sensitive information.

CVE-2024-34632
Samsung Notes General
4.0
MEDIUM
EPSS
0.2%
2024 1 PoC

Out-of-bounds read in uuid parsing in Samsung Notes prior to version 4.4.21.62 allows local attacker to access unauthorized memory.