3333 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-40777
iOS and iPadOS General
3.3
LOW
EPSS
0.5%
2024 2 PoCs

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, visionOS 1.3, watchOS 10.6. Processing a maliciously crafted file may lead to unexpected app termination.

CVE-2024-30363
PDF Reader General
3.3
LOW
EPSS
0.3%
2024 CWE-125 1 PoC

Foxit PDF Reader U3D File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of U3D files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with othe

CVE-2024-40798
iOS and iPadOS General
3.3
LOW
EPSS
0.0%
2024 3 PoCs

This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. An app may be able to read Safari's browsing history.

CVE-2024-9246
PDF Reader General
3.3
LOW
EPSS
0.3%
2024 CWE-125 1 PoC

Foxit PDF Reader Annotation Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction with

CVE-2024-0886
EZ CD Audio Converter General
3.3
LOW
EPSS
0.0%
2024 CWE-404 1 PoC

A vulnerability classified as problematic was found in Poikosoft EZ CD Audio Converter 8.0.7. Affected by this vulnerability is an unknown functionality of the component Activation Handler. The manipulation of the argument Key leads to denial of service. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The identifier VDB-252037 was assigned to this vulnerability.

CVE-2024-40795
iOS and iPadOS General
3.3
LOW
EPSS
0.0%
2024 2 PoCs

This issue was addressed with improved data protection. This issue is fixed in iOS 17.6 and iPadOS 17.6, macOS Sonoma 14.6, tvOS 17.6, watchOS 10.6. An app may be able to read sensitive location information.

CVE-2024-20807
Samsung Email General
3.3
LOW
EPSS
0.1%
2024 1 PoC

Implicit intent hijacking vulnerability in Samsung Email prior to version 6.1.90.16 allows local attacker to get sensitive information.

CVE-2024-20836
Samsung Mobile Devices General
3.3
LOW
EPSS
0.1%
2024 1 PoC

Out of bounds Read vulnerability in ssmis_get_frm in libsubextractor.so prior to SMR Mar-2024 Release 1 allows local attackers to read out of bounds memory.

CVE-2024-20805
Samsung Mobile Devices General
3.3
LOW
EPSS
0.1%
2024 1 PoC

Path traversal vulnerability in ZipCompressor of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in Android 13 allows local attackers to write arbitrary file.

CVE-2024-20810
Samsung Mobile Devices General
3.3
LOW
EPSS
0.1%
2024 1 PoC

Implicit intent hijacking vulnerability in Smart Suggestions prior to SMR Feb-2024 Release 1 allows local attackers to get sensitive information.

CVE-2024-29508
Software Genérico General
3.3
LOW
EPSS
0.0%
2024 2 PoCs

Artifex Ghostscript before 10.03.0 has a heap-based pointer disclosure (observable in a constructed BaseFont name) in the function pdf_base_font_alloc.

CVE-2024-30356
PDF Reader General
3.3
LOW
EPSS
0.3%
2024 CWE-125 1 PoC

Foxit PDF Reader AcroForm Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects in AcroForms. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this in conjunction w

CVE-2024-23743
Software Genérico General
3.3
LOW
EPSS
0.2%
2024 2 PoCs

Notion through 3.1.0 on macOS might allow code execution because of RunAsNode and enableNodeClilnspectArguments. NOTE: the vendor states "the attacker must launch the Notion Desktop application with nonstandard flags that turn the Electron-based application into a Node.js execution environment."

CVE-2024-3872
Mattermost General
3.1
LOW
EPSS
0.4%
2024 CWE-400 1 PoC

Mattermost Mobile app versions 2.13.0 and earlier use a regular expression with polynomial complexity to parse certain deeplinks, which allows an unauthenticated remote attacker to freeze or crash the app via a long maliciously crafted link.

CVE-2024-36250
Mattermost General
3.1
LOW
EPSS
0.3%
2024 CWE-303 1 PoC

Mattermost versions 9.11.x <= 9.11.2, and 9.5.x <= 9.5.10 fail to protect the mfa code against replay attacks, which allows an attacker to reuse the MFA code within ~30 seconds

CVE-2024-1952
Mattermost General
3.1
LOW
EPSS
0.3%
2024 CWE-200 1 PoC

Mattermost version 8.1.x before 8.1.9 fails to sanitize data associated with permalinks when a plugin updates an ephemeral post, allowing an authenticated attacker who can control the ephemeral post update to access individual posts' contents in channels they are not a member of.

CVE-2024-39361
Mattermost General
3.1
LOW
EPSS
0.1%
2024 CWE-284 1 PoC

Mattermost versions 9.8.0, 9.7.x <= 9.7.4, 9.6.x <= 9.6.2 and 9.5.x <= 9.5.5 fail to prevent users from specifying a RemoteId for their posts which allows an attacker to specify both a remoteId and the post ID, resulting in creating a post with a user-defined post ID. This can cause some broken functionality in the channel or thread with user-defined posts

CVE-2024-36066
Software Genérico General
3.1
LOW
EPSS
0.4%
2024 1 PoC

The CMP CLI client in KeyFactor EJBCA before 8.3.1 has only 6 octets of salt, and is thus not compliant with the security requirements of RFC 4211, and might make man-in-the-middle attacks easier. CMP includes password-based MAC as one of the options for message integrity and authentication (the other option is certificate-based). RFC 4211 section 4.4 requires that password-based MAC parameters use a salt with a random value of at least 8 octets. This helps to inhibit dictionary attacks. Because the standalone CMP client originally was developed as test code, the salt was instead hardcoded and

CVE-2024-22091
Mattermost General
3.1
LOW
EPSS
0.1%
2024 CWE-400 1 PoC

Mattermost versions 8.1.x <= 8.1.10, 9.6.x <= 9.6.0, 9.5.x <= 9.5.2 and 8.1.x <= 8.1.11 fail to limit the size of a request path that includes user inputs which allows an attacker to cause excessive resource consumption, possibly leading to a DoS via sending large request paths

CVE-2024-47145
Mattermost General
3.1
LOW
EPSS
0.3%
2024 CWE-284 1 PoC

Mattermost versions 9.5.x <= 9.5.8 fail to properly authorize access to archived channels when viewing archived channels is disabled, which allows an attacker to view posts and files of archived channels via file links.