3333 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-36241
Mattermost General
3.1
LOW
EPSS
0.4%
2024 CWE-284 1 PoC

Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to enforce proper access controls which allows user to view arbitrary post contents via the /playbook add slash command

CVE-2024-28053
Mattermost General
3.1
LOW
EPSS
0.1%
2024 CWE-400 1 PoC

Resource Exhaustion in Mattermost Server versions 8.1.x before 8.1.10 fails to limit the size of the payload that can be read and parsed allowing an attacker to send a very large email payload and crash the server.

CVE-2024-21848
Mattermost General
3.1
LOW
EPSS
0.2%
2024 CWE-284 1 PoC

Improper Access Control in Mattermost Server versions 8.1.x before 8.1.11 allows an attacker that is in a channel with an active call to keep participating in the call even if they are removed from the channel

CVE-2024-22229
Unity General
3.1
LOW
EPSS
0.2%
2024 CWE-117 1 PoC

Dell Unity, versions prior to 5.4, contain a vulnerability whereby log messages can be spoofed by an authenticated attacker. An attacker could exploit this vulnerability to forge log entries, create false alarms, and inject malicious content into logs that compromise logs integrity. A malicious attacker could also prevent the product from logging information while malicious actions are performed or implicate an arbitrary user for malicious activities.

CVE-2024-0351
Engineers Online Portal General
3.1
LOW
EPSS
0.0%
2024 CWE-384 1 PoC

A vulnerability classified as problematic has been found in SourceCodester Engineers Online Portal 1.0. This affects an unknown part. The manipulation leads to session fixiation. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The exploitability is told to be difficult. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-250119.

CVE-2024-39807
Mattermost General
3.1
LOW
EPSS
0.4%
2024 CWE-200 1 PoC

Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to properly sanitize the recipients of a webhook event which allows an attacker monitoring webhook events to retrieve the channel IDs of archived or restored channels.

CVE-2024-47003
Mattermost General
3.1
LOW
EPSS
0.5%
2024 CWE-400 1 PoC

Mattermost versions 9.11.x <= 9.11.0 and 9.5.x <= 9.5.8 fail to validate that the message of the permalink post is a string, which allows an attacker to send a non-string value as the message of a permalink post and crash the frontend.

CVE-2024-23488
Mattermost General
3.1
LOW
EPSS
0.2%
2024 CWE-284 1 PoC

Mattermost fails to properly restrict the access of files attached to posts in an archived channel, resulting in members being able to access files of archived channels even if the “Allow users to view archived channels” option is disabled.

CVE-2024-3247
Xpdf General
2.9
LOW
EPSS
0.0%
2024 CWE-674 1 PoC

In Xpdf 4.05 (and earlier), a PDF object loop in an object stream leads to infinite recursion and a stack overflow.

CVE-2024-3248
Xpdf General
2.9
LOW
EPSS
0.0%
2024 CWE-674 1 PoC

In Xpdf 4.05 (and earlier), a PDF object loop in the attachments leads to infinite recursion and a stack overflow.

CVE-2024-56430
OpenFHE General
2.9
LOW
EPSS
0.0%
2024 CWE-476 1 PoC

OpenFHE through 1.2.3 has a NULL pointer dereference in BinFHEContext::EvalFloor in lib/binfhe-base-scheme.cpp.

CVE-2024-29210
Phish Alert Button (PAB) for Outlook General
2.8
LOW
EPSS
0.0%
2024 1 PoC

A local privilege escalation (LPE) vulnerability has been identified in Phish Alert Button for Outlook (PAB), specifically within its configuration management functionalities. This vulnerability allows a regular user to modify the application's configuration file to redirect update checks to an arbitrary server, which can then be exploited in conjunction with CVE-2024-29209 to execute arbitrary code with elevated privileges. The issue stems from improper permission settings on the application's configuration file, which is stored in a common directory accessible to all users. This file includ

CVE-2024-23760
Software Genérico General
2.7
LOW
EPSS
0.1%
2024 1 PoC

Cleartext Storage of Sensitive Information in Gambio 4.9.2.0 allows attackers to obtain sensitive information via error-handler.log.json and legacy-error-handler.log.txt under the webroot.

CVE-2024-41926
Mattermost General
2.7
LOW
EPSS
0.2%
2024 CWE-284 1 PoC

Mattermost versions 9.9.x <= 9.9.0 and 9.5.x <= 9.5.6 fail to validate the source of sync messages and only allow the correct remote IDs, which allows a malicious remote to set arbitrary RemoteId values for synced users and therefore claim that a user was synced from another remote.

CVE-2024-29977
Mattermost General
2.7
LOW
EPSS
0.2%
2024 CWE-284 1 PoC

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly validate synced reactions, when shared channels are enabled, which allows a malicious remote to create arbitrary reactions on arbitrary posts

CVE-2024-36257
Mattermost General
2.7
LOW
EPSS
0.1%
2024 CWE-284 1 PoC

Mattermost versions 9.5.x <= 9.5.5 and 9.8.0, when using shared channels with multiple remote servers connected, fail to check that the remote server A requesting the server B to update the profile picture of a user is the remote that actually has the user as a local one . This allows a malicious remote A to change the profile images of users that belong to another remote server C that is connected to the server A.

CVE-2024-23600
PingIDM General
2.7
LOW
EPSS
0.4%
2024 CWE-20 1 PoC

Improper Input Validation of query search results for private field data in PingIDM (Query Filter module) allows for a potentially efficient brute forcing approach leading to information disclosure.

CVE-2024-4235
DG834Gv5 General
2.7
LOW
EPSS
0.1%
2024 CWE-312 1 PoC

A vulnerability classified as problematic was found in Netgear DG834Gv5 1.6.01.34. This vulnerability affects unknown code of the component Web Management Interface. The manipulation leads to cleartext storage of sensitive information. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. VDB-262126 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-39353
Mattermost General
2.7
LOW
EPSS
0.3%
2024 CWE-200 1 PoC

Mattermost versions 9.5.x <= 9.5.5 and 9.8.0 fail to sanitize the RemoteClusterFrame payloads before audit logging them which allows a high privileged attacker with access to the audit logs to read message contents.

CVE-2024-40884
Mattermost General
2.7
LOW
EPSS
0.1%
2024 CWE-284 1 PoC

Mattermost versions 9.5.x <= 9.5.7, 9.10.x <= 9.10.0 fail to properly enforce permissions which allows a team admin user without "Add Team Members" permission to disable the invite URL.