40888 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-42040
Software Genérico General
8.1
HIGH
EPSS
0.1%
2024 1 PoC

Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from its initial commit in 2002 (3861aa5) up to today on any platform allows an attacker on the local network to leak memory from four up to 32 bytes of memory stored behind the packet to the network depending on the later use of DHCP-provided parameters via crafted DHCP responses.

CVE-2022-21938
Metasys ADS/ADX/OAS server General
8.1
HIGH
EPSS
0.4%
2022 CWE-79 1 PoC

Under certain circumstances, a vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 could allow a user to inject malicious code into the MUI Graphics web interface.

CVE-2024-52867
Software Genérico General
8.1
HIGH
EPSS
0.0%
2024 1 PoC

guix-daemon in GNU Guix before 5ab3c4c allows privilege escalation because build outputs are accessible by local users before file metadata concerns (e.g., for setuid and setgid programs) are properly addressed. The vulnerability can be remediated within the product via certain pull, reconfigure, and restart actions. Both 5ab3c4c and 5582241 are needed to resolve the vulnerability.

CVE-2024-24794
libdicom General
8.1
HIGH
EPSS
0.5%
2024 CWE-416 2 PoCs

A use-after-free vulnerability exists in the DICOM Element Parsing as implemented in Imaging Data Commons libdicom 1.0.5. A specially crafted DICOM file can cause premature freeing of memory that is used later. To trigger this vulnerability, an attacker would need to induce the vulnerable application to process a malicious DICOM image.The Use-After-Free happens in the `parse_meta_sequence_end()` parsing the Sequence Value Represenations.

CVE-2022-43607
Open Babel General
8.1
HIGH
EPSS
0.1%
2022 CWE-119 1 PoC

An out-of-bounds write vulnerability exists in the MOL2 format attribute and value functionality of Open Babel 3.1.1 and master commit 530dbfa3. A specially crafted malformed file can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2024-27876
iOS and iPadOS General
8.1
HIGH
EPSS
0.0%
2024 1 PoC

A race condition was addressed with improved locking. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7, visionOS 2. Unpacking a maliciously crafted archive may allow an attacker to write arbitrary files.

CVE-2020-28593
Cosori General
8.1
HIGH
EPSS
2.0%
2020 CWE-912 2 PoCs

A unauthenticated backdoor exists in the configuration server functionality of Cosori Smart 5.8-Quart Air Fryer CS158-AF 1.1.0. A specially crafted JSON object can lead to code execution. An attacker can send a malicious packet to trigger this vulnerability.

CVE-2022-25900
git-clone General
8.1
HIGH
EPSS
4.7%
2022 1 PoC

All versions of package git-clone are vulnerable to Command Injection due to insecure usage of the --upload-pack feature of git.

CVE-2024-44068
Software Genérico General
8.1
HIGH
EPSS
0.7%
2024 2 PoCs

An issue was discovered in the m2m scaler driver in Samsung Mobile Processor and Wearable Processor Exynos 9820, 9825, 980, 990, 850,and W920. A Use-After-Free in the mobile processor leads to privilege escalation.

CVE-2024-41971
CC100 0751-9x01 General
8.1
HIGH
EPSS
1.8%
2024 CWE-22 1 PoC

A low privileged remote attacker can overwrite an arbitrary file on the filesystem leading to a DoS and data loss.

CVE-2024-36598
Software Genérico General
8.1
HIGH
EPSS
0.2%
2024 2 PoCs

An arbitrary file upload vulnerability in Aegon Life v1.0 allows attackers to execute arbitrary code via uploading a crafted image file.

CVE-2022-42272
NVIDIA DGX servers General
8.1
HIGH
EPSS
0.8%
2022 CWE-120 1 PoC

NVIDIA BMC contains a vulnerability in IPMI handler, where an authorized attacker can cause a buffer overflow, which may lead to code execution, denial of service or escalation of privileges.

CVE-2020-10061
zephyr General
8.1
HIGH
EPSS
0.1%
2020 CWE-119 1 PoC

Improper handling of the full-buffer case in the Zephyr Bluetooth implementation can result in memory corruption. This issue affects: zephyrproject-rtos zephyr version 2.2.0 and later versions, and version 1.14.0 and later versions.

CVE-2024-29946
Splunk Enterprise General
8.1
HIGH
EPSS
0.4%
2024 CWE-20 1 PoC

In Splunk Enterprise versions below 9.2.1, 9.1.4, and 9.0.9, the Dashboard Examples Hub lacks protections for risky SPL commands. This could let attackers bypass SPL safeguards for risky commands in the Hub. The vulnerability would require the attacker to phish the victim by tricking them into initiating a request within their browser.

CVE-2024-41973
CC100 0751-9x01 General
8.1
HIGH
EPSS
1.8%
2024 CWE-35 1 PoC

A low privileged remote attacker can specify an arbitrary file on the filesystem which may lead to an arbitrary file writes with root privileges.

CVE-2022-41674
Software Genérico General
8.1
HIGH
EPSS
0.5%
2022 2 PoCs

An issue was discovered in the Linux kernel before 5.19.16. Attackers able to inject WLAN frames could cause a buffer overflow in the ieee80211_bss_info_update function in net/mac80211/scan.c.

CVE-2024-58101
Software Genérico General
8.1
HIGH
EPSS
0.1%
2024 1 PoC

Samsung Galaxy Buds and Galaxy Buds 2 audio devices are Bluetooth pairable by default without user input nor a way to stop this mode. As a consequence, audio playback takeover or even microphone recording without user consent or notification is achieved. Note: This is considered a low severity vulnerability by the vendor.

CVE-2022-1650
eventsource/eventsource General
8.1
HIGH
EPSS
1.5%
2022 CWE-212 1 PoC

Improper Removal of Sensitive Information Before Storage or Transfer in GitHub repository eventsource/eventsource prior to v2.0.2.

CVE-2024-3157
Chrome General
8.1
HIGH
EPSS
0.7%
2024 1 PoC

Out of bounds memory access in Compositing in Google Chrome prior to 123.0.6312.122 allowed a remote attacker who had compromised the GPU process to potentially perform a sandbox escape via specific UI gestures. (Chromium security severity: High)

CVE-2024-22752
Software Genérico General
8.1
HIGH
EPSS
0.6%
2024 1 PoC

Insecure permissions issue in EaseUS MobiMover 6.0.5 Build 21620 allows attackers to gain escalated privileges via use of crafted executable launched from the application installation directory.