3333 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-12786
Adobe Downloader General
8.5
HIGH
EPSS
0.1%
2024 CWE-269 1 PoC

A vulnerability, which was classified as critical, was found in X1a0He Adobe Downloader up to 1.3.1 on macOS. Affected is the function shouldAcceptNewConnection of the file com.x1a0he.macOS.Adobe-Downloader.helper of the component XPC Service. The manipulation leads to improper privilege management. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. This product is not affiliated with the company Adobe.

CVE-2024-45752
Software Genérico General
8.5
HIGH
EPSS
0.0%
2024 1 PoC

logiops through 0.3.4, in its default configuration, allows any unprivileged user to configure its logid daemon via an unrestricted D-Bus service, including setting malicious keyboard macros. This allows for privilege escalation with minimal user interaction.

CVE-2024-9054
TimeProvider 4100 General
8.5
HIGH
EPSS
32.6%
2024 CWE-78 1 PoC

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Microchip TimeProvider 4100 (Configuration modules) allows Command Injection.This issue affects TimeProvider 4100: from 1.0 before 2.4.7.

CVE-2024-58315
Tosibox Key Service General
8.5
HIGH
EPSS
0.0%
2024 CWE-428 1 PoC

Tosibox Key Service 3.3.0 contains an unquoted service path vulnerability that allows local non-privileged users to potentially execute code with elevated system privileges. Attackers can exploit the service startup process by inserting malicious code in the system root path, enabling unauthorized code execution during application startup or system reboot.

CVE-2024-14032
Twitch Studio General
8.5
HIGH
EPSS
0.0%
2024 CWE-862 2 PoCs

Twitch Studio version 0.114.8 and prior contain a privilege escalation vulnerability in its privileged helper tool that allows local attackers to execute arbitrary code as root by exploiting an unprotected XPC service. Attackers can invoke the installFromPath:toPath:withReply: method to overwrite system files and privileged binaries, achieving full system compromise. Twitch Studio was discontinued in May 2024.

CVE-2024-58278
perl2exe General
8.5
HIGH
EPSS
0.0%
2024 CWE-78 1 PoC

perl2exe <= V30.10C contains an arbitrary code execution vulnerability that allows local authenticated attackers to execute malicious scripts. Attackers can control the 0th argument of packed executables to execute another executable, allowing them to bypass restrictions and gain unauthorized access.

CVE-2024-10093
ConvertXtoDvd General
8.5
HIGH
EPSS
0.1%
2024 CWE-427 1 PoC

A vulnerability, which was classified as critical, was found in VSO ConvertXtoDvd 7.0.0.83. Affected is an unknown function in the library avcodec.dll of the file ConvertXtoDvd.exe. The manipulation leads to uncontrolled search path. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CVE-2024-44067
Software Genérico General
8.4
HIGH
EPSS
0.0%
2024 1 PoC

The T-Head XuanTie C910 CPU in the TH1520 SoC and the T-Head XuanTie C920 CPU in the SOPHON SG2042 have instructions that allow unprivileged attackers to write to arbitrary physical memory locations, aka GhostWrite.

CVE-2024-42415
G Structured File Library (libgsf) General
8.4
HIGH
EPSS
0.1%
2024 CWE-190 2 PoCs

An integer overflow vulnerability exists in the Compound Document Binary File format parser of v1.14.52 of the GNOME Project G Structured File Library (libgsf). A specially crafted file can result in an integer overflow that allows for a heap-based buffer overflow when processing the sector allocation table. This can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2024-35333
Software Genérico General
8.4
HIGH
EPSS
0.2%
2024 1 PoC

A stack-buffer-overflow vulnerability exists in the read_charset_decl function of html2xhtml 1.3. This vulnerability occurs due to improper bounds checking when copying data into a fixed-size stack buffer. An attacker can exploit this vulnerability by providing a specially crafted input to the vulnerable function, causing a buffer overflow and potentially leading to arbitrary code execution, denial of service, or data corruption.

CVE-2024-40800
macOS General
8.4
HIGH
EPSS
0.0%
2024 3 PoCs

An input validation issue was addressed with improved input validation. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. An app may be able to modify protected parts of the file system.

CVE-2024-34329
Software Genérico General
8.4
HIGH
EPSS
8.0%
2024 2 PoCs

Insecure permissions in Entrust Datacard XPS Card Printer Driver 8.5 and earlier without the dxp1-patch-E24-004 patch allows unauthenticated attackers to execute arbitrary code as SYSTEM via a crafted DLL payload.

CVE-2024-41605
Software Genérico General
8.4
HIGH
EPSS
0.0%
2024 1 PoC

In Foxit PDF Reader before 2024.3, and PDF Editor before 2024.3 and 13.x before 13.1.4, an attacker can replace an update file with a Trojan horse via side loading, because the update service lacks integrity validation for the updater. Attacker-controlled code may thus be executed.

CVE-2024-43087
Android General
8.4
HIGH
EPSS
0.1%
2024 1 PoC

In getInstalledAccessibilityPreferences of AccessibilitySettings.java, there is a possible way to hide an enabled accessibility service in the accessibility service settings due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.

CVE-2024-40821
macOS General
8.4
HIGH
EPSS
0.0%
2024 2 PoCs

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. Third party app extensions may not receive the correct sandbox restrictions.

CVE-2024-32502
Software Genérico General
8.4
HIGH
EPSS
0.1%
2024 1 PoC

An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 850, Exynos 1080, Exynos 2100, Exynos 1280, Exynos 1380, Exynos 1330, Exynos W920, Exynos W930. The mobile processor lacks proper reference count checking, which can result in a UAF (Use-After-Free) vulnerability.

CVE-2024-28146
Scan2Net General
8.4
HIGH
EPSS
0.1%
2024 CWE-798 2 PoCs

The application uses several hard-coded credentials to encrypt config files during backup, to decrypt the new firmware during an update and some passwords allow a direct connection to the database server of the affected device.

CVE-2024-6473
Browser General
8.4
HIGH
EPSS
3.1%
2024 CWE-426 1 PoC

Yandex Browser for Desktop before 24.7.1.380 has a DLL Hijacking Vulnerability because an untrusted search path is used.

CVE-2024-47921
SPS General
8.4
HIGH
EPSS
0.0%
2024 CWE-327 1 PoC

Smadar SPS – CWE-327: Use of a Broken or Risky Cryptographic Algorithm

CVE-2024-20812
Samsung Mobile Devices General
8.4
HIGH
EPSS
0.0%
2024 1 PoC

Out-of-bounds Write in padmd_vld_htbl of libpadm.so prior to SMR Feb-2024 Release 1 allows local attacker to execute arbitrary code.