3333 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-3157
Chrome General
8.1
HIGH
EPSS
0.7%
2024 1 PoC

Out of bounds memory access in Compositing in Google Chrome prior to 123.0.6312.122 allowed a remote attacker who had compromised the GPU process to potentially perform a sandbox escape via specific UI gestures. (Chromium security severity: High)

CVE-2024-51329
Software Genérico General
8.1
HIGH
EPSS
0.2%
2024 1 PoC

A Host header injection vulnerability in Agile-Board 1.0 allows attackers to obtain the password reset token via user interaction with a crafted password reset link.

CVE-2024-52867
Software Genérico General
8.1
HIGH
EPSS
0.0%
2024 1 PoC

guix-daemon in GNU Guix before 5ab3c4c allows privilege escalation because build outputs are accessible by local users before file metadata concerns (e.g., for setuid and setgid programs) are properly addressed. The vulnerability can be remediated within the product via certain pull, reconfigure, and restart actions. Both 5ab3c4c and 5582241 are needed to resolve the vulnerability.

CVE-2024-58101
Software Genérico General
8.1
HIGH
EPSS
0.1%
2024 1 PoC

Samsung Galaxy Buds and Galaxy Buds 2 audio devices are Bluetooth pairable by default without user input nor a way to stop this mode. As a consequence, audio playback takeover or even microphone recording without user consent or notification is achieved. Note: This is considered a low severity vulnerability by the vendor.

CVE-2024-42040
Software Genérico General
8.1
HIGH
EPSS
0.1%
2024 1 PoC

Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from its initial commit in 2002 (3861aa5) up to today on any platform allows an attacker on the local network to leak memory from four up to 32 bytes of memory stored behind the packet to the network depending on the later use of DHCP-provided parameters via crafted DHCP responses.

CVE-2024-36886
Linux General
8.1
HIGH
EPSS
0.3%
2024 9 PoCs

In the Linux kernel, the following vulnerability has been resolved: tipc: fix UAF in error path Sam Page (sam4k) working with Trend Micro Zero Day Initiative reported a UAF in the tipc_buf_append() error path: BUG: KASAN: slab-use-after-free in kfree_skb_list_reason+0x47e/0x4c0 linux/net/core/skbuff.c:1183 Read of size 8 at addr ffff88804d2a7c80 by task poc/8034 CPU: 1 PID: 8034 Comm: poc Not tainted 6.8.2 #1 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.16.0-debian-1.16.0-5 04/01/2014 Call Trace: <IRQ> __dump_stack linux/lib/dump_stack.c:88 dump_stack_lvl+0xd9/0x1b0 lin

CVE-2024-41967
CC100 0751-9x01 General
8.1
HIGH
EPSS
1.3%
2024 CWE-306 1 PoC

A low privileged remote attacker may modify the boot mode configuration setup of the device, leading to modification of the firmware upgrade process or a denial-of-service attack.

CVE-2024-35430
Software Genérico General
8.1
HIGH
EPSS
0.1%
2024 1 PoC

In ZKTeco ZKBio CVSecurity v6.1.1_R and earlier (fixed in 6.1.3_R) an authenticated user can bypass password checks while exporting data from the application.

CVE-2024-41971
CC100 0751-9x01 General
8.1
HIGH
EPSS
1.8%
2024 CWE-22 1 PoC

A low privileged remote attacker can overwrite an arbitrary file on the filesystem leading to a DoS and data loss.

CVE-2024-34391
Software Genérico General
8.1
HIGH
EPSS
3.2%
2024 CWE-843 1 PoC

libxmljs is vulnerable to a type confusion vulnerability when parsing a specially crafted XML while invoking a function on the result of attrs() that was called on a parsed node. This vulnerability might lead to denial of service (on both 32-bit systems and 64-bit systems), data leak, infinite loop and remote code execution (on 32-bit systems with the XML_PARSE_HUGE flag enabled).

CVE-2024-35433
Software Genérico General
8.1
HIGH
EPSS
0.1%
2024 1 PoC

ZKTeco ZKBio CVSecurity 6.1.1 is vulnerable to Incorrect Access Control. An authenticated user, without the permissions of managing users, can create a new admin user.

CVE-2024-28114
peering-manager General
8.1
HIGH
EPSS
0.4%
2024 CWE-74 1 PoC

Peering Manager is a BGP session management tool. There is a Server Side Template Injection vulnerability that leads to Remote Code Execution in Peering Manager <=1.8.2. As a result arbitrary commands can be executed on the operating system that is running Peering Manager. This issue has been addressed in version 1.8.3. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVE-2024-36789
Software Genérico General
8.1
HIGH
EPSS
0.1%
2024 1 PoC

An issue in Netgear WNR614 JNR1010V2/N300-V1.1.0.54_1.0.1 allows attackers to create passwords that do not conform to defined security standards.

CVE-2024-46097
Software Genérico General
8.1
HIGH
EPSS
0.1%
2024 1 PoC

TestLink 1.9.20 is vulnerable to Incorrect Access Control in the TestPlan editing section. When a new TestPlan is created, an ID with an incremental value is automatically generated. Using the edit function you can change the tplan_id parameter to another ID. The application does not carry out a check on the user's permissions maing it possible to recover the IDs of all the TestPlans (even the administrative ones) and modify them even with minimal privileges.

CVE-2024-2887
Chrome General
8.1
HIGH
EPSS
12.2%
2024 3 PoCs

Type Confusion in WebAssembly in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

CVE-2024-24794
libdicom General
8.1
HIGH
EPSS
0.5%
2024 CWE-416 2 PoCs

A use-after-free vulnerability exists in the DICOM Element Parsing as implemented in Imaging Data Commons libdicom 1.0.5. A specially crafted DICOM file can cause premature freeing of memory that is used later. To trigger this vulnerability, an attacker would need to induce the vulnerable application to process a malicious DICOM image.The Use-After-Free happens in the `parse_meta_sequence_end()` parsing the Sequence Value Represenations.

CVE-2024-36444
Software Genérico General
8.1
HIGH
EPSS
0.1%
2024 2 PoCs

cgi-bin/fdmcgiwebv2.cgi on Swissphone DiCal-RED 4009 devices allows an unauthenticated attacker to gain access to device logs.

CVE-2024-39583
PowerScale InsightIQ General
8.1
HIGH
EPSS
0.3%
2024 CWE-327 1 PoC

Dell PowerScale InsightIQ, versions 5.0 through 5.1, contains a Use of a Broken or Risky Cryptographic Algorithm vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges.

CVE-2024-27876
iOS and iPadOS General
8.1
HIGH
EPSS
0.0%
2024 1 PoC

A race condition was addressed with improved locking. This issue is fixed in iOS 17.7 and iPadOS 17.7, iOS 18 and iPadOS 18, macOS Sequoia 15, macOS Sonoma 14.7, macOS Ventura 13.7, visionOS 2. Unpacking a maliciously crafted archive may allow an attacker to write arbitrary files.

CVE-2024-5138
snapd General
8.1
HIGH
EPSS
0.6%
2024 1 PoC

The snapctl component within snapd allows a confined snap to interact with the snapd daemon to take certain privileged actions on behalf of the snap. It was found that snapctl did not properly parse command-line arguments, allowing an unprivileged user to trigger an authorised action on behalf of the snap that would normally require administrator privileges to perform. This could possibly allow an unprivileged user to perform a denial of service or similar.