3333 vulnerabilidades · General Orden: CVSS EPSS Año ID
CVE-2024-47187
suricata General
7.5
HIGH
EPSS
0.1%
2024 CWE-330 1 PoC

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.7, missing initialization of the random seed for "thash" leads to datasets having predictable hash table behavior. This can lead to dataset file loading to use excessive time to load, as well as runtime performance issues during traffic handling. This issue has been addressed in 7.0.7. As a workaround, avoid loading datasets from untrusted sources. Avoid dataset rules that track traffic in rules.

CVE-2024-0040
Android General
7.5
HIGH
EPSS
18.4%
2024 2 PoCs

In setParameter of MtpPacket.cpp, there is a possible out of bounds read due to a heap buffer overflow. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2024-46292
Software Genérico General
7.5
HIGH
EPSS
0.8%
2024 1 PoC

A buffer overflow in modsecurity v3.0.12 allows attackers to cause a Denial of Service (DoS) via a crafted input inserted into the name parameter. NOTE: this is disputed by the Supplier because it cannot be reproduced. Also, the product's documentation indicates that it is not guaranteed to be usable with very large values of SecRequestBodyNoFilesLimit (which are required by the claimed issue).

CVE-2024-4549
DIAEnergie General
7.5
HIGH
EPSS
0.1%
2024 1 PoC

A denial of service vulnerability exists in Delta Electronics DIAEnergie v1.10.1.8610 and prior. When processing an 'ICS Restart!' message, CEBC.exe restarts the system.

CVE-2024-8383
Firefox General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

Firefox normally asks for confirmation before asking the operating system to find an application to handle a scheme that the browser does not support. It did not ask before doing so for the Usenet-related schemes news: and snews:. Since most operating systems don't have a trusted newsreader installed by default, an unscrupulous program that the user downloaded could register itself as a handler. The website that served the application download could then launch that application at will. This vulnerability affects Firefox < 130, Firefox ESR < 128.2, and Firefox ESR < 115.15.

CVE-2024-48142
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 1 PoC

A prompt injection vulnerability in the chatbox of Butterfly Effect Limited Monica ChatGPT AI Assistant v2.4.0 allows attackers to access and exfiltrate all previous and subsequent chat data between the user and the AI assistant via a crafted message.

CVE-2024-23261
macOS General
7.5
HIGH
EPSS
0.3%
2024 1 PoC

A logic issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.4, macOS Ventura 13.6.8. An attacker may be able to read information belonging to another user.

CVE-2024-33605
Multiple MFPs (multifunction printers) General ⚡ nuclei
7.5
HIGH
EPSS
60.2%
2024 CWE-22 3 PoCs

Improper processing of some parameters of installed_emanual_list.html leads to a path traversal vulnerability. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

CVE-2024-53027
Snapdragon General
7.5
HIGH
EPSS
0.3%
2024 CWE-120 1 PoC

Transient DOS may occur while processing the country IE.

CVE-2024-22328
Maximo Application Suite General
7.5
HIGH
EPSS
0.0%
2024 CWE-22 1 PoC

IBM Maximo Application Suite 8.10 and 8.11 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 279950.

CVE-2024-21539
@eslint/plugin-kit General
7.5
HIGH
EPSS
0.2%
2024 CWE-1333 1 PoC

Versions of the package @eslint/plugin-kit before 0.2.3 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by exploiting this vulnerability.

CVE-2024-24426
Software Genérico General
7.5
HIGH
EPSS
0.4%
2024 1 PoC

Reachable assertions in the NGAP_FIND_PROTOCOLIE_BY_ID function of OpenAirInterface Magma v1.8.0 and OAI EPC Federation v1.2.0 allow attackers to cause a Denial of Service (DoS) via a crafted NGAP packet.

CVE-2024-36857
Software Genérico General ⚡ nuclei
7.5
HIGH
EPSS
53.4%
2024 0 PoCs

Jan v0.4.12 was discovered to contain an arbitrary file read vulnerability via the /v1/app/readFileSync interface.

CVE-2024-6960
Software Genérico General
7.5
HIGH
EPSS
0.2%
2024 CWE-502 1 PoC

The H2O machine learning platform uses "Iced" classes as the primary means of moving Java Objects around the cluster. The Iced format supports inclusion of serialized Java objects. When a model is deserialized, any class is allowed to be deserialized (no class whitelist). An attacker can construct a crafted Iced model that uses Java gadgets and leads to arbitrary code execution when imported to the H2O platform.

CVE-2024-40829
iOS and iPadOS General
7.5
HIGH
EPSS
0.4%
2024 3 PoCs

The issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Ventura 13.6.8, watchOS 10.6. An attacker may be able to view restricted content from the lock screen.

CVE-2024-12085
Software Genérico General
7.5
HIGH
EPSS
19.1%
2024 CWE-908 1 PoC

A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time.

CVE-2024-34619
Samsung Mobile Devices General
7.5
HIGH
EPSS
1.5%
2024 1 PoC

Improper input validation in librtp.so prior to SMR Aug-2024 Release 1 allows remote attackers to execute arbitrary code with system privilege. User interaction is required for triggering this vulnerability.

CVE-2024-37880
Software Genérico General
7.5
HIGH
EPSS
0.1%
2024 1 PoC

The Kyber reference implementation before 9b8d306, when compiled by LLVM Clang through 18.x with some common optimization options, has a timing side channel that allows attackers to recover an ML-KEM 512 secret key in minutes. This occurs because poly_frommsg in poly.c does not prevent Clang from emitting a vulnerable secret-dependent branch.

CVE-2024-48953
Software Genérico General
7.5
HIGH
EPSS
0.3%
2024 2 PoCs

An issue was discovered in Logpoint before 7.5.0. Endpoints for creating, editing, or deleting third-party authentication modules lacked proper authorization checks. This allowed unauthenticated users to register their own authentication plugins in Logpoint, resulting in unauthorized access.

CVE-2024-8176
Software Genérico General
7.5
HIGH
EPSS
0.7%
2024 CWE-674 2 PoCs

A stack overflow vulnerability exists in the libexpat library due to the way it handles recursive entity expansion in XML documents. When parsing an XML document with deeply nested entity references, libexpat can be forced to recurse indefinitely, exhausting the stack space and causing a crash. This issue could lead to denial of service (DoS) or, in some cases, exploitable memory corruption, depending on the environment and library usage.