6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-23208
iOS and iPadOS General
7.8
HIGH
EPSS
3.2%
2024 1 PoC

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS 10.3. An app may be able to execute arbitrary code with kernel privileges.

CVE-2024-12194
Navisworks Freedom General
7.8
HIGH
EPSS
0.5%
2024 CWE-120 1 PoC

A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

CVE-2024-43097
Android General
7.8
HIGH
EPSS
0.9%
2024 1 PoC

In resizeToAtLeast of SkRegion.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2024-21111
VM VirtualBox Database Windows
7.8
HIGH
EPSS
11.1%
2024 5 PoCs

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.16. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. Note: This vulnerability applies to Windows hosts only. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I

CVE-2024-23144
AutoCAD Windows
7.8
HIGH
EPSS
0.4%
2024 CWE-787 1 PoC

A maliciously crafted CATPART file, when parsed in CC5Dll.dll and ASMBASE228A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

CVE-2024-23122
AutoCAD General
7.8
HIGH
EPSS
0.4%
2024 CWE-787 2 PoCs

A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

CVE-2024-12837
Graphics DDK General
7.8
HIGH
EPSS
0.2%
2024 CWE-416 1 PoC

Software installed and run as a non-privileged user may conduct improper GPU system calls to corrupt kernel heap memory.

CVE-2024-25004
Software Genérico General
7.8
HIGH
EPSS
0.6%
2024 4 PoCs

KiTTY versions 0.76.1.13 and before is vulnerable to a stack-based buffer overflow via the username, occurs due to insufficient bounds checking and input sanitization (at line 2600). This allows an attacker to overwrite adjacent memory, which leads to arbitrary code execution.

CVE-2024-22545
Software Genérico General
7.8
HIGH
EPSS
0.1%
2024 1 PoC

An issue was discovered in TRENDnet TEW-824DRU version 1.04b01, allows unauthenticated attackers to execute arbitrary code via the system.ntp.server parameter in the sub_420AE0() function. The attack can be launched remotely.

CVE-2024-40662
Android General
7.8
HIGH
EPSS
0.1%
2024 2 PoCs

In scheme of Uri.java, there is a possible way to craft a malformed Uri object due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2024-30371
PDF Reader General
7.8
HIGH
EPSS
2.2%
2024 CWE-416 1 PoC

Foxit PDF Reader AcroForm Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of AcroForms. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current proce

CVE-2024-9248
PDF Reader General
7.8
HIGH
EPSS
1.3%
2024 CWE-787 1 PoC

Foxit PDF Reader PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code

CVE-2024-43705
Graphics DDK General
7.8
HIGH
EPSS
0.0%
2024 CWE-280 1 PoC

Software installed and run as a non-privileged user can trigger the GPU kernel driver to write to arbitrary read-only system files that have been mapped into application memory.

CVE-2024-35141
Security Verify Access Docker DevOps
7.8
HIGH
EPSS
0.0%
2024 CWE-250 1 PoC

IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to execution of unnecessary privileges.

CVE-2024-9244
PDF Reader General
7.8
HIGH
EPSS
0.0%
2024 CWE-732 1 PoC

Foxit PDF Reader Update Service Incorrect Permission Assignment Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PDF Reader. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of the configuration files used by the Foxit Reader Update Service. The issue results from incorrect permissions set on a resource used by the service. An attacker can leverage this vulnerability to esc

CVE-2024-9956
Chrome General
7.8
HIGH
EPSS
0.0%
2024 1 PoC

Inappropriate implementation in WebAuthentication in Google Chrome on Android prior to 130.0.6723.58 allowed a local attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)

CVE-2024-13759
Prime Windows
7.8
HIGH
EPSS
0.1%
2024 CWE-59 1 PoC

Local Privilege Escalation in Avira.Spotlight.Service.exe in Avira Prime 1.1.96.2 on Windows 10 x64  allows local attackers to gain system-level privileges via arbitrary file deletion

CVE-2024-23131
AutoCAD General
7.8
HIGH
EPSS
0.3%
2024 CWE-119 2 PoCs

A maliciously crafted STP file, when parsed in ASMIMPORT229A.dll, ASMKERN228A.dll, ASMkern229A.dll or ASMDATAX228A.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.

CVE-2024-24686
libigl General
7.8
HIGH
EPSS
9.0%
2024 CWE-121 2 PoCs

Multiple stack-based buffer overflow vulnerabilities exist in the readOFF functionality of libigl v2.5.0. A specially crafted .off file can lead to stack-based buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.This vulnerability concerns the parsing of comments within the faces section of an `.off` file processed via the `readOFF` function.

CVE-2024-50591
Elefant Software Updater Windows
7.8
HIGH
EPSS
0.4%
2024 CWE-77 2 PoCs

An attacker with local access the to medical office computer can escalate his Windows user privileges to "NT AUTHORITY\SYSTEM" by exploiting a command injection vulnerability in the Elefant Update Service. The command injection can be exploited by communicating with the Elefant Update Service which is running as "SYSTEM" via Windows Named Pipes.The Elefant Software Updater (ESU) consists of two components. An ESU service which runs as "NT AUTHORITY\SYSTEM" and an ESU tray client which communicates with the service to update or repair the installation and is running with user permission