6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-27386
Software Genérico General
6.7
MEDIUM
EPSS
0.1%
2024 2 PoCs

A vulnerability was discovered in the slsi_handle_nan_rx_event_log_ind function in Samsung Mobile Processor Exynos 1380 and Exynos 1480 related to no input validation check on tag_len for tx coming from userspace, which can lead to heap overwrite.

CVE-2024-31953
Software Genérico General
6.7
MEDIUM
EPSS
0.2%
2024 1 PoC

An issue was discovered in Samsung Magician 8.0.0 on macOS. Because it is possible to tamper with the directory and executable files used during the installation process, an attacker can escalate privileges through arbitrary code execution. (The attacker must already have user privileges, and an administrator password must be entered during the program installation stage for privilege escalation.)

CVE-2024-12426
LibreOffice General
6.7
MEDIUM
EPSS
0.5%
2024 CWE-200 1 PoC

Exposure of Environmental Variables and arbitrary INI file values to an Unauthorized Actor vulnerability in The Document Foundation LibreOffice. URLs could be constructed which expanded environmental variables or INI file values, so potentially sensitive information could be exfiltrated to a remote server on opening a document containing such links. This issue affects LibreOffice: from 24.8 before < 24.8.4.

CVE-2024-31952
Software Genérico General
6.7
MEDIUM
EPSS
0.1%
2024 1 PoC

An issue was discovered in Samsung Magician 8.0.0 on macOS. Because symlinks are used during the installation process, an attacker can escalate privileges via arbitrary file permission writes. (The attacker must already have user privileges, and an administrator password must be entered during the program installation stage for privilege escalation.)

CVE-2024-48122
Software Genérico General
6.7
MEDIUM
EPSS
0.1%
2024 1 PoC

Insecure default configurations in HI-SCAN 6040i Hitrax HX-03-19-I allow authenticated attackers with low-level privileges to escalate to root-level privileges.

CVE-2024-1395
Arm 5th Gen GPU Architecture Kernel Driver General
6.7
MEDIUM
EPSS
0.1%
2024 CWE-416 1 PoC

Use After Free vulnerability in Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations. If the system’s memory is carefully prepared by the user, then this in turn could give them access to already freed memory. This issue affects Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r47p0.

CVE-2024-38433
NPCM7xx (Poleg) BootBlock General
6.7
MEDIUM
EPSS
0.0%
2024 CWE-305 1 PoC

Nuvoton - CWE-305: Authentication Bypass by Primary Weakness An attacker with write access to the SPI-Flash on an NPCM7xx BMC subsystem that uses the Nuvoton BootBlock reference code can modify the u-boot image header on flash parsed by the BootBlock which could lead to arbitrary code execution.

CVE-2024-27460
Plantronics Hub General
6.7
MEDIUM
EPSS
2.5%
2024 3 PoCs

A privilege escalation exists in the updater for Plantronics Hub 3.25.1 and below.

CVE-2024-22026
EPMM General
6.7
MEDIUM
EPSS
0.2%
2024 1 PoC

A local privilege escalation vulnerability in EPMM before 12.1.0.0 allows an authenticated local user to bypass shell restriction and execute arbitrary commands on the appliance.

CVE-2024-27146
Toshiba Tec e-Studio multi-function peripheral (MFP) General
6.7
MEDIUM
EPSS
0.1%
2024 CWE-250 1 PoC

The Toshiba printers do not implement privileges separation. As for the affected products/models/versions, see the reference URL.

CVE-2024-35976
Linux General
6.7
MEDIUM
EPSS
0.0%
2024 2 PoCs

In the Linux kernel, the following vulnerability has been resolved: xsk: validate user input for XDP_{UMEM|COMPLETION}_FILL_RING syzbot reported an illegal copy in xsk_setsockopt() [1] Make sure to validate setsockopt() @optlen parameter. [1] BUG: KASAN: slab-out-of-bounds in copy_from_sockptr_offset include/linux/sockptr.h:49 [inline] BUG: KASAN: slab-out-of-bounds in copy_from_sockptr include/linux/sockptr.h:55 [inline] BUG: KASAN: slab-out-of-bounds in xsk_setsockopt+0x909/0xa40 net/xdp/xsk.c:1420 Read of size 4 at addr ffff888028c6cde3 by task syz-executor.0/7549 CPU: 0 PID: 7549

CVE-2024-20819
Samsung Mobile Devices General
6.6
MEDIUM
EPSS
0.1%
2024 1 PoC

Out-of-bounds Write vulnerabilities in svc1td_vld_plh_ap of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overflow.

CVE-2024-41629
Software Genérico General
6.6
MEDIUM
EPSS
0.0%
2024 2 PoCs

An issue in Texas Instruments Fusion Digital Power Designer v.7.10.1 allows a local attacker to obtain sensitive information via the plaintext storage of credentials

CVE-2024-21519
opencart/opencart Web
6.6
MEDIUM
EPSS
0.3%
2024 CWE-20 1 PoC

This affects versions of the package opencart/opencart from 4.0.0.0. An Arbitrary File Creation issue was identified via the database restoration functionality. By injecting PHP code into the database, an attacker with admin privileges can create a backup file with an arbitrary filename (including the extension), within /system/storage/backup. **Note:** It is less likely for the created file to be available within the web root, as part of the security recommendations for the application suggest moving the storage path outside of the web root.

CVE-2024-41958
mailcow-dockerized DevOps
6.6
MEDIUM
EPSS
30.3%
2024 CWE-697 1 PoC

mailcow: dockerized is an open source groupware/email suite based on docker. A vulnerability has been discovered in the two-factor authentication (2FA) mechanism. This flaw allows an authenticated attacker to bypass the 2FA protection, enabling unauthorized access to other accounts that are otherwise secured with 2FA. To exploit this vulnerability, the attacker must first have access to an account within the system and possess the credentials of the target account that has 2FA enabled. By leveraging these credentials, the attacker can circumvent the 2FA process and gain access to the protected

CVE-2024-20818
Samsung Mobile Devices General
6.6
MEDIUM
EPSS
0.1%
2024 1 PoC

Out-of-bounds Write vulnerabilities in svc1td_vld_elh of libsthmbc.so prior to SMR Feb-2024 Release 1 allows local attackers to trigger buffer overflow.

CVE-2024-20044
MT6739, MT6757, MT6761, MT6763, MT6765, MT6768, MT6771, MT6779, MT6781, MT6785, MT6833, MT6853, MT6873, MT6877, MT6885, MT6893, MT8167, MT8168, MT8173, MT8175, MT8185, MT8195, MT8321, MT8362A, MT8365, MT8385, MT8395, MT8666, MT8673, MT8678, MT8765, MT8766, MT8768, MT8781, MT8786, MT8788, MT8789, MT8791, MT8791T, MT8796, MT8797, MT8798 General
6.6
MEDIUM
EPSS
0.0%
2024 1 PoC

In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541784; Issue ID: ALPS08541784.

CVE-2024-27282
Software Genérico General
6.6
MEDIUM
EPSS
0.6%
2024 1 PoC

An issue was discovered in Ruby 3.x through 3.3.0. If attacker-supplied data is provided to the Ruby regex compiler, it is possible to extract arbitrary heap data relative to the start of the text, including pointers and sensitive strings. The fixed versions are 3.0.7, 3.1.5, 3.2.4, and 3.3.1.

CVE-2024-56264
ACF City Selector General
6.6
MEDIUM
EPSS
13.8%
2024 CWE-434 2 PoCs

Unrestricted Upload of File with Dangerous Type vulnerability in Beee ACF City Selector acf-city-selector allows Upload a Web Shell to a Web Server.This issue affects ACF City Selector: from n/a through <= 1.14.0.

CVE-2024-32228
Software Genérico General
6.6
MEDIUM
EPSS
0.4%
2024 1 PoC

FFmpeg 7.0 is vulnerable to Buffer Overflow. There is a SEGV at libavcodec/hevcdec.c:2947:22 in hevc_frame_end.