6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-53869
NVIDIA GPU Display Driver, vGPU software General
5.5
MEDIUM
EPSS
0.0%
2024 CWE-459 1 PoC

NVIDIA Unified Memory driver for Linux contains a vulnerability where an attacker could leak uninitialized memory. A successful exploit of this vulnerability might lead to information disclosure.

CVE-2024-57360
Software Genérico Web
5.5
MEDIUM
EPSS
0.0%
2024 1 PoC

https://www.gnu.org/software/binutils/ nm >=2.43 is affected by: Incorrect Access Control. The type of exploitation is: local. The component is: `nm --without-symbol-version` function.

CVE-2024-0357
Eva Web Database
5.5
MEDIUM
EPSS
0.1%
2024 CWE-89 1 PoC

A vulnerability was found in coderd-repos Eva 1.0.0 and classified as critical. Affected by this issue is some unknown functionality of the file /system/traceLog/page of the component HTTP POST Request Handler. The manipulation of the argument property leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250124.

CVE-2024-2760
Bkav Home General
5.5
MEDIUM
EPSS
0.0%
2024 CWE-404 1 PoC

Bkav Home v7816, build 2403161130 is vulnerable to a Memory Information Leak vulnerability by triggering the 0x222240 IOCTL code of the BkavSDFlt.sys driver.

CVE-2024-34629
Samsung Notes General
5.5
MEDIUM
EPSS
0.2%
2024 1 PoC

Out-of-bounds read in applying binary with text common object in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

CVE-2024-40793
iOS and iPadOS General
5.5
MEDIUM
EPSS
0.0%
2024 4 PoCs

This issue was addressed by removing the vulnerable code. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, watchOS 10.6. An app may be able to access user-sensitive data.

CVE-2024-40823
macOS General
5.5
MEDIUM
EPSS
0.0%
2024 2 PoCs

The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. An app may be able to access user-sensitive data.

CVE-2024-24488
Software Genérico General
5.5
MEDIUM
EPSS
0.0%
2024 1 PoC

An issue in Shenzen Tenda Technology CP3V2.0 V11.10.00.2311090948 allows a local attacker to obtain sensitive information via the password component.

CVE-2024-34624
Samsung Notes General
5.5
MEDIUM
EPSS
0.2%
2024 1 PoC

Out-of-bounds read in applying paragraphs in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

CVE-2024-37877
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2024 1 PoC

UERANSIM before 3.2.6 allows out-of-bounds read when a RLS packet is sent to gNodeB with malformed PDU length. This occurs in function readOctetString in src/utils/octet_view.cpp and in function DecodeRlsMessage in src/lib/rls/rls_pdu.cpp

CVE-2024-0094
vGPU software and Cloud Gaming Cloud
5.5
MEDIUM
EPSS
0.0%
2024 CWE-799 1 PoC

NVIDIA vGPU software for Linux contains a vulnerability in the Virtual GPU Manager, where an untrusted guest VM can cause improper control of the interaction frequency in the host. A successful exploit of this vulnerability might lead to denial of service.

CVE-2024-0344
TimeMail Web Database
5.5
MEDIUM
EPSS
0.1%
2024 CWE-89 1 PoC

A vulnerability, which was classified as critical, has been found in soxft TimeMail up to 1.1. Affected by this issue is some unknown functionality of the file check.php. The manipulation of the argument c leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-250112.

CVE-2024-57784
Software Genérico Web
5.5
MEDIUM
EPSS
14.3%
2024 1 PoC

An issue in the component /php/script_uploads.php of Zenitel AlphaWeb XE v11.2.3.10 allows attackers to execute a directory traversal.

CVE-2024-34631
Samsung Notes General
5.5
MEDIUM
EPSS
0.2%
2024 1 PoC

Out-of-bounds read in applying new binary in Samsung Notes prior to version 4.4.21.62 allows local attackers to potentially read memory.

CVE-2024-40835
iOS and iPadOS General
5.5
MEDIUM
EPSS
0.0%
2024 4 PoCs

A logic issue was addressed with improved checks. This issue is fixed in iOS 16.7.9 and iPadOS 16.7.9, iOS 17.6 and iPadOS 17.6, macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8, watchOS 10.6. A shortcut may be able to use sensitive data with certain actions without prompting the user.

CVE-2024-3048
Bannerlid Web Windows
5.5
MEDIUM
EPSS
0.2%
2024 1 PoC

The Bannerlid WordPress plugin through 1.1.0 does not escape generated URLs before outputting them in attributes, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as administrators

CVE-2024-47102
AIX General
5.5
MEDIUM
EPSS
0.0%
2024 CWE-863 1 PoC

IBM AIX 7.2, 7.3, VIOS 3.1, and 4.1 could allow a non-privileged local user to exploit a vulnerability in the AIX perfstat kernel extension to cause a denial of service.

CVE-2024-31211
wordpress-develop Web Windows
5.5
MEDIUM
EPSS
39.7%
2024 CWE-502 1 PoC

WordPress is an open publishing platform for the Web. Unserialization of instances of the `WP_HTML_Token` class allows for code execution via its `__destruct()` magic method. This issue was fixed in WordPress 6.4.2 on December 6th, 2023. Versions prior to 6.4.0 are not affected.

CVE-2024-0684
Software Genérico General
5.5
MEDIUM
EPSS
0.1%
2024 CWE-122 1 PoC

A flaw was found in the GNU coreutils "split" program. A heap overflow with user-controlled data of multiple hundred bytes in length could occur in the line_bytes_split() function, potentially leading to an application crash and denial of service.

CVE-2024-0030
Android General
5.5
MEDIUM
EPSS
1.5%
2024 1 PoC

In btif_to_bta_response of btif_gatt_util.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.