6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-14032
Twitch Studio General
8.5
HIGH
EPSS
0.0%
2024 CWE-862 2 PoCs

Twitch Studio version 0.114.8 and prior contain a privilege escalation vulnerability in its privileged helper tool that allows local attackers to execute arbitrary code as root by exploiting an unprotected XPC service. Attackers can invoke the installFromPath:toPath:withReply: method to overwrite system files and privileged binaries, achieving full system compromise. Twitch Studio was discontinued in May 2024.

CVE-2024-27191
Slivery Extender General
8.5
HIGH
EPSS
1.0%
2024 CWE-94 1 PoC

Improper Control of Generation of Code ('Code Injection') vulnerability in inpersttion Slivery Extender slivery-extender allows Remote Code Inclusion.This issue affects Slivery Extender: from n/a through <= 1.0.2.

CVE-2024-32502
Software Genérico General
8.4
HIGH
EPSS
0.1%
2024 1 PoC

An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 850, Exynos 1080, Exynos 2100, Exynos 1280, Exynos 1380, Exynos 1330, Exynos W920, Exynos W930. The mobile processor lacks proper reference count checking, which can result in a UAF (Use-After-Free) vulnerability.

CVE-2024-25817
Software Genérico General
8.4
HIGH
EPSS
0.1%
2024 1 PoC

Buffer Overflow vulnerability in eza before version 0.18.2, allows local attackers to execute arbitrary code via the .git/HEAD, .git/refs, and .git/objects components.

CVE-2024-36474
G Structured File Library (libgsf) General
8.4
HIGH
EPSS
0.1%
2024 CWE-190 2 PoCs

An integer overflow vulnerability exists in the Compound Document Binary File format parser of the GNOME Project G Structured File Library (libgsf) version v1.14.52. A specially crafted file can result in an integer overflow when processing the directory from the file that allows for an out-of-bounds index to be used when reading and writing to an array. This can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2024-48123
Software Genérico General
8.4
HIGH
EPSS
0.1%
2024 1 PoC

An issue in the USB Autorun function of HI-SCAN 6040i Hitrax HX-03-19-I allows attackers to execute arbitrary code via uploading a crafted script from a USB device.

CVE-2024-32229
Software Genérico General
8.4
HIGH
EPSS
0.2%
2024 1 PoC

FFmpeg 7.0 contains a heap-buffer-overflow at libavfilter/vf_tiltandshift.c:189:5 in copy_column.

CVE-2024-35142
Security Verify Access Docker DevOps
8.4
HIGH
EPSS
0.0%
2024 CWE-250 1 PoC

IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to execution of unnecessary privileges. IBM X-Force ID: 292418.

CVE-2024-55211
Software Genérico Networking
8.4
HIGH
EPSS
0.1%
2024 1 PoC

An issue in Think Router Tk-Rt-Wr135G V3.0.2-X000 allows attackers to bypass authentication via a crafted cookie.

CVE-2024-40821
macOS General
8.4
HIGH
EPSS
0.0%
2024 2 PoCs

An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. Third party app extensions may not receive the correct sandbox restrictions.

CVE-2024-6769
Windows 10 Windows
8.4
HIGH
EPSS
16.0%
2024 CWE-426 1 PoC

A DLL Hijacking caused by drive remapping combined with a poisoning of the activation cache in Microsoft Windows 10, Windows 11, Windows Server 2016, Windows Server 2019, and Windows Server 2022 allows a malicious authenticated attacker to elevate from a medium integrity process to a high integrity process without the intervention of a UAC prompt.

CVE-2024-2608
Firefox General
8.4
HIGH
EPSS
0.2%
2024 1 PoC

`AppendEncodedAttributeValue(), ExtraSpaceNeededForAttrEncoding()` and `AppendEncodedCharacters()` could have experienced integer overflows, causing underallocation of an output buffer leading to an out of bounds write. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

CVE-2024-20812
Samsung Mobile Devices General
8.4
HIGH
EPSS
0.0%
2024 1 PoC

Out-of-bounds Write in padmd_vld_htbl of libpadm.so prior to SMR Feb-2024 Release 1 allows local attacker to execute arbitrary code.

CVE-2024-51379
Software Genérico Web
8.4
HIGH
EPSS
0.1%
2024 1 PoC

Stored Cross-Site Scripting (XSS) vulnerability discovered in JATOS v3.9.3. The vulnerability exists in the description component of the study section, where an attacker can inject JavaScript into the description field. This allows for the execution of malicious scripts when an admin views the description, potentially leading to account takeover and unauthorized actions.

CVE-2024-47921
SPS General
8.4
HIGH
EPSS
0.0%
2024 CWE-327 1 PoC

Smadar SPS – CWE-327: Use of a Broken or Risky Cryptographic Algorithm

CVE-2024-29050
Windows 10 Version 1809 Windows
8.4
HIGH
EPSS
38.3%
2024 CWE-197 1 PoC

Windows Cryptographic Services Remote Code Execution Vulnerability

CVE-2024-20053
MT2713, MT2737, MT6781, MT6789, MT6835, MT6855, MT6879, MT6880, MT6886, MT6890, MT6895, MT6980, MT6983, MT6985, MT6989, MT6990, MT8167, MT8168, MT8173, MT8175, MT8188, MT8195, MT8321, MT8362A, MT8365, MT8385, MT8390, MT8395, MT8666, MT8667, MT8673, MT8765, MT8766, MT8768, MT8781, MT8786, MT8788, MT8789, MT8791, MT8791T, MT8796, MT8797, MT8798 General
8.4
HIGH
EPSS
0.0%
2024 1 PoC

In flashc, there is a possible out of bounds write due to an uncaught exception. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541757; Issue ID: ALPS08541764.

CVE-2024-31319
Android General
8.4
HIGH
EPSS
0.0%
2024 2 PoCs

In updateNotificationChannelFromPrivilegedListener of NotificationManagerService.java, there is a possible cross-user data leak due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2024-42415
G Structured File Library (libgsf) General
8.4
HIGH
EPSS
0.1%
2024 CWE-190 2 PoCs

An integer overflow vulnerability exists in the Compound Document Binary File format parser of v1.14.52 of the GNOME Project G Structured File Library (libgsf). A specially crafted file can result in an integer overflow that allows for a heap-based buffer overflow when processing the sector allocation table. This can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2024-32504
Software Genérico General
8.4
HIGH
EPSS
0.2%
2024 1 PoC

An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 850, Exynos 1080, Exynos 2100, Exynos 1280, Exynos 1380, Exynos 1330, Exynos W920, Exynos W930. The mobile processor lacks proper length checking, which can result in an OOB (Out-of-Bounds) Write vulnerability.