6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-40828
macOS General
8.4
HIGH
EPSS
0.0%
2024 2 PoCs

The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.7.6, macOS Sonoma 14.6, macOS Ventura 13.6.8. A malicious app may be able to gain root privileges.

CVE-2024-42415
G Structured File Library (libgsf) General
8.4
HIGH
EPSS
0.1%
2024 CWE-190 2 PoCs

An integer overflow vulnerability exists in the Compound Document Binary File format parser of v1.14.52 of the GNOME Project G Structured File Library (libgsf). A specially crafted file can result in an integer overflow that allows for a heap-based buffer overflow when processing the sector allocation table. This can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2024-20813
Samsung Mobile Devices General
8.4
HIGH
EPSS
0.1%
2024 1 PoC

Out-of-bounds Write in padmd_vld_qtbl of libpadm.so prior to SMR Feb-2024 Release 1 allows local attacker to execute arbitrary code.

CVE-2024-28143
Scan2Net Web
8.4
HIGH
EPSS
0.1%
2024 CWE-620 2 PoCs

The password change function at /cgi/admin.cgi does not require the current/old password, which makes the application vulnerable to account takeover. An attacker can use this to forcefully set a new password within the -rsetpass+-aaction+- parameter for a user without knowing the old password, e.g. by exploiting a CSRF issue.

CVE-2024-36600
Software Genérico General
8.4
HIGH
EPSS
0.1%
2024 1 PoC

Buffer Overflow Vulnerability in libcdio 2.2.0 (fixed in 2.3.0) allows an attacker to execute arbitrary code via a crafted ISO 9660 image file.

CVE-2024-44067
Software Genérico General
8.4
HIGH
EPSS
0.0%
2024 1 PoC

The T-Head XuanTie C910 CPU in the TH1520 SoC and the T-Head XuanTie C920 CPU in the SOPHON SG2042 have instructions that allow unprivileged attackers to write to arbitrary physical memory locations, aka GhostWrite.

CVE-2024-41309
Software Genérico General
8.4
HIGH
EPSS
0.2%
2024 1 PoC

An issue in the Hardware info module of IT Solutions Enjay CRM OS v1.0 allows attackers to escape the restricted terminal environment and gain root-level privileges on the underlying system.

CVE-2024-38399
Snapdragon General
8.4
HIGH
EPSS
0.1%
2024 CWE-416 1 PoC

Memory corruption while processing user packets to generate page faults.

CVE-2024-32503
Software Genérico General
8.4
HIGH
EPSS
0.1%
2024 1 PoC

An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 850, Exynos 1080, Exynos 2100, Exynos 1280, Exynos 1380, Exynos 1330, Exynos W920, Exynos W930. The mobile processor lacks proper memory deallocation checking, which can result in a UAF (Use-After-Free) vulnerability.

CVE-2024-41340
Software Genérico General
8.4
HIGH
EPSS
0.1%
2024 1 PoC

An issue in Draytek devices Vigor 165/166 prior to v4.2.6 , Vigor 2620/LTE200 prior to v3.9.8.8, Vigor 2860/2925 prior to v3.9.7, Vigor 2862/2926 prior to v3.9.9.4, Vigor 2133/2762/2832 prior to v3.9.8, Vigor 2135/2765/2766 prior to v4.4.5.1, Vigor 2865/2866/2927 prior to v4.4.5.3, Vigor 2962/3910 prior to v4.3.2.7, Vigor 3912 prior to v4.3.5.2, and Vigor 2925 up to v3.9.6 allows attackers to upload crafted APP Enforcement modules, leading to arbitrary code execution.

CVE-2024-2448
LoadMaster General
8.4
HIGH
EPSS
44.8%
2024 CWE-78 1 PoC

An OS command injection vulnerability has been identified in LoadMaster.  An authenticated UI user with any permission settings may be able to inject commands into a UI component using a shell command resulting in OS command injection.

CVE-2024-34329
Software Genérico General
8.4
HIGH
EPSS
8.0%
2024 2 PoCs

Insecure permissions in Entrust Datacard XPS Card Printer Driver 8.5 and earlier without the dxp1-patch-E24-004 patch allows unauthenticated attackers to execute arbitrary code as SYSTEM via a crafted DLL payload.

CVE-2024-34620
Samsung Mobile Devices General
8.4
HIGH
EPSS
0.1%
2024 1 PoC

Improper privilege management in SumeNNService prior to SMR Aug-2024 Release 1 allows local attackers to start privileged service.

CVE-2024-32502
Software Genérico General
8.4
HIGH
EPSS
0.1%
2024 1 PoC

An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 850, Exynos 1080, Exynos 2100, Exynos 1280, Exynos 1380, Exynos 1330, Exynos W920, Exynos W930. The mobile processor lacks proper reference count checking, which can result in a UAF (Use-After-Free) vulnerability.

CVE-2024-52035
catdoc General
8.4
HIGH
EPSS
0.2%
2024 CWE-190 2 PoCs

An integer overflow vulnerability exists in the OLE Document File Allocation Table Parser functionality of catdoc 0.95. A specially crafted malformed file can lead to heap-based memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2024-1708
🔥 KEV ScreenConnect General
8.4
HIGH
EPSS
84.0%
2024 CWE-22 2 PoCs

ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confidential data or critical systems.

CVE-2024-51381
Software Genérico Web
8.4
HIGH
EPSS
0.1%
2024 1 PoC

Cross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 that allows attackers to perform actions reserved for administrators, including creating admin accounts. This critical flaw can lead to unauthorized activities, compromising the security and integrity of the platform, especially if an attacker gains administrative control.

CVE-2024-32504
Software Genérico General
8.4
HIGH
EPSS
0.2%
2024 1 PoC

An issue was discovered in Samsung Mobile Processor and Wearable Processor Exynos 850, Exynos 1080, Exynos 2100, Exynos 1280, Exynos 1380, Exynos 1330, Exynos W920, Exynos W930. The mobile processor lacks proper length checking, which can result in an OOB (Out-of-Bounds) Write vulnerability.

CVE-2024-40811
macOS General
8.4
HIGH
EPSS
0.1%
2024 1 PoC

The issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14.6. An app may be able to modify protected parts of the file system.

CVE-2024-43087
Android General
8.4
HIGH
EPSS
0.1%
2024 1 PoC

In getInstalledAccessibilityPreferences of AccessibilitySettings.java, there is a possible way to hide an enabled accessibility service in the accessibility service settings due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation.