6739 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-37004
AutoCAD General
7.8
HIGH
EPSS
0.2%
2024 CWE-416 1 PoC

A maliciously crafted SLDPRT file, when parsed in ASMKERN229A.dll through Autodesk applications, can cause a use-after-free vulnerability. This vulnerability, along with other vulnerabilities, could lead to code execution in the current process.

CVE-2024-11477
7-Zip General
7.8
HIGH
EPSS
43.6%
2024 CWE-191 1 PoC

7-Zip Zstandard Decompression Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of 7-Zip. Interaction with this library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The specific flaw exists within the implementation of Zstandard decompression. The issue results from the lack of proper validation of user-supplied data, which can result in an integer underflow before writing to memory. An attacker can leverage this vulnerability to execute

CVE-2024-37001
AutoCAD General
7.8
HIGH
EPSS
0.1%
2024 CWE-122 1 PoC

A maliciously crafted 3DM file, when parsed in opennurbs.dll through Autodesk applications, can be used to cause a Heap-based Overflow. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

CVE-2024-39069
Software Genérico General
7.8
HIGH
EPSS
3.4%
2024 2 PoCs

An issue in ifood Order Manager v3.35.5 'Gestor de Peddios.exe' allows attackers to execute arbitrary code via a DLL hijacking attack.

CVE-2024-46060
Software Genérico General
7.8
HIGH
EPSS
0.0%
2024 1 PoC

Anaconda3 macOS installers before 2024.06-1 contain a local privilege escalation vulnerability when installed outside the user's home directory. During installation, world-writable files are created and executed with root privileges. This allows a local low-privileged user to inject arbitrary commands, leading to code execution as the root user.

CVE-2024-30338
PDF Reader General
7.8
HIGH
EPSS
2.2%
2024 CWE-416 1 PoC

Foxit PDF Reader Doc Object Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current p

CVE-2024-13944
Norton Utilities Ultimate Windows
7.8
HIGH
EPSS
0.1%
2024 CWE-367 1 PoC

Link Following Local Privilege Escalation Vulnerability in NortonUtilitiesSvc in Norton Utilities Ultimate Version 24.2.16862.6344 on Windows 10 Pro x64 allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via the creation of a symbolic link and leveraging a TOCTTOU (time-of-check to time-of-use) attack.

CVE-2024-0044
Android General
7.8
HIGH
EPSS
9.7%
2024 12 PoCs

In createSessionInternal of PackageInstallerService.java, there is a possible run-as any app due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2024-25376
Software Genérico General
7.8
HIGH
EPSS
0.1%
2024 1 PoC

An issue discovered in Thesycon Software Solutions Gmbh & Co. KG TUSBAudio MSI-based installers before 5.68.0 allows a local attacker to execute arbitrary code via the msiexec.exe repair mode.

CVE-2024-48605
Software Genérico General
7.8
HIGH
EPSS
5.8%
2024 2 PoCs

An issue in Helakuru Desktop Application v1.1 allows a local attacker to execute arbitrary code via the lack of proper validation of the wow64log.dll file.

CVE-2024-35141
Security Verify Access Docker DevOps
7.8
HIGH
EPSS
0.0%
2024 CWE-250 1 PoC

IBM Security Verify Access Docker 10.0.0 through 10.0.6 could allow a local user to escalate their privileges due to execution of unnecessary privileges.

CVE-2024-9248
PDF Reader General
7.8
HIGH
EPSS
1.3%
2024 CWE-787 1 PoC

Foxit PDF Reader PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code

CVE-2024-38127
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
8.1%
2024 CWE-126 1 PoC

Windows Hyper-V Elevation of Privilege Vulnerability

CVE-2024-25446
Software Genérico General
7.8
HIGH
EPSS
0.1%
2024 1 PoC

An issue in the HuginBase::PTools::setDestImage function of Hugin v2022.0.0 allows attackers to cause a heap buffer overflow via parsing a crafted image.

CVE-2024-53920
Software Genérico General
7.8
HIGH
EPSS
0.1%
2024 1 PoC

In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrary code. (This unsafe expansion also occurs if a user chooses to enable on-the-fly diagnosis that byte compiles untrusted Emacs Lisp source code.)

CVE-2024-12194
Navisworks Freedom General
7.8
HIGH
EPSS
0.5%
2024 CWE-120 1 PoC

A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

CVE-2024-30341
PDF Reader General
7.8
HIGH
EPSS
1.2%
2024 CWE-125 1 PoC

Foxit PDF Reader Doc Object Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the

CVE-2024-26581
Linux General
7.8
HIGH
EPSS
0.3%
2024 1 PoC

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_set_rbtree: skip end interval element from gc rbtree lazy gc on insert might collect an end interval element that has been just added in this transactions, skip end interval elements that are not yet active.

CVE-2024-24092
Software Genérico Web Database
7.8
HIGH
EPSS
0.1%
2024 1 PoC

SQL Injection vulnerability in Code-projects.org Scholars Tracking System 1.0 allows attackers to run arbitrary code via login.php.

CVE-2024-43097
Android General
7.8
HIGH
EPSS
0.9%
2024 1 PoC

In resizeToAtLeast of SkRegion.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.