3165 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-20845
Samsung Mobile Devices General
8.4
HIGH
EPSS
0.1%
2024 1 PoC

Out-of-bounds write vulnerability while releasing memory in libsavsac.so prior to SMR Apr-2024 Release 1 allows local attacker to execute arbitrary code.

CVE-2024-2608
Firefox General
8.4
HIGH
EPSS
0.2%
2024 1 PoC

`AppendEncodedAttributeValue(), ExtraSpaceNeededForAttrEncoding()` and `AppendEncodedCharacters()` could have experienced integer overflows, causing underallocation of an output buffer leading to an out of bounds write. This vulnerability affects Firefox < 124, Firefox ESR < 115.9, and Thunderbird < 115.9.

CVE-2024-51382
Software Genérico Web
8.4
HIGH
EPSS
0.1%
2024 1 PoC

Cross-Site Request Forgery (CSRF) vulnerability in JATOS v3.9.3 allows an attacker to reset the administrator's password. This critical security flaw can result in unauthorized access to the platform, enabling attackers to hijack admin accounts and compromise the integrity and security of the system.

CVE-2024-43088
Android General
8.4
HIGH
EPSS
0.4%
2024 1 PoC

In multiple functions in AppInfoBase.java, there is a possible way to manipulate app permission settings belonging to another user on the device due to a missing permission check. This could lead to local escalation of privilege across user boundaries with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2024-20053
MT2713, MT2737, MT6781, MT6789, MT6835, MT6855, MT6879, MT6880, MT6886, MT6890, MT6895, MT6980, MT6983, MT6985, MT6989, MT6990, MT8167, MT8168, MT8173, MT8175, MT8188, MT8195, MT8321, MT8362A, MT8365, MT8385, MT8390, MT8395, MT8666, MT8667, MT8673, MT8765, MT8766, MT8768, MT8781, MT8786, MT8788, MT8789, MT8791, MT8791T, MT8796, MT8797, MT8798 General
8.4
HIGH
EPSS
0.0%
2024 1 PoC

In flashc, there is a possible out of bounds write due to an uncaught exception. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541757; Issue ID: ALPS08541764.

CVE-2024-29050
Windows 10 Version 1809 Windows
8.4
HIGH
EPSS
38.3%
2024 CWE-197 1 PoC

Windows Cryptographic Services Remote Code Execution Vulnerability

CVE-2024-34329
Software Genérico General
8.4
HIGH
EPSS
8.0%
2024 2 PoCs

Insecure permissions in Entrust Datacard XPS Card Printer Driver 8.5 and earlier without the dxp1-patch-E24-004 patch allows unauthenticated attackers to execute arbitrary code as SYSTEM via a crafted DLL payload.

CVE-2024-44067
Software Genérico General
8.4
HIGH
EPSS
0.0%
2024 1 PoC

The T-Head XuanTie C910 CPU in the TH1520 SoC and the T-Head XuanTie C920 CPU in the SOPHON SG2042 have instructions that allow unprivileged attackers to write to arbitrary physical memory locations, aka GhostWrite.

CVE-2024-45273
mbNET.mini General
8.4
HIGH
EPSS
0.1%
2024 CWE-261 1 PoC

An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used.

CVE-2024-31959
Software Genérico General
8.4
HIGH
EPSS
0.1%
2024 1 PoC

An issue was discovered in Samsung Mobile Processor Exynos 2200, Exynos 1480, Exynos 2400. It lacks a check for the validation of native handles, which can result in code execution.

CVE-2024-55211
Software Genérico Networking
8.4
HIGH
EPSS
0.1%
2024 1 PoC

An issue in Think Router Tk-Rt-Wr135G V3.0.2-X000 allows attackers to bypass authentication via a crafted cookie.

CVE-2024-54028
catdoc General
8.4
HIGH
EPSS
0.2%
2024 CWE-191 2 PoCs

An integer underflow vulnerability exists in the OLE Document DIFAT Parser functionality of catdoc 0.95. A specially crafted malformed file can lead to heap-based memory corruption. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2024-3435
parisneo/lollms-webui General
8.4
HIGH
EPSS
0.4%
2024 CWE-29 1 PoC

A path traversal vulnerability exists in the 'save_settings' endpoint of the parisneo/lollms-webui application, affecting versions up to the latest release before 9.5. The vulnerability arises due to insufficient sanitization of the 'config' parameter in the 'apply_settings' function, allowing an attacker to manipulate the application's configuration by sending specially crafted JSON payloads. This could lead to remote code execution (RCE) by bypassing existing patches designed to mitigate such vulnerabilities.

CVE-2024-6473
Browser General
8.4
HIGH
EPSS
3.1%
2024 CWE-426 1 PoC

Yandex Browser for Desktop before 24.7.1.380 has a DLL Hijacking Vulnerability because an untrusted search path is used.

CVE-2024-31319
Android General
8.4
HIGH
EPSS
0.0%
2024 2 PoCs

In updateNotificationChannelFromPrivilegedListener of NotificationManagerService.java, there is a possible cross-user data leak due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2024-20812
Samsung Mobile Devices General
8.4
HIGH
EPSS
0.0%
2024 1 PoC

Out-of-bounds Write in padmd_vld_htbl of libpadm.so prior to SMR Feb-2024 Release 1 allows local attacker to execute arbitrary code.

CVE-2024-41605
Software Genérico General
8.4
HIGH
EPSS
0.0%
2024 1 PoC

In Foxit PDF Reader before 2024.3, and PDF Editor before 2024.3 and 13.x before 13.1.4, an attacker can replace an update file with a Trojan horse via side loading, because the update service lacks integrity validation for the updater. Attacker-controlled code may thus be executed.

CVE-2024-48123
Software Genérico General
8.4
HIGH
EPSS
0.1%
2024 1 PoC

An issue in the USB Autorun function of HI-SCAN 6040i Hitrax HX-03-19-I allows attackers to execute arbitrary code via uploading a crafted script from a USB device.

CVE-2024-48877
xls2csv General
8.4
HIGH
EPSS
0.2%
2024 CWE-680 2 PoCs

A memory corruption vulnerability exists in the Shared String Table Record Parser implementation in xls2csv utility version 0.95. A specially crafted malformed file can lead to a heap buffer overflow. An attacker can provide a malicious file to trigger this vulnerability.

CVE-2024-52333
DCMTK General
8.4
HIGH
EPSS
0.1%
2024 CWE-119 1 PoC

An improper array index validation vulnerability exists in the determineMinMax functionality of OFFIS DCMTK 3.6.8. A specially crafted DICOM file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.