7500 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2024-43097
Android General
7.8
HIGH
EPSS
0.9%
2024 1 PoC

In resizeToAtLeast of SkRegion.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2024-0118
GPU, vGPU, and Cloud Gaming Cloud Windows
7.8
HIGH
EPSS
0.2%
2024 CWE-125 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

CVE-2024-12194
Navisworks Freedom General
7.8
HIGH
EPSS
0.5%
2024 CWE-120 1 PoC

A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.

CVE-2024-30353
PDF Reader General
7.8
HIGH
EPSS
1.4%
2024 CWE-125 1 PoC

Foxit PDF Reader AcroForm Out-Of-Bounds Read Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Doc objects in AcroForms. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute

CVE-2024-23208
iOS and iPadOS General
7.8
HIGH
EPSS
3.2%
2024 1 PoC

The issue was addressed with improved memory handling. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS 10.3. An app may be able to execute arbitrary code with kernel privileges.

CVE-2024-43583
Windows 10 Version 1809 Windows
7.8
HIGH
EPSS
3.7%
2024 CWE-250 2 PoCs

Winlogon Elevation of Privilege Vulnerability

CVE-2024-0120
GPU, vGPU, and Cloud Gaming Cloud Windows
7.8
HIGH
EPSS
0.2%
2024 CWE-125 1 PoC

NVIDIA GPU Display Driver for Windows contains a vulnerability in the user mode layer, where an unprivileged regular user can cause an out-of-bounds read. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

CVE-2024-43762
Android General
7.8
HIGH
EPSS
0.3%
2024 2 PoCs

In multiple locations, there is a possible way to avoid unbinding of a service from the system due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

CVE-2024-23773
Software Genérico Windows
7.8
HIGH
EPSS
0.3%
2024 1 PoC

An issue was discovered in Quest KACE Agent for Windows 12.0.38 and 13.1.23.0. An Arbitrary file delete vulnerability exists in the KSchedulerSvc.exe component. Local attackers can delete any file of their choice with NT Authority\SYSTEM privileges.

CVE-2024-0090
GPU display driver, vGPU software, and Cloud Gaming Cloud Windows
7.8
HIGH
EPSS
0.3%
2024 CWE-787 1 PoC

NVIDIA GPU driver for Windows and Linux contains a vulnerability where a user can cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.

CVE-2024-25088
Software Genérico General
7.8
HIGH
EPSS
0.1%
2024 1 PoC

Improper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges and execute arbitrary code.

CVE-2024-22029
Container suse/manager/5.0/x86_64/server:5.0.0-beta1.2.122 DevOps Web
7.8
HIGH
EPSS
0.0%
2024 CWE-732 1 PoC

Insecure permissions in the packaging of tomcat allow local users that win a race during package installation to escalate to root

CVE-2024-42052
Software Genérico Windows
7.8
HIGH
EPSS
0.0%
2024 1 PoC

The MSI installer for Splashtop Streamer for Windows before 3.5.8.0 uses a temporary folder with weak permissions during installation. A local user can exploit this to escalate privileges to SYSTEM by placing a wevtutil.exe file in the folder.

CVE-2024-49557
SmartFabric OS10 Software General
7.8
HIGH
EPSS
0.3%
2024 CWE-77 1 PoC

Dell SmartFabric OS10 Software, version(s) 10.5.6.x, 10.5.5.x, 10.5.4.x, 10.5.3.x, contain(s) an Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.

CVE-2024-43630
Windows Server 2022 Windows
7.8
HIGH
EPSS
3.6%
2024 CWE-121 1 PoC

Windows Kernel Elevation of Privilege Vulnerability

CVE-2024-34332
Software Genérico Web Windows
7.8
HIGH
EPSS
0.0%
2024 1 PoC

An issue in SiSoftware SANDRA v31.66 (SANDRA.sys 15.18.1.1) and before allows an attacker to escalate privileges via a crafted buffer sent to the Kernel Driver using the DeviceIoControl Windows API.

CVE-2024-37006
AutoCAD General
7.8
HIGH
EPSS
0.2%
2024 CWE-787 1 PoC

A maliciously crafted CATPRODUCT file, when parsed in CC5Dll.dll through Autodesk applications, can lead to a memory corruption vulnerability by write access violation. This vulnerability, in conjunction with other vulnerabilities, can lead to code execution in the context of the current process.

CVE-2024-50126
Linux Web Networking
7.8
HIGH
EPSS
0.0%
2024 1 PoC

In the Linux kernel, the following vulnerability has been resolved: net: sched: use RCU read-side critical section in taprio_dump() Fix possible use-after-free in 'taprio_dump()' by adding RCU read-side critical section there. Never seen on x86 but found on a KASAN-enabled arm64 system when investigating https://syzkaller.appspot.com/bug?extid=b65e0af58423fc8a73aa: [T15862] BUG: KASAN: slab-use-after-free in taprio_dump+0xa0c/0xbb0 [T15862] Read of size 4 at addr ffff0000d4bb88f8 by task repro/15862 [T15862] [T15862] CPU: 0 UID: 0 PID: 15862 Comm: repro Not tainted 6.11.0-rc1-00293-gdefaf1a

CVE-2024-13960
TuneUp Windows
7.8
HIGH
EPSS
0.1%
2024 CWE-59 1 PoC

Link Following Local Privilege Escalation Vulnerability in TuneUp Service in AVG TuneUp Version 23.4 (build 15592) on Windows 10 allows local attackers to escalate privileges and execute arbitrary code in the context of SYSTEM via creating a symbolic link and leveraging a TOCTTOU (time-of-check to time-of-use) attack.