8.4

CVSS4.0

CVE-2024-12741 - Deserialization Of Untrusted Data Vulnerability In NI DAQExpress Project File

A deserialization of untrusted data vulnerability exists in NI DAQExpress that may result in remote code execution. Successful exploitation requires an attacker to get a user to open a specially crafted project file. This vulnerability affects DAQExpress 5.1 and prior versions.  Please note that DA…

📅 Published: Dec. 18, 2024, 7:20 p.m. 🔄 Last Modified: March 6, 2025, 4:18 p.m.

8.8

CVSS4.0

CVE-2024-52591 - Missing validation allows spoofed profiles and notes in Misskey

Misskey is an open source, federated social media platform. In affected versions missing validation in `ApRequestService.signedGet` and `HttpRequestService.getActivityJson` allows an attacker to create fake user profiles and forged notes. The spoofed users will appear to be from a different instanc…

📅 Published: Dec. 18, 2024, 7:20 p.m. 🔄 Last Modified: Nov. 26, 2025, 4:25 p.m.

6.9

CVSS4.0

CVE-2024-52592 - Missing validation allows spoofed poll updates in Misskey

Misskey is an open source, federated social media platform. In affected versions missing validation in `ApInboxService.update` allows an attacker to modify the result of polls belonging to another user. No authentication is required, except for a valid signature from any actor on any remote instanc…

📅 Published: Dec. 18, 2024, 7:19 p.m. 🔄 Last Modified: Nov. 26, 2025, 4:34 p.m.

5.1

CVSS4.0

CVE-2024-52593 - Missing validation allows spoofed "origin" links in Misskey

Misskey is an open source, federated social media platform.In affected versions missing validation in `NoteCreateService.insertNote`, `ApPersonService.createPerson`, and `ApPersonService.updatePerson` allows an attacker to control the target of any "origin" links (such as the "view on remote instan…

📅 Published: Dec. 18, 2024, 7:17 p.m. 🔄 Last Modified: Nov. 26, 2025, 4:34 p.m.

7.1

CVSS3.1

CVE-2024-53271 - HTTP/1.1 multiple issues with envoy.reloadable_features.http1_balsa_delay_reset in envoy

Envoy is a cloud-native high-performance edge/middle/service proxy. In affected versions envoy does not properly handle http 1.1 non-101 1xx responses. This can lead to downstream failures in networked devices. This issue has been addressed in versions 1.31.5 and 1.32.3. Users are advised to upgra…

📅 Published: Dec. 18, 2024, 7:12 p.m. 🔄 Last Modified: Sept. 4, 2025, 2:03 p.m.

7.5

CVSS3.1

CVE-2024-53270 - HTTP/1: sending overload crashes when the request is reset beforehand in envoy

Envoy is a cloud-native high-performance edge/middle/service proxy. In affected versions `sendOverloadError` is going to assume the active request exists when `envoy.load_shed_points.http1_server_abort_dispatch` is configured. If `active_request` is nullptr, only onMessageBeginImpl() is called. How…

📅 Published: Dec. 18, 2024, 7:12 p.m. 🔄 Last Modified: Sept. 4, 2025, 1:47 p.m.

4.5

CVSS3.1

CVE-2024-53269 - Happy Eyeballs: Validate that additional_address are IP addresses instead of crashing when sorting …

Envoy is a cloud-native high-performance edge/middle/service proxy. When additional address are not ip addresses, then the Happy Eyeballs sorting algorithm will crash in data plane. This issue has been addressed in releases 1.32.2, 1.31.4, and 1.30.8. Users are advised to upgrade. Users unable to u…

📅 Published: Dec. 18, 2024, 7:12 p.m. 🔄 Last Modified: Aug. 28, 2025, 2:41 p.m.

10

CVSS4.0

CVE-2024-47040 - Use After Free in the android.hardware.radio.sap.ISap/slot2 service

There is a possible UAF due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

📅 Published: Dec. 18, 2024, 7:08 p.m. 🔄 Last Modified: July 24, 2025, 6 p.m.

10

CVSS4.0

CVE-2024-47039 - OOB Read in the android.hardware.boot.IBootControl/default service

In isSlotMarkedSuccessful of BootControl.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local  information disclosure with no additional execution privileges needed. User  interaction is not needed for exploitation.

📅 Published: Dec. 18, 2024, 7:04 p.m. 🔄 Last Modified: July 24, 2025, 6:02 p.m.

10

CVSS4.0

CVE-2024-47038 -

In dhd_prot_flowrings_pool_release of dhd_msgbuf.c, there is a possible outcof bounds write due to a missing bounds check. This could lead to localcescalation of privilege with no additional execution privileges needed. Usercinteraction is not needed for exploitation.

📅 Published: Dec. 18, 2024, 7:01 p.m. 🔄 Last Modified: July 24, 2025, 6:02 p.m.
Total resulsts: 343947
Page 6896 of 34,395
« previous page » next page
Filters