6.9

CVSS4.0

CVE-2024-56139 - A stack overflow Segmentation Fault (SEGV) and Memory Leak in pdftools

pdftools is a high level tools to convert PDF files to ePUB formats. In versions up to and including 0.5.0 maliciously crafted epub files can cause a stack overflow leading to a crash. This issue has not yet been addressed and users are advised to avoid untrusted input to their systems.

πŸ“… Published: Dec. 17, 2024, 6:32 p.m. πŸ”„ Last Modified: Dec. 20, 2024, 9:15 p.m.

7.5

CVSS3.1

CVE-2024-51479 - Authorization bypass in Next.js

Next.js is a React framework for building full-stack web applications. In affected versions if a Next.js application is performing authorization in middleware based on pathname, it was possible for this authorization to be bypassed for pages directly under the application's root directory. For exam…

πŸ“… Published: Dec. 17, 2024, 6:13 p.m. πŸ”„ Last Modified: Sept. 10, 2025, 3:48 p.m.

4.9

CVSS3.1

CVE-2024-49816 - IBM Security Guardium Key Lifecycle Manager information disclosure

IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1Β stores potentially sensitive information in log files that could be read by a local privileged user.

πŸ“… Published: Dec. 17, 2024, 5:42 p.m. πŸ”„ Last Modified: Jan. 7, 2025, 5:25 p.m.

3.7

CVSS3.1

CVE-2024-49820 - IBM Security Guardium Key Lifecycle Manager information disclosure

IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1Β could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in …

πŸ“… Published: Dec. 17, 2024, 5:42 p.m. πŸ”„ Last Modified: Jan. 10, 2025, 5:42 p.m.

4.1

CVSS3.1

CVE-2024-49819 - IBM Security Guardium Key Lifecycle Manager information disclosure

IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1Β could allow a remote attacker to obtain sensitive information in cleartext in a communication channel that can be sniffed by unauthorized actors.

πŸ“… Published: Dec. 17, 2024, 5:41 p.m. πŸ”„ Last Modified: Jan. 10, 2025, 5:52 p.m.

4.3

CVSS3.1

CVE-2024-49818 - IBM Security Guardium Key Lifecycle Manager information disclosure

IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.

πŸ“… Published: Dec. 17, 2024, 5:35 p.m. πŸ”„ Last Modified: Jan. 7, 2025, 5:20 p.m.

4.4

CVSS3.1

CVE-2024-49817 - IBM Security Guardium Key Lifecycle Manager information disclosure

IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores user credentials in configuration files which can be read by a local privileged user.

πŸ“… Published: Dec. 17, 2024, 5:34 p.m. πŸ”„ Last Modified: Jan. 7, 2025, 5:23 p.m.

3.1

CVSS3.1

CVE-2024-42194 - HCL BigFix Inventory is affected by an access control vulnerability

An improper handling of insufficient permissions or privileges affects HCL BigFix Inventory. An attacker having access via a read-only account can possibly change certain configuration parameters by crafting a specific REST API call.

πŸ“… Published: Dec. 17, 2024, 5:28 p.m. πŸ”„ Last Modified: Dec. 17, 2024, 8:37 p.m.

7.8

CVSS3.1

CVE-2024-12671 - DWFX File Parsing Vulnerabilities in Autodesk Navisworks Desktop Software

A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.

πŸ“… Published: Dec. 17, 2024, 3:28 p.m. πŸ”„ Last Modified: Aug. 26, 2025, 5:17 p.m.

7.8

CVSS3.1

CVE-2024-12670 - DWFX File Parsing Vulnerabilities in Autodesk Navisworks Desktop Software

A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can be used to cause a Heap-based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.

πŸ“… Published: Dec. 17, 2024, 3:28 p.m. πŸ”„ Last Modified: Nov. 13, 2025, 7:32 p.m.
Total resulsts: 343923
Page 6906 of 34,393
Β« previous page Β» next page
Filters