7.6
CVE-2024-8058 -
An improper parsing vulnerability was reported in the FileZ client that could allow a crafted file in the FileZ directory to read arbitrary files on the device due to URL preloading.
8.1
CVE-2024-6001 -
An improper certificate validation vulnerability was reported in LADM that could allow a network attacker with the ability to redirect an update request to a remote server and execute code with elevated privileges.
7.8
CVE-2024-4762 -
An improper validation vulnerability was reported in the firmware update mechanism of LADM and LDCC that could allow a local attacker to escalate privileges.
9.2
CVE-2024-11144 - Race Condition with LightFTP
The server lacks thread safety and can be crashed by anomalous data sent by an anonymous user from a remote network. The crash causes the FTP service to become unavailable, affecting all users and processes that rely on it for file transfers. If the crash occurs during file upload or download, it cโฆ
6.8
CVE-2024-12657 - IObit Advanced SystemCare Utimate IOCTL AscRegistryFilter.sys 0x8001E000 null pointer dereference
A vulnerability has been found in IObit Advanced SystemCare Utimate up to 17.0.0 and classified as problematic. This vulnerability affects the function 0x8001E000 in the library AscRegistryFilter.sys of the component IOCTL Handler. The manipulation leads to null pointer dereference. An attack has tโฆ
6.8
CVE-2024-12656 - FabulaTech USB over Network IOCT ftusbbus2.sys 0x220448 null pointer dereference
A vulnerability, which was classified as problematic, was found in FabulaTech USB over Network 6.0.6.1. This affects the function 0x220448 in the library ftusbbus2.sys of the component IOCT Handler. The manipulation leads to null pointer dereference. The attack needs to be approached locally. The eโฆ
8.4
CVE-2024-10095 - Progress UI for WPF format provider unsafe deserialization vulnerability
In Progress Telerik UI for WPF versions prior to 2024 Q4 (2024.4.1213), a code execution attack is possible through an insecure deserialization vulnerability.
6.8
CVE-2024-12655 - FabulaTech USB over Network IOCT ftusbbus2.sys 0x220420 null pointer dereference
A vulnerability, which was classified as problematic, has been found in FabulaTech USB over Network 6.0.6.1. Affected by this issue is the function 0x220420 in the library ftusbbus2.sys of the component IOCT Handler. The manipulation leads to null pointer dereference. It is possible to launch the aโฆ
0.0
CVE-2024-12681 -
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
5.7
CVE-2024-11358 - Insecure Android File Provider Paths
Mattermost Android Mobile Apps versions <=2.21.0 fail to properly configure file providers which allows an attacker with local access to access files via file provider.