6.5

CVSS3.1

CVE-2018-9352 -

In ihevcd_allocate_dynamic_bufs of ihevcd_api.c there is a possible resource exhaustion due to integer overflow. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.

📅 Published: Nov. 27, 2024, 10:31 p.m. 🔄 Last Modified: Dec. 18, 2024, 8:24 p.m.

6.5

CVSS3.1

CVE-2018-9351 -

In ih264e_fmt_conv_420p_to_420sp of ih264e_fmt_conv.c there is a possible out of bound read due to missing bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is needed for exploitation.

📅 Published: Nov. 27, 2024, 10:05 p.m. 🔄 Last Modified: Dec. 18, 2024, 7:45 p.m.

6.5

CVSS3.1

CVE-2018-9350 -

In ih264d_assign_pic_num of ih264d_utils.c there is a possible out of bound read due to missing bounds check. This could lead to a denial of service with no additional execution privileges needed. User interaction is needed for exploitation.

📅 Published: Nov. 27, 2024, 9:52 p.m. 🔄 Last Modified: Dec. 18, 2024, 8:34 p.m.

6.5

CVSS3.1

CVE-2018-9349 -

In mv_err_cost of mcomp.c there is a possible out of bounds read due to missing bounds check. This could lead to denial of service with no additional execution privileges needed. User interaction is needed for exploitation.

📅 Published: Nov. 27, 2024, 9:45 p.m. 🔄 Last Modified: Dec. 18, 2024, 8:33 p.m.

8.4

CVSS3.1

CVE-2017-13323 -

In String16 of String16.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege in an unprivileged process with no additional execution privileges needed. User interaction is not needed for exploitation.

📅 Published: Nov. 27, 2024, 9:35 p.m. 🔄 Last Modified: Dec. 18, 2024, 8:33 p.m.

8.6

CVSS3.1

CVE-2024-53860 - Potential Abuse for Sending Arbitrary Emails in sp-php-email-handler

sp-php-email-handler is a PHP package for handling contact form submissions. Messages sent using this script are vulnerable to abuse, as the script allows anybody to specify arbitrary email recipients and include user-provided content in confirmation emails. This could enable malicious actors to us…

📅 Published: Nov. 27, 2024, 9:31 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.2

CVSS3.1

CVE-2017-13321 -

In SensorService::isDataInjectionEnabled of frameworks/native/services/sensorservice/SensorService.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not neede…

📅 Published: Nov. 27, 2024, 9:28 p.m. 🔄 Last Modified: Dec. 18, 2024, 8:32 p.m.

6.8

CVSS3.1

CVE-2024-53260 - Course Roster vulnerable to CSV Injection in Autolab

Autolab is a course management service that enables auto-graded programming assignments. A user can modify their first and or last name to include a valid excel / spreadsheet formula. When an instructor downloads their course's roster and opens, this name will then be evaluated as a formula. This c…

📅 Published: Nov. 27, 2024, 9:28 p.m. 🔄 Last Modified: April 21, 2025, 3:07 p.m.

6.5

CVSS3.1

CVE-2024-53858 - Recursive repository cloning can leak authentication tokens to non-GitHub submodule hosts in the gh…

The gh cli is GitHub’s official command line tool. A security vulnerability has been identified in the GitHub CLI that could leak authentication tokens when cloning repositories containing `git` submodules hosted outside of GitHub.com and ghe.com. This vulnerability stems from several `gh` commands…

📅 Published: Nov. 27, 2024, 9:25 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-53859 - go-gh `auth.TokenForHost` violates GitHub host security boundary within a codespace

go-gh is a Go module for interacting with the `gh` utility and the GitHub API from the command line. A security vulnerability has been identified in `go-gh` that could leak authentication tokens intended for GitHub hosts to non-GitHub hosts when within a codespace. `go-gh` sources authentication to…

📅 Published: Nov. 27, 2024, 9:25 p.m. 🔄 Last Modified: Sept. 22, 2025, 6:16 p.m.
Total resulsts: 349182
Page 7685 of 34,919
« previous page » next page
Filters