6.5

CVSS3.1

CVE-2017-13320 -

In impeg2d_bit_stream_flush() of libmpeg2dec there is a possible OOB read due to a missing bounds check. This could lead to Remote DoS with no additional execution privileges needed. User interaction is needed for exploitation.

📅 Published: Nov. 27, 2024, 9:24 p.m. 🔄 Last Modified: Dec. 18, 2024, 8:30 p.m.

7.5

CVSS3.1

CVE-2017-13319 -

In pvmp3_get_main_data_size of pvmp3_get_main_data_size.cpp, there is a possible buffer overread due to a missing bounds check. This could lead to remote information disclosure of global static variables with no additional execution privileges needed. User interaction is not needed for exploitation.

📅 Published: Nov. 27, 2024, 7:55 p.m. 🔄 Last Modified: Dec. 18, 2024, 8:30 p.m.

8.4

CVSS3.1

CVE-2017-13316 -

In checkPermissions of RecognitionService.java, there is a possible permissions bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

📅 Published: Nov. 27, 2024, 7:18 p.m. 🔄 Last Modified: Dec. 18, 2024, 7:49 p.m.

5.1

CVSS4.0

CVE-2024-53264 - Open Redirect Vulnerability in Loading Page in bunkerweb

bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). A open redirect vulnerability exists in the loading endpoint, allowing attackers to redirect authenticated users to arbitrary external URLs via the "next" parameter. The loading endpoint accepts and uses an unvalidated …

📅 Published: Nov. 27, 2024, 6:31 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

1.9

CVSS3.1

CVE-2024-53855 - User can view tickets from organizations they're not apart of in centurion_erp

Centurion ERP (Enterprise Rescource Planning) is a simple application developed to provide open source IT management with a large emphasis on the IT Service Management (ITSM) modules. A user who is authenticated and has view permissions for a ticket, can view the tickets of another organization the…

📅 Published: Nov. 27, 2024, 6:27 p.m. 🔄 Last Modified: Sept. 23, 2025, 1:05 p.m.

8.7

CVSS4.0

CVE-2023-29001 - Uncontrolled recursion due to insufficient validation of the IPv6 source routing header in Contiki-…

Contiki-NG is an open-source, cross-platform operating system for IoT devices. The Contiki-NG operating system processes source routing headers (SRH) in its two alternative RPL protocol implementations. The IPv6 implementation uses the results of this processing to determine whether an incoming pac…

📅 Published: Nov. 27, 2024, 6:20 p.m. 🔄 Last Modified: April 10, 2025, 2:58 p.m.

8.4

CVSS3.1

CVE-2024-41125 - Out-of-bounds read in SNMP when decoding a string in Contiki-NG

Contiki-NG is an open-source, cross-platform operating system for IoT devices. An out-of-bounds read of 1 byte can be triggered when sending a packet to a device running the Contiki-NG operating system with SNMP enabled. The SNMP module is disabled in the default Contiki-NG configuration. The vulne…

📅 Published: Nov. 27, 2024, 6:20 p.m. 🔄 Last Modified: April 10, 2025, 2:55 p.m.

8.4

CVSS3.1

CVE-2024-41126 - Out-of-bounds read when decoding SNMP messages in Contiki-NG

Contiki-NG is an open-source, cross-platform operating system for IoT devices. An out-of-bounds read of 1 byte can be triggered when sending a packet to a device running the Contiki-NG operating system with SNMP enabled. The SNMP module is disabled in the default Contiki-NG configuration. The vulne…

📅 Published: Nov. 27, 2024, 6:20 p.m. 🔄 Last Modified: April 10, 2025, 2:54 p.m.

7.5

CVSS3.1

CVE-2024-47181 - Unaligned memory access in RPL option processing in Contiki-NG

Contiki-NG is an open-source, cross-platform operating system for IoT devices. An unaligned memory access can be triggered in the two RPL implementations of the Contiki-NG operating system. The problem can occur when either one of these RPL implementations is enabled and connected to an RPL instanc…

📅 Published: Nov. 27, 2024, 6:20 p.m. 🔄 Last Modified: April 10, 2025, 2:49 p.m.

8.8

CVSS3.1

CVE-2024-9369 -

Insufficient data validation in Mojo in Google Chrome prior to 129.0.6668.89 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)

📅 Published: Nov. 27, 2024, 5:50 p.m. 🔄 Last Modified: Nov. 20, 2025, 7:16 p.m.
Total resulsts: 349182
Page 7686 of 34,919
« previous page » next page
Filters