7.8

CVSS3.1

CVE-2024-8272 - macOS Universal Audio (UAConnect) <= 2.7.0 - Local Privilege Escalation

The com.uaudio.bsd.helper service, responsible for handling privileged operations, fails to implement critical client validation during XPC inter-process communication (IPC). Specifically, the service does not verify the code requirements, entitlements, or security flags of any client attempting to…

📅 Published: Nov. 25, 2024, 5:52 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2024-7915 - macOS Sensei Mac Cleaner Local Privilege Escalation via PID Reuse - Race Condition Attack

The application Sensei Mac Cleaner contains a local privilege escalation vulnerability, allowing an attacker to perform multiple operations as the root user. These operations include arbitrary file deletion and writing, loading and unloading daemons, manipulating file permissions, and loading exten…

📅 Published: Nov. 25, 2024, 5:45 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-11738 - Rustls: rustls network-reachable panic in `acceptor::accept`

A flaw was found in Rustls 0.23.13 and related APIs. This vulnerability allows denial of service (panic) via a fragmented TLS ClientHello message.

📅 Published: Nov. 25, 2024, 4:57 p.m. 🔄 Last Modified: Nov. 20, 2025, 6:22 p.m.

5.3

CVSS3.1

CVE-2023-26280 - IBM Jazz Foundation improper access control

IBM Jazz Foundation 7.0.2 and 7.0.3 could allow a user to change their dashboard using a specially crafted HTTP request due to improper access control.

📅 Published: Nov. 25, 2024, 3:51 p.m. 🔄 Last Modified: Jan. 16, 2025, 4:13 p.m.

6.1

CVSS3.1

CVE-2023-45181 - IBM Jazz Foundation cross-site scripting

IBM Jazz Foundation 7.0.2 and below are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

📅 Published: Nov. 25, 2024, 3:48 p.m. 🔄 Last Modified: Jan. 14, 2025, 7:46 p.m.

5.4

CVSS3.1

CVE-2024-11670 -

Incorrect authorization in the permission validation component of Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows a malicious authenticated user to bypass the "View Password" permission via specific actions.

📅 Published: Nov. 25, 2024, 2:46 p.m. 🔄 Last Modified: March 28, 2025, 4:22 p.m.

5.4

CVSS3.1

CVE-2024-11671 -

Improper authentication in SQL data source MFA validation in Devolutions Remote Desktop Manager 2024.3.17 and earlier on Windows allows an authenticated user to bypass the MFA validation via data source switching.

📅 Published: Nov. 25, 2024, 2:46 p.m. 🔄 Last Modified: March 28, 2025, 4:21 p.m.

4.3

CVSS3.1

CVE-2024-11672 -

Incorrect authorization in the add permission component in Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows an authenticated malicious user to bypass the "Add" permission via the import in vault feature.

📅 Published: Nov. 25, 2024, 2:46 p.m. 🔄 Last Modified: March 28, 2025, 4:21 p.m.

7

CVSS3.1

CVE-2024-27134 - Excessive directory permissions in MLflow leads to local privilege escalation when using spark_udf

Excessive directory permissions in MLflow leads to local privilege escalation when using spark_udf. This behavior can be exploited by a local attacker to gain elevated permissions by using a ToCToU attack. The issue is only relevant when the spark_udf() MLflow API is called.

📅 Published: Nov. 25, 2024, 1:48 p.m. 🔄 Last Modified: Feb. 3, 2025, 3:05 p.m.

6.9

CVSS4.0

CVE-2024-11403 - Out of Bounds Memory Read/Write in libjxl

There exists an out of bounds read/write in LibJXL versions prior to commit 9cc451b91b74ba470fd72bd48c121e9f33d24c99. The JPEG decoder used by the JPEG XL encoder when doing JPEG recompression (i.e. if using JxlEncoderAddJPEGFrame on untrusted input) does not properly check bounds in the presence o…

📅 Published: Nov. 25, 2024, 1:08 p.m. 🔄 Last Modified: July 24, 2025, 1:25 p.m.
Total resulsts: 349182
Page 7709 of 34,919
« previous page » next page
Filters