9.8

CVSS3.1

CVE-2024-41593 -

DrayTek Vigor310 devices through 4.3.2.6 allow a remote attacker to execute arbitrary code via the function ft_payload_dns(), because a byte sign-extension operation occurs for the length argument of a _memcpy call, leading to a heap-based Buffer Overflow.

๐Ÿ“… Published: Oct. 3, 2024, midnight ๐Ÿ”„ Last Modified: March 13, 2025, 7:15 p.m.

7.5

CVSS3.1

CVE-2024-41594 -

An issue in DrayTek Vigor310 devices through 4.3.2.6 allows an attacker to obtain sensitive information because the httpd server of the Vigor management UI uses a static string for seeding the PRNG of OpenSSL.

๐Ÿ“… Published: Oct. 3, 2024, midnight ๐Ÿ”„ Last Modified: March 19, 2025, 4:15 p.m.

6.3

CVSS3.1

CVE-2024-45872 -

Bandisoft BandiView 7.05 is vulnerable to Buffer Overflow via sub_0x410d1d. The vulnerability occurs due to insufficient validation of PSD files.

๐Ÿ“… Published: Oct. 3, 2024, midnight ๐Ÿ”„ Last Modified: April 28, 2025, 6 p.m.

6.3

CVSS3.1

CVE-2024-45871 -

Bandisoft BandiView 7.05 is Incorrect Access Control via sub_0x232bd8 resulting in denial of service (DOS).

๐Ÿ“… Published: Oct. 3, 2024, midnight ๐Ÿ”„ Last Modified: April 28, 2025, 6:05 p.m.

4.7

CVSS3.1

CVE-2024-41583 -

DrayTek Vigor3910 devices through 4.3.2.6 are vulnerable to stored Cross Site Scripting (XSS) by authenticated users due to poor sanitization of the router name.

๐Ÿ“… Published: Oct. 3, 2024, midnight ๐Ÿ”„ Last Modified: April 10, 2025, 6:15 p.m.

5.4

CVSS3.1

CVE-2024-41587 -

Stored XSS, by authenticated users, is caused by poor sanitization of the Login Page Greeting message in DrayTek Vigor310 devices through 4.3.2.6.

๐Ÿ“… Published: Oct. 3, 2024, midnight ๐Ÿ”„ Last Modified: March 18, 2025, 4:15 p.m.

8

CVSS3.1

CVE-2024-41590 -

Several CGI endpoints are vulnerable to buffer overflows, by authenticated users, because of missing bounds checking on parameters passed through POST requests to the strcpy function on DrayTek Vigor310 devices through 4.3.2.6.

๐Ÿ“… Published: Oct. 3, 2024, midnight ๐Ÿ”„ Last Modified: June 11, 2025, 1:49 p.m.

5.9

CVSS3.1

CVE-2024-34535 -

In Mastodon 4.1.6, API endpoint rate limiting can be bypassed by setting a crafted HTTP request header.

๐Ÿ“… Published: Oct. 3, 2024, midnight ๐Ÿ”„ Last Modified: May 6, 2025, 6:30 p.m.

8

CVSS3.1

CVE-2024-46658 -

Syrotech SY-GOPON-8OLT-L3 v1.6.0_240629 was discovered to contain an authenticated command injection vulnerability.

๐Ÿ“… Published: Oct. 3, 2024, midnight ๐Ÿ”„ Last Modified: Oct. 7, 2024, 7:37 p.m.

8

CVSS3.1

CVE-2024-41592 -

DrayTek Vigor3910 devices through 4.3.2.6 have a stack-based overflow when processing query string parameters because GetCGI mishandles extraneous ampersand characters and long key-value pairs.

๐Ÿ“… Published: Oct. 3, 2024, midnight ๐Ÿ”„ Last Modified: June 3, 2025, 1:52 p.m.
Total resulsts: 342251
Page 7720 of 34,226
ยซ previous page ยป next page
Filters