7.8

CVSS3.1

CVE-2024-46951 - ghostscript: Arbitrary Code Execution in Artifex Ghostscript Pattern Color Space

An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. An unchecked Implementation pointer in Pattern color space could lead to arbitrary code execution.

πŸ“… Published: Nov. 10, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 11:16 p.m.

4.3

CVSS3.1

CVE-2024-46613 -

WeeChat before 4.4.2 has an integer overflow and resultant buffer overflow at core/core-string.c when there are more than two billion items in a list. This affects string_free_split_shared , string_free_split, string_free_split_command, and string_free_split_tags.

πŸ“… Published: Nov. 10, 2024, midnight πŸ”„ Last Modified: Nov. 19, 2024, 9:35 p.m.

7.8

CVSS3.1

CVE-2024-46956 - ghostscript: Out-of-Bounds Data Access in Ghostscript Leads to Arbitrary Code Execution

An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code execution.

πŸ“… Published: Nov. 10, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 11:16 p.m.

5.5

CVSS3.1

CVE-2024-46955 - ghostscript: Out-of-Bounds Read in Ghostscript Indexed Color Space

An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. There is an out-of-bounds read when reading color in Indexed color space.

πŸ“… Published: Nov. 10, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 11:16 p.m.

9.1

CVSS3.1

CVE-2021-35473 -

An issue was discovered in LemonLDAP::NG before 2.0.12. There is a missing expiration check in the OAuth2.0 handler, i.e., it does not verify access token validity. An attacker can use a expired access token from an OIDC client to access the OAuth2 handler The earliest affected version is 2.0.4.

πŸ“… Published: Nov. 10, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2021-41737 -

In Faust 2.23.1, an input file with the lines "// r visualisation tCst" and "//process = +: L: abM-^Q;" and "process = route(3333333333333333333,2,1,2,3,1) : *;" leads to stack consumption.

πŸ“… Published: Nov. 10, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2020-10367 -

Certain Cypress (and Broadcom) Wireless Combo chips, when a January 2021 firmware update is not present, allow memory access via a "Spectra" attack.

πŸ“… Published: Nov. 10, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2020-10369 -

Certain Cypress (and Broadcom) Wireless Combo chips, when a January 2021 firmware update is not present, allow inferences about memory content via a "Spectra" attack.

πŸ“… Published: Nov. 10, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2024-46953 - ghostscript: Path Traversal and Code Execution via Integer Overflow in Ghostscript

An issue was discovered in base/gsdevice.c in Artifex Ghostscript before 10.04.0. An integer overflow when parsing the filename format string (for the output filename) results in path truncation, and possible path traversal and code execution.

πŸ“… Published: Nov. 10, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 11:16 p.m.

4.3

CVSS3.1

CVE-2024-52032 - Private channel names leaking when Elasticsearch is enabled

Mattermost versions 10.0.x <= 10.0.0 and 9.11.x <= 9.11.2 fail to properly query ElasticSearch whenΒ searching for the channel name in channel switcherΒ which allows an attacker to get private channels names of channels that they are not a member of,Β when Elasticsearch v8 was enabled.

πŸ“… Published: Nov. 9, 2024, 5:19 p.m. πŸ”„ Last Modified: Nov. 14, 2024, 4:47 p.m.
Total resulsts: 349182
Page 7957 of 34,919
Β« previous page Β» next page
Filters