7.8

CVSS3.1

CVE-2024-50124 - Bluetooth: ISO: Fix UAF on iso_sock_timeout

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: Fix UAF on iso_sock_timeout conn->sk maybe have been unlinked/freed while waiting for iso_conn_lock so this checks if the conn->sk is still valid by checking if it part of iso_sk_list.

πŸ“… Published: Nov. 5, 2024, 5:10 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 11:16 p.m.

5.5

CVSS3.1

CVE-2024-50118 - btrfs: reject ro->rw reconfiguration if there are hard ro requirements

In the Linux kernel, the following vulnerability has been resolved: btrfs: reject ro->rw reconfiguration if there are hard ro requirements [BUG] Syzbot reports the following crash: BTRFS info (device loop0 state MCS): disabling free space tree BTRFS info (device loop0 state MCS): clearing co…

πŸ“… Published: Nov. 5, 2024, 5:10 p.m. πŸ”„ Last Modified: Oct. 1, 2025, 9:15 p.m.

7.8

CVSS3.1

CVE-2024-49522 - Substance3D - Painter | Out-of-bounds Write (CWE-787)

Substance3D - Painter versions 10.0.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

πŸ“… Published: Nov. 5, 2024, 4:59 p.m. πŸ”„ Last Modified: Nov. 8, 2024, 6:06 p.m.

7.5

CVSS3.1

CVE-2024-9579 - Certain Poly Video Conference Devices – Potential Remote Code Execution

A potential vulnerability was discovered in certain Poly video conferencing devices. The firmware flaw does not properly sanitize user input. The exploitation of this vulnerability is dependent on a layered attack and cannot be exploited by itself.

πŸ“… Published: Nov. 5, 2024, 4:22 p.m. πŸ”„ Last Modified: Nov. 8, 2024, 6:08 p.m.

4.2

CVSS3.1

CVE-2023-29126 - Insecure loose comparison in Enel X JuiceBox

The Waybox Enel X web management application contains a PHP-type juggling vulnerability that may allow a brute force process and under certain conditions bypass authentication.

πŸ“… Published: Nov. 5, 2024, 3:28 p.m. πŸ”„ Last Modified: Nov. 8, 2024, 4:15 p.m.

9

CVSS3.1

CVE-2023-29125 - Heap overflow in CM_main.exe binary in Enel X JuiceBox

A heap buffer overflow could be triggered by sending a specific packet to TCP port 7700.

πŸ“… Published: Nov. 5, 2024, 3:27 p.m. πŸ”„ Last Modified: Nov. 8, 2024, 4:10 p.m.

6.7

CVSS3.1

CVE-2023-29122 - Incorrect file ownership of privileged service's libraries in Enel X JuiceBox

Under certain conditions, access to service libraries is granted to account they should not have access to.

πŸ“… Published: Nov. 5, 2024, 3:24 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.6

CVSS3.1

CVE-2023-29121 - Exposed TCF agent service in Enel X Juicebox

Waybox Enel TCF Agent service could be used to get administrator’s privileges over the Waybox system.

πŸ“… Published: Nov. 5, 2024, 3:23 p.m. πŸ”„ Last Modified: Nov. 8, 2024, 4:09 p.m.

9.6

CVSS3.1

CVE-2023-29120 - Unauthorized Remote Command Execution in Enel X Juicebox

Waybox Enel X web management application could be used to execute arbitrary OS commands and provide administrator’s privileges over the Waybox system.

πŸ“… Published: Nov. 5, 2024, 3:22 p.m. πŸ”„ Last Modified: Nov. 8, 2024, 4:09 p.m.

9.6

CVSS3.1

CVE-2023-29119 - Unauthorized SQLite Injection

Waybox Enel X web management application could execute arbitrary requests on the internal database viaΒ /admin/dbstore.php.

πŸ“… Published: Nov. 5, 2024, 3:20 p.m. πŸ”„ Last Modified: Nov. 8, 2024, 4:09 p.m.
Total resulsts: 349182
Page 8013 of 34,919
Β« previous page Β» next page
Filters