7.8
CVE-2024-50124 - Bluetooth: ISO: Fix UAF on iso_sock_timeout
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: Fix UAF on iso_sock_timeout conn->sk maybe have been unlinked/freed while waiting for iso_conn_lock so this checks if the conn->sk is still valid by checking if it part of iso_sk_list.
5.5
CVE-2024-50118 - btrfs: reject ro->rw reconfiguration if there are hard ro requirements
In the Linux kernel, the following vulnerability has been resolved: btrfs: reject ro->rw reconfiguration if there are hard ro requirements [BUG] Syzbot reports the following crash: BTRFS info (device loop0 state MCS): disabling free space tree BTRFS info (device loop0 state MCS): clearing coβ¦
7.8
CVE-2024-49522 - Substance3D - Painter | Out-of-bounds Write (CWE-787)
Substance3D - Painter versions 10.0.1 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
7.5
CVE-2024-9579 - Certain Poly Video Conference Devices β Potential Remote Code Execution
A potential vulnerability was discovered in certain Poly video conferencing devices. The firmware flaw does not properly sanitize user input. The exploitation of this vulnerability is dependent on a layered attack and cannot be exploited by itself.
4.2
CVE-2023-29126 - Insecure loose comparison in Enel X JuiceBox
The Waybox Enel X web management application contains a PHP-type juggling vulnerability that may allow a brute force process and under certain conditions bypass authentication.
9
CVE-2023-29125 - Heap overflow in CM_main.exe binary in Enel X JuiceBox
A heap buffer overflow could be triggered by sending a specific packet to TCP port 7700.
6.7
CVE-2023-29122 - Incorrect file ownership of privileged service's libraries in Enel X JuiceBox
Under certain conditions, access to service libraries is granted to account they should not have access to.
9.6
CVE-2023-29121 - Exposed TCF agent service in Enel X Juicebox
Waybox Enel TCF Agent service could be used to get administratorβs privileges over the Waybox system.
9.6
CVE-2023-29120 - Unauthorized Remote Command Execution in Enel X Juicebox
Waybox Enel X web management application could be used to execute arbitrary OS commands and provide administratorβs privileges over the Waybox system.
9.6
CVE-2023-29119 - Unauthorized SQLite Injection
Waybox Enel X web management application could execute arbitrary requests on the internal database viaΒ /admin/dbstore.php.