3.7
CVE-2024-45403 - H2O assertion failure when HTTP/3 requests are cancelled
h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. When h2o is configured as a reverse proxy and HTTP/3 requests are cancelled by the client, h2o might crash due to an assertion failure. The crash can be exploited by an attacker to mount a Denial-of-Service attack. By default, the β¦
5.9
CVE-2024-45397 - H2O alllows bypassing address-based access control with 0-RTT
h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. When an HTTP request using TLS/1.3 early data on top of TCP Fast Open or QUIC 0-RTT packets is received and the IP-address-based access control is used, the access control does not detect and prohibit HTTP requests conveyed by packβ¦
0.0
CVE-2024-9869 -
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.
3.1
CVE-2024-25622 - H2O ignores headers configuration directives
h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. The configuration directives provided by the headers handler allows users to modify the response headers being sent by h2o. The configuration file of h2o has scopes, and the inner scopes (e.g., path level) are expected to inherit tβ¦
8.4
CVE-2024-8755 - Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Coβ¦
Improper Input Validation vulnerability of Authenticated User in Progress LoadMaster allows : OS Command Injection.This issue affects: β―Product Affected Versions LoadMaster From 7.2.55.0 to 7.2.60.1 (inclusive) β―Β From 7.2.49.0 to 7.2.54.12 (inclusive) β―Β β¦
5.9
CVE-2024-8530 -
CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause exposure of private data when an already generated βlogcapturesβ archive is accessed directly by HTTPS.
6.5
CVE-2024-6657 - BLE peripheral DoS after few cycles of connect/disconnects
A denial of service may be caused to a single peripheral device in a BLE network when multiple central devices continuously connect and disconnect to the peripheral. A hard reset is required to recover the peripheral device.
7.2
CVE-2024-8531 -
CWE-347: Improper Verification of Cryptographic Signature vulnerability exists that could compromise the Data Center Expert software when an upgrade bundle is manipulated to include arbitrary bash scripts that are executed as root.
7.8
CVE-2024-9002 -
CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentiality, integrity, and availability of the workstation when non-admin authenticated user tries to perform privilege escalation by tampering with the binaries
5.1
CVE-2024-9856 - 07FLYCMS/07FLY-CMS/07FlyCRM System Settings Page cross site scripting
A vulnerability was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM 1.3.8. It has been rated as problematic. Affected by this issue is some unknown functionality of the component System Settings Page. The manipulation of the argument Login Interface Copyright leads to cross site scripting. The attack mayβ¦