7.7
CVE-2024-37179 - Insecure File Operations vulnerability in SAP BusinessObjects Business Intelligence Platform (Web Iβ¦
SAP BusinessObjects Business Intelligence Platform allows an authenticated user to send a specially crafted request to the Web Intelligence Reporting Server to download any file from the machine hosting the service, causing high impact on confidentiality of the application.
3.3
CVE-2024-45382 - Liteos_a has an Out-of-bounds Write vulnerability
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS through out-of-bounds write.
3.3
CVE-2024-43697 - Liteos_a has an Improper Input Validation vulnerability
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS through improper input.
3.3
CVE-2024-43696 - Liteos_a has an Memory Leak vulnerability
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS by memory leak.
4.4
CVE-2024-39831 - AccessTokenManager has an use after free vulnerability
in OpenHarmony v4.1.0 allow a local attacker with high privileges arbitrary code execution in pre-installed apps through use after free.
5.5
CVE-2024-39806 - Liteos_a has an out-of-bounds Read vulnerability
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read.
8.1
CVE-2024-38229 - .NET and Visual Studio Remote Code Execution Vulnerability
.NET and Visual Studio Remote Code Execution Vulnerability
7.5
CVE-2024-43483 - .NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
5.3
CVE-2024-9622 - Resteasy-netty4-cdi: resteasy-netty4: resteasy-reactor-netty: http request smuggling leading to cliβ¦
A vulnerability was found in the resteasy-netty4 library arising from improper handling of HTTP requests using smuggling techniques. When an HTTP smuggling request with an ASCII control character is sent, it causes the Netty HttpObjectDecoder to transition into a BAD_MESSAGE state. As a result, anyβ¦
9.8
CVE-2024-44349 -
A SQL injection vulnerability in login portal in AnteeoWMS before v4.7.34 allows unauthenticated attackers to execute arbitrary SQL commands via the username parameter and disclosure of some data in the underlying DB.