6.7

CVSS3.1

CVE-2024-23374 - Stack-based Buffer Overflow in Power Management IC

Memory corruption is possible when an attempt is made from userspace or console to write some haptics effects pattern to the haptics debugfs file.

πŸ“… Published: Oct. 7, 2024, 12:58 p.m. πŸ”„ Last Modified: Oct. 16, 2024, 8:26 p.m.

6.7

CVSS3.1

CVE-2024-23370 - Use After Free in Automotive Multimedia

Memory corruption when a process invokes IOCTL calls from user-space to create a HAB virtual channel and another process invokes IOCTL calls to destroy the same.

πŸ“… Published: Oct. 7, 2024, 12:58 p.m. πŸ”„ Last Modified: Oct. 16, 2024, 8:27 p.m.

7.8

CVSS3.1

CVE-2024-23369 - Improper Restriction of Operations within the Bounds of a Memory Buffer in HLOS

Memory corruption when invalid length is provided from HLOS for FRS/UDS request/response buffers.

πŸ“… Published: Oct. 7, 2024, 12:58 p.m. πŸ”„ Last Modified: Aug. 11, 2025, 3:06 p.m.

7.8

CVSS3.1

CVE-2024-21455 - Untrusted Pointer Dereference in DSP Service

Memory corruption when a compat IOCTL call is followed by another IOCTL call from userspace to a driver.

πŸ“… Published: Oct. 7, 2024, 12:58 p.m. πŸ”„ Last Modified: Aug. 11, 2025, 3:06 p.m.

6.7

CVSS3.1

CVE-2024-42027 -

The E2EE password entropy generated by Rocket.Chat Mobile prior to version 4.5.1 is insufficient, allowing attackers to crack it if they have the appropriate time and resources.

πŸ“… Published: Oct. 7, 2024, 12:46 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-45153 - Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Experience Manager versions 6.5.20 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they brow…

πŸ“… Published: Oct. 7, 2024, 12:14 p.m. πŸ”„ Last Modified: Dec. 2, 2024, 10:44 p.m.

5.3

CVSS3.1

CVE-2024-47344 - WordPress uListing plugin <= 2.1.5 - Sensitive Data Exposure vulnerability

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Stylemix uListing ulisting.This issue affects uListing: from n/a through <= 2.1.5.

πŸ“… Published: Oct. 7, 2024, 5:34 a.m. πŸ”„ Last Modified: April 23, 2026, 3:19 p.m.

7.6

CVSS3.1

CVE-2024-47335 - WordPress Bit Form plugin <= 2.13.11 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Bit Apps Bit Form bit-form allows SQL Injection.This issue affects Bit Form: from n/a through <= 2.13.11.

πŸ“… Published: Oct. 7, 2024, 5:31 a.m. πŸ”„ Last Modified: April 23, 2026, 3:19 p.m.

4.9

CVSS3.1

CVE-2024-20102 -

In wlan driver, there is a possible out of bounds read due to improper input validation. This could lead to remote information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08998892; Issue ID: MSV-1601.

πŸ“… Published: Oct. 7, 2024, 2:35 a.m. πŸ”„ Last Modified: March 13, 2025, 7:15 p.m.

6.7

CVSS3.1

CVE-2024-20099 -

In power, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08997492; Issue ID: MSV-1625.

πŸ“… Published: Oct. 7, 2024, 2:35 a.m. πŸ”„ Last Modified: April 25, 2025, 6:37 p.m.
Total resulsts: 349182
Page 8378 of 34,919
Β« previous page Β» next page
Filters