3.1

CVSS3.1

CVE-2024-4099 - Improper Encoding or Escaping of Output in GitLab

An issue has been discovered in GitLab EE affecting all versions starting from 16.0 prior to 17.2.8, from 17.3 prior to 17.3.4, and from 17.4 prior to 17.4.1. An AI feature was found to read unsanitized content in a way that could have allowed an attacker to hide prompt injection.

📅 Published: Sept. 26, 2024, 11:02 p.m. 🔄 Last Modified: Oct. 4, 2024, 5:33 p.m.

2.6

CVSS3.1

CVE-2024-8974 - Incorrect Provision of Specified Functionality in GitLab

Information disclosure in Gitlab EE/CE affecting all versions from 15.6 prior to 17.2.8, 17.3 prior to 17.3.4, and 17.4 prior to 17.4.1 in specific conditions it was possible to disclose to an unauthorised user the path of a private project."

📅 Published: Sept. 26, 2024, 11:02 p.m. 🔄 Last Modified: Oct. 4, 2024, 5:30 p.m.

0.0

CVE-2024-9268 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.

📅 Published: Sept. 26, 2024, 10:10 p.m. 🔄 Last Modified: Sept. 27, 2024, 5:15 p.m.

8.4

CVSS4.0

CVE-2024-6769 - Medium to High Integrity Privilege Escalation in Microsoft Windows

A DLL Hijacking caused by drive remapping combined with a poisoning of the activation cache in Microsoft Windows 10, Windows 11, Windows Server 2016, Windows Server 2019, and Windows Server 2022 allows a malicious authenticated attacker to elevate from a medium integrity process to a high integrity…

📅 Published: Sept. 26, 2024, 8:18 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-47176 - cups-browsed binds to `INADDR_ANY:631`, trusting any packet from any source

CUPS is a standards-based, open-source printing system, and `cups-browsed` contains network printing functionality including, but not limited to, auto-discovering print services and shared printers. `cups-browsed` binds to `INADDR_ANY:631`, causing it to trust any packet from any source, and can ca…

📅 Published: Sept. 26, 2024, 8 p.m. 🔄 Last Modified: Nov. 4, 2025, 10:16 p.m.

8.6

CVSS3.1

CVE-2024-47175 - libppd's ppdCreatePPDFromIPP2 function does not sanitize IPP attributes when creating the PPD buffer

CUPS is a standards-based, open-source printing system, and `libppd` can be used for legacy PPD file support. The `libppd` function `ppdCreatePPDFromIPP2` does not sanitize IPP attributes when creating the PPD buffer. When used in combination with other functions such as `cfGetPrinterAttributes5`, …

📅 Published: Sept. 26, 2024, 8 p.m. 🔄 Last Modified: Nov. 3, 2025, 11:16 p.m.

8.6

CVSS3.1

CVE-2024-47076 - libcupsfilters's cfGetPrinterAttributes5 does not validate IPP attributes returned from an IPP serv…

CUPS is a standards-based, open-source printing system, and `libcupsfilters` contains the code of the filters of the former `cups-filters` package as library functions to be used for the data format conversion tasks needed in Printer Applications. The `cfGetPrinterAttributes5` function in `libcupsf…

📅 Published: Sept. 26, 2024, 8 p.m. 🔄 Last Modified: Nov. 3, 2025, 11:16 p.m.

6.1

CVSS3.1

CVE-2024-47177 - cups-filters: foomatic: foomatic-rip in cups-filters allows arbitrary command execution via the Foo…

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-47076, CVE-2024-47175, CVE-2024-47176. Reason: This candidate is a duplicate of CVE-2024-47076, CVE-2024-47175, and CVE-2024-47176. Notes: All CVE users should reference CVE-2024-47076, CVE-2024-47175, and/or CVE-2024-47176 instead…

📅 Published: Sept. 26, 2024, 8 p.m. 🔄 Last Modified: May 12, 2025, 9:15 p.m.

7.5

CVSS3.1

CVE-2024-7594 - Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default

Vault’s SSH secrets engine did not require the valid_principals list to contain a value by default. If the valid_principals and default_user fields of the SSH secrets engine configuration are not set, an SSH certificate requested by an authorized user to Vault’s SSH secrets engine could be used to …

📅 Published: Sept. 26, 2024, 7:52 p.m. 🔄 Last Modified: Nov. 13, 2025, 5:51 p.m.

8.8

CVSS3.1

CVE-2024-47180 - Shields.io Remote Code Execution vulnerability in Dynamic JSON/TOML/YAML badges

Shields.io is a service for concise, consistent, and legible badges in SVG and raster format. Shields.io and users self-hosting their own instance of shields using version < `server-2024-09-25` are vulnerable to a remote execution vulnerability via the JSONPath library used by the Dynamic JSON/Toml…

📅 Published: Sept. 26, 2024, 7:21 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 8461 of 34,919
« previous page » next page
Filters