2.6

CVSS3.1

CVE-2024-1656 -

Affected versions of Octopus Server had a weak content security policy.

πŸ“… Published: Sept. 11, 2024, 4:05 a.m. πŸ”„ Last Modified: July 2, 2025, 5:26 p.m.

8

CVSS3.1

CVE-2024-43690 -

Inclusion of Functionality from Untrusted Control Sphere(CWE-829) in the Command Centre Server and Workstations may allow an attacker to perform Remote Code Execution (RCE). This issue affects: Command Centre Server and Command Centre WorkstationsΒ 9.10 prior to vEL9.10.1530 (MR2), 9.00 prior to vE…

πŸ“… Published: Sept. 11, 2024, 4:04 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.6

CVSS3.1

CVE-2024-39808 -

Incorrect Calculation of Buffer Size (CWE-131) in the Controller 6000 and Controller 7000 OSDP message handling, allows an attacker with physical access to Controller wiring to instigate a reboot leading to a denial of service. This issue affects: Controller 6000 and Controller 7000 9.10 prior …

πŸ“… Published: Sept. 11, 2024, 4:03 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-24972 -

Buffer Copy without Checking Size of Input (CWE-120) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authorised and authenticated operator to reboot the Controller, causing a Denial of Service. Gallagher recommend the diagnostic web page is not enabled (default is off)…

πŸ“… Published: Sept. 11, 2024, 4:03 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-23906 -

Improper Neutralization of Input During Web Page Generation (CWE-79) in the Controller 6000 and Controller 7000 diagnostic webpage allows an attacker to modify Controller configuration during an authenticated Operator's session. This issue affects: Controller 6000 and Controller 7000 9.10 pri…

πŸ“… Published: Sept. 11, 2024, 4:02 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-8253 - Post Grid and Gutenberg Blocks 2.2.87 - 2.2.90 - Authenticated (Subscriber+) Privilege Escalation

The Post Grid and Gutenberg Blocks plugin for WordPress is vulnerable to privilege escalation in all versions 2.2.87 to 2.2.90. This is due to the plugin not properly restricting what user meta values can be updated and ensuring a form is active. This makes it possible for authenticated attackers, …

πŸ“… Published: Sept. 11, 2024, 3:31 a.m. πŸ”„ Last Modified: Sept. 25, 2024, 7:42 p.m.

7.8

CVSS3.1

CVE-2024-40662 -

In scheme of Uri.java, there is a possible way to craft a malformed Uri object due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

πŸ“… Published: Sept. 11, 2024, 12:09 a.m. πŸ”„ Last Modified: Dec. 17, 2024, 7:07 p.m.

5.5

CVSS3.1

CVE-2024-40659 -

In getRegistration of RemoteProvisioningService.java, there is a possible way to permanently disable the AndroidKeyStore key generation feature by updating the attestation keys of all installed apps due to improper input validation. This could lead to local denial of service with no additional exec…

πŸ“… Published: Sept. 11, 2024, 12:09 a.m. πŸ”„ Last Modified: Dec. 17, 2024, 7:07 p.m.

7.8

CVSS3.1

CVE-2024-40658 -

In getConfig of SoftVideoDecoderOMXComponent.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

πŸ“… Published: Sept. 11, 2024, 12:09 a.m. πŸ”„ Last Modified: Dec. 17, 2024, 7:07 p.m.

7.8

CVSS3.1

CVE-2024-40657 -

In addPreferencesForType of AccountTypePreferenceLoader.java, there is a possible way to disable apps for other users due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

πŸ“… Published: Sept. 11, 2024, 12:09 a.m. πŸ”„ Last Modified: Dec. 17, 2024, 7:10 p.m.
Total resulsts: 349182
Page 8599 of 34,919
Β« previous page Β» next page
Filters