9.8
CVE-2024-39685 - fishaudio/Bert-VITS2 Command Injection in webui_preprocess.py resample function
Bert-VITS2 is the VITS2 Backbone with multilingual bert. User input supplied to the data_dir variable is used directly in a command executed with subprocess.run(cmd, shell=True) in the resample function, which leads to arbitrary command execution. This affects fishaudio/Bert-VITS2 2.3 and earlier.
3.5
CVE-2024-41829 -
In JetBrains TeamCity before 2024.07 an OAuth code for JetBrains Space could be stolen via Space Application connection
2.6
CVE-2024-41828 -
In JetBrains TeamCity before 2024.07 comparison of authorization tokens took non-constant time
7.4
CVE-2024-41827 -
In JetBrains TeamCity before 2024.07 access tokens could continue working after deletion or expiration
3.5
CVE-2024-41826 -
In JetBrains TeamCity before 2024.07 stored XSS was possible on Show Connection page
4.6
CVE-2024-41825 -
In JetBrains TeamCity before 2024.07 stored XSS was possible on the Code Inspection tab
6.4
CVE-2024-41824 -
In JetBrains TeamCity before 2024.07 parameters of the "password" type could leak into the build log in some specific cases
5.3
CVE-2024-41132 - SixLabors ImageSharp Allows Excessive Memory Allocation in Gif Decoder
ImageSharp is a 2D graphics API. A vulnerability discovered in the ImageSharp library, where the processing of specially crafted files can lead to excessive memory usage in the Gif decoder. The vulnerability is triggered when ImageSharp attempts to process image files that are designed to exploit tβ¦
7.5
CVE-2024-41131 - Out-of-bounds Write in SixLabors ImageSharp
ImageSharp is a 2D graphics API. An Out-of-bounds Write vulnerability has been found in the ImageSharp gif decoder, allowing attackers to cause a crash using a specially crafted gif. This can potentially lead to denial of service. All users are advised to upgrade to v3.1.5 or v2.1.9.
5.3
CVE-2024-29073 -
An vulnerability in the handling of Latex exists in Ankitects Anki 24.04. When Latex is sanitized to prevent unsafe commands, the verbatim package, which comes installed by default in many Latex distributions, has been overlooked. A specially crafted flashcard can lead to an arbitrary file read. Anβ¦