7.8

CVSS3.1

CVE-2024-20087 -

In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08932916; Issue ID: MSV-1550.

πŸ“… Published: Sept. 2, 2024, 2:07 a.m. πŸ”„ Last Modified: Sept. 5, 2024, 2:26 p.m.

7.8

CVSS3.1

CVE-2024-20086 -

In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08932916; Issue ID: MSV-1551.

πŸ“… Published: Sept. 2, 2024, 2:07 a.m. πŸ”„ Last Modified: Sept. 5, 2024, 2:26 p.m.

4.4

CVSS3.1

CVE-2024-20085 -

In power, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08944204; Issue ID: MSV-1560.

πŸ“… Published: Sept. 2, 2024, 2:07 a.m. πŸ”„ Last Modified: Oct. 27, 2024, 3:35 a.m.

4.4

CVSS3.1

CVE-2024-20084 -

In power, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08944210; Issue ID: MSV-1561.

πŸ“… Published: Sept. 2, 2024, 2:07 a.m. πŸ”„ Last Modified: Oct. 27, 2024, 3:35 a.m.

6.2

CVSS3.1

CVE-2024-8365 - Vault Leaks AppRole Client Tokens And Accessor in Audit Log

Vault Community Edition and Vault Enterprise experienced a regression where functionality that HMAC’d sensitive headers in the configured audit device, specifically client tokens and token accessors, was removed. This resulted in the plaintext values of client tokens and token accessors being store…

πŸ“… Published: Sept. 2, 2024, 1:30 a.m. πŸ”„ Last Modified: Sept. 4, 2024, 5:18 p.m.

5.4

CVSS3.1

CVE-2024-45528 -

CodeAstro MembershipM-PHP (aka Membership Management System in PHP) 1.0 allows add_members.php fullname stored XSS.

πŸ“… Published: Sept. 2, 2024, midnight πŸ”„ Last Modified: March 31, 2025, 6:53 p.m.

9.8

CVSS3.1

CVE-2024-45623 -

D-Link DAP-2310 Hardware A Firmware 1.16RC028 allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the ATP binary that handles PHP HTTP GET requests for the Apache HTTP Server (httpd). NOTE: This vulnerability only affects products that are no longer supported by t…

πŸ“… Published: Sept. 2, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.9

CVSS3.1

CVE-2024-45616 - Libopensc: uninitialized values after incorrect check or usage of apdu response values in libopensc

A vulnerability was found in OpenSC, OpenSC tools, PKCS#11 module, minidriver, and CTK. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. The following problems were caused by insufficient control of the response A…

πŸ“… Published: Sept. 2, 2024, midnight πŸ”„ Last Modified: Nov. 7, 2025, 12:29 a.m.

6.1

CVSS3.1

CVE-2024-45527 -

REDCap 14.7.0 allows HTML injection via the project title of a New Project action. This can lead to resultant logout CSRF via index.php?logout=1, and can also be used to insert a link to an external phishing website.

πŸ“… Published: Sept. 2, 2024, midnight πŸ”„ Last Modified: April 30, 2025, 4:44 p.m.

3.9

CVSS3.1

CVE-2024-45620 - Libopensc: incorrect handling of the length of buffers or files in pkcs15init

A vulnerability was found in the pkcs15-init tool in OpenSC. An attacker could use a crafted USB Device or Smart Card, which would present the system with a specially crafted response to APDUs. When buffers are partially filled with data, initialized parts of the buffer can be incorrectly accessed.

πŸ“… Published: Sept. 2, 2024, midnight πŸ”„ Last Modified: Nov. 7, 2025, 12:29 a.m.
Total resulsts: 349182
Page 8687 of 34,919
Β« previous page Β» next page
Filters