2.1

CVSS4.0

CVE-2024-7867 - Integer overflow and divide-by-zero in Xpdf 4.05 due to bogus page box coordinates

In Xpdf 4.05 (and earlier), very large coordinates in a page box can cause an integer overflow and divide-by-zero.

πŸ“… Published: Aug. 15, 2024, 8:06 p.m. πŸ”„ Last Modified: Aug. 28, 2024, 9:59 p.m.

6.9

CVSS4.0

CVE-2024-7838 - itsourcecode Online Food Ordering System addcategory.php sql injection

A vulnerability was found in itsourcecode Online Food Ordering System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /addcategory.php. The manipulation of the argument cname leads to sql injection. The attack may be launched remotely. The exploi…

πŸ“… Published: Aug. 15, 2024, 8 p.m. πŸ”„ Last Modified: Aug. 20, 2024, 7:16 p.m.

2.1

CVSS4.0

CVE-2024-7866 - Stack overflow in Xpdf 4.05 due to object loop in PDF pattern

In Xpdf 4.05 (and earlier), a PDF object loop in a pattern resource leads to infinite recursion and a stack overflow.

πŸ“… Published: Aug. 15, 2024, 7:50 p.m. πŸ”„ Last Modified: Aug. 20, 2024, 7:23 p.m.

0.0

CVE-2024-7865 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2023-2414. Reason: This candidate is a reservation duplicate of CVE-2023-2414. Notes: All CVE users should reference CVE-2023-2414 instead of this candidate. All references and descriptions in this candidate have been removed to prevent…

πŸ“… Published: Aug. 15, 2024, 7:36 p.m. πŸ”„ Last Modified: Nov. 15, 2024, 4:15 p.m.

6.5

CVSS3.1

CVE-2024-42476 - oauth CSRF vulnerability

In the OAuth library for nim prior to version 0.11, the Authorization Code grant and Implicit grant both rely on the `state` parameter to prevent cross-site request forgery (CSRF) attacks where a resource owner might have their session associated with protected resources belonging to an attacker. W…

πŸ“… Published: Aug. 15, 2024, 6:48 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-42475 - OAuth library for nim allows insecure generation of state values by generateState - entropy too low…

In the OAuth library for nim prior to version 0.11, the `state` values generated by the `generateState` function do not have sufficient entropy. These can be successfully guessed by an attacker allowing them to perform a CSRF vs a user, associating the user's session with the attacker's protected r…

πŸ“… Published: Aug. 15, 2024, 6:40 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS3.1

CVE-2024-43357 - JavaScript specification issue may lead to type confusion and pointer dereference in implementations

ECMA-262 is the language specification for the scripting language ECMAScript. A problem in the ECMAScript (JavaScript) specification of async generators, introduced by a May 2021 spec refactor, may lead to mis-implementation in a way that could present as a security vulnerability, such as type conf…

πŸ“… Published: Aug. 15, 2024, 6:36 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-25633 - In eLabFTW, if administrators can create users, users can too

eLabFTW is an open source electronic lab notebook for research labs. In an eLabFTW system, one can configure who is allowed to create new user accounts. A vulnerability has been found starting in version 4.4.0 and prior to version 5.0.0 that allows regular users to create new, validated accounts in…

πŸ“… Published: Aug. 15, 2024, 6:23 p.m. πŸ”„ Last Modified: Aug. 19, 2025, 3:17 p.m.

5.9

CVSS3.1

CVE-2024-31905 - IBM QRadar Network Packet Capture information disclosure

IBM QRadar Network Packet Capture 7.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques.

πŸ“… Published: Aug. 15, 2024, 4:56 p.m. πŸ”„ Last Modified: Sept. 29, 2025, 3:16 p.m.

6.5

CVSS3.1

CVE-2024-40705 - IBM InfoSphere Information Server denial of service

IBM InfoSphere Information Server could allow an authenticated user to consume file space resources due to unrestricted file uploads. IBM X-Force ID: 298279.

πŸ“… Published: Aug. 15, 2024, 4:48 p.m. πŸ”„ Last Modified: Aug. 19, 2024, 8:35 p.m.
Total resulsts: 349182
Page 8836 of 34,919
Β« previous page Β» next page
Filters