4.3
CVE-2024-7001 - chromium-browser: Inappropriate implementation in HTML
Inappropriate implementation in HTML in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
10
CVE-2024-41110 - Moby authz zero length regression
Moby is an open-source project created by Docker for software containerization. A security vulnerability has been detected in certain versions of Docker Engine, which could allow an attacker to bypass authorization plugins (AuthZ) under specific circumstances. The base likelihood of this being explβ¦
7.5
CVE-2024-40060 -
go-chart v2.1.1 was discovered to contain an infinite loop via the drawCanvas() function.
4.3
CVE-2024-7004 - chromium-browser: Insufficient validation of untrusted input in Safe Browsing
Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 127.0.6533.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass discretionary access control via a malicious file. (Chromium security severity: Low)
8.8
CVE-2024-6991 - chromium-browser: Use after free in Dawn
Use after free in Dawn in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
5.9
CVE-2024-39702 - OpenResty: Hashing function allows HashDoS (Hash Denial of Service) attacks
In lj_str_hash.c in OpenResty 1.19.3.1 through 1.25.3.1, the string hashing function (used during string interning) allows HashDoS (Hash Denial of Service) attacks. An attacker could cause excessive resource usage during proxy operations via crafted requests, potentially leading to a denial of servβ¦
6.3
CVE-2024-41012 - filelock: Remove locks reliably when fcntl/close race is detected
In the Linux kernel, the following vulnerability has been resolved: filelock: Remove locks reliably when fcntl/close race is detected When fcntl_setlk() races with close(), it removes the created lock with do_lock_file_wait(). However, LSMs can allow the first do_lock_file_wait() that created theβ¦
8.8
CVE-2024-41319 -
TOTOLINK A6000R V1.0.1-B20201211.2000 was discovered to contain a command injection vulnerability via the cmd parameter in the webcmd function.
9.8
CVE-2024-6806 - Missing Authorization Checks In NI VeriStand Gateway For Project Resources
The NI VeriStand Gateway is missing authorization checks when an actor attempts to access Project resources. These missing checks may result in remote code execution. This affects NI VeriStand 2024 Q2 and prior versions.
7.5
CVE-2024-6805 - Missing Authorization Checks in NI VeriStand Gateway for File Transfer Resources
The NI VeriStand Gateway is missing authorization checks when an actor attempts to access File Transfer resources. These missing checks may result in information disclosure or remote code execution. This affects NI VeriStand 2024 Q2 and prior versions.