9.8

CVSS3.1

CVE-2024-38439 -

Netatalk before 3.2.1 has an off-by-one error and resultant heap-based buffer overflow because of setting ibuf[PASSWDLEN] to '\0' in FPLoginExt in login in etc/uams/uams_pam.c. 2.4.1 and 3.1.19 are also fixed versions.

๐Ÿ“… Published: June 16, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 3, 2025, 10:17 p.m.

9.8

CVSS3.1

CVE-2024-38468 -

Shenzhen Guoxin Synthesis image system before 8.3.0 allows unauthorized password resets via the resetPassword API.

๐Ÿ“… Published: June 16, 2024, midnight ๐Ÿ”„ Last Modified: March 26, 2025, 4:15 p.m.

4

CVSS3.1

CVE-2024-38465 -

Shenzhen Guoxin Synthesis image system before 8.3.0 allows username enumeration because of the response discrepancy of incorrect versus error.

๐Ÿ“… Published: June 16, 2024, midnight ๐Ÿ”„ Last Modified: March 14, 2025, 1:15 a.m.

7.5

CVSS3.1

CVE-2024-38461 -

irodsServerMonPerf in iRODS before 4.3.2 attempts to proceed with use of a path even if it is not a directory.

๐Ÿ“… Published: June 16, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 21, 2024, 9:25 a.m.

9.1

CVSS3.1

CVE-2024-38448 -

htags in GNU Global through 6.6.12 allows code execution in situations where dbpath (aka -d) is untrusted, because shell metacharacters may be used.

๐Ÿ“… Published: June 16, 2024, midnight ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-38458 -

Xenforo before 2.2.16 allows code injection.

๐Ÿ“… Published: June 16, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 21, 2024, 9:25 a.m.

9.8

CVSS3.1

CVE-2024-38466 -

Shenzhen Guoxin Synthesis image system before 8.3.0 has a 123456Qw default password.

๐Ÿ“… Published: June 16, 2024, midnight ๐Ÿ”„ Last Modified: March 19, 2025, 8:15 p.m.

6.5

CVSS3.1

CVE-2023-27636 -

Progress Sitefinity before 15.0.0 allows XSS by authenticated users via the content form in the SF Editor.

๐Ÿ“… Published: June 16, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 21, 2024, 7:53 a.m.

7.5

CVSS3.1

CVE-2024-38440 -

Netatalk before 3.2.1 has an off-by-one error, and resultant heap-based buffer overflow and segmentation violation, because of incorrectly using FPLoginExt in BN_bin2bn in etc/uams/uams_dhx_pam.c. The original issue 1097 report stated: 'The latest version of Netatalk (v3.2.0) contains a security vuโ€ฆ

๐Ÿ“… Published: June 16, 2024, midnight ๐Ÿ”„ Last Modified: Nov. 3, 2025, 10:17 p.m.

9.8

CVSS3.1

CVE-2024-38395 -

In iTerm2 before 3.5.2, the "Terminal may report window title" setting is not honored, and thus remote code execution might occur but "is not trivially exploitable."

๐Ÿ“… Published: June 16, 2024, midnight ๐Ÿ”„ Last Modified: June 18, 2025, 4:40 p.m.
Total resulsts: 347742
Page 9282 of 34,775
ยซ previous page ยป next page
Filters