7.4

CVSS3.1

CVE-2024-36702 -

libiec61850 v1.5 was discovered to contain a heap overflow via the BerEncoder_encodeLength function at /asn1/ber_encoder.c.

πŸ“… Published: June 11, 2024, midnight πŸ”„ Last Modified: June 18, 2025, 5:35 p.m.

7.5

CVSS3.1

CVE-2023-4727 - Ca: token authentication bypass vulnerability

A flaw was found in dogtag-pki and pki-core. The token authentication scheme can be bypassed with a LDAP injection. By passing the query string parameter sessionID=*, an attacker can authenticate with an existing session saved in the LDAP directory server, which may lead to escalation of privilege.

πŸ“… Published: June 11, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-36650 -

TOTOLINK AC1200 Wireless Dual Band Gigabit Router firmware A3100R V4.1.2cu.5247_B20211129, in the cgi function `setNoticeCfg` of the file `/lib/cste_modules/system.so`, the length of the user input string `NoticeUrl` is not checked. This can lead to a buffer overflow, allowing attackers to construc…

πŸ“… Published: June 11, 2024, midnight πŸ”„ Last Modified: June 4, 2025, 5:24 p.m.

6.1

CVSS3.1

CVE-2024-5693 - Mozilla: Cross-Origin Image leak via Offscreen Canvas

Offscreen Canvas did not properly track cross-origin tainting, which could be used to access image data from another site in violation of same-origin policy. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.

πŸ“… Published: June 11, 2024, midnight πŸ”„ Last Modified: March 27, 2025, 8:02 p.m.

4.7

CVSS3.1

CVE-2024-5691 - Mozilla: Sandboxed iframes were able to bypass sandbox restrictions to open a new window

By tricking the browser with a `X-Frame-Options` header, a sandboxed iframe could have presented a button that, if clicked by a user, would bypass restrictions to open a new window. This vulnerability affects Firefox < 127, Firefox ESR < 115.12, and Thunderbird < 115.12.

πŸ“… Published: June 11, 2024, midnight πŸ”„ Last Modified: March 19, 2025, 9:15 p.m.

6.5

CVSS3.1

CVE-2024-5692 - Mozilla: Bypass of file name restrictions during saving

On Windows 10, when using the 'Save As' functionality, an attacker could have tricked the browser into saving the file with a disallowed extension such as `.url` by including an invalid character in the extension. *Note:* This issue only affected Windows operating systems. Other operating systems a…

πŸ“… Published: June 11, 2024, midnight πŸ”„ Last Modified: Feb. 27, 2026, 4:40 p.m.

6.8

CVSS3.1

CVE-2024-36821 -

Insecure permissions in Linksys Velop WiFi 5 (WHW01v1) 1.1.13.202617 allows attackers to escalate privileges from Guest to root.

πŸ“… Published: June 11, 2024, midnight πŸ”„ Last Modified: Nov. 21, 2024, 9:22 a.m.

4.2

CVSS3.1

CVE-2024-5891 - Quay: unauthorized user may authenticate via oauth application token

A vulnerability was found in Quay. If an attacker can obtain the client ID for an application, they can use an OAuth token to authenticate despite not having access to the organization from which the application was created. This issue is limited to authentication and not authorization. However, in…

πŸ“… Published: June 11, 2024, midnight πŸ”„ Last Modified: Nov. 21, 2024, 9:48 a.m.

0.0

CVSS3.1

CVE-2024-35329 - libyaml: vulnerable to a heap-based Buffer Overflow in yaml_document_add_sequence in api.c

DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

πŸ“… Published: June 11, 2024, midnight πŸ”„ Last Modified: Aug. 28, 2024, 4:15 p.m.

2.7

CVSS3.1

CVE-2024-22261 - SQL Injection in Harbor scan log API

SQL-Injection in Harbor allows priviledge users to leak the task IDs

πŸ“… Published: June 10, 2024, 11:25 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 8:55 a.m.
Total resulsts: 349182
Page 9513 of 34,919
Β« previous page Β» next page
Filters