7.5
CVE-2024-4599 - Denial of service vulnerability in LAN Messenger
Remote denial of service vulnerability in LAN Messenger affecting version 3.4.0. This vulnerability allows an attacker to crash the LAN Messenger service by sending a long string directly and continuously over the UDP protocol.
4.3
CVE-2023-6810 - ClickCease Click Fraud Protection <= 3.2.4 - Improper Authorization to sensitive information exposuβ¦
The ClickCease Click Fraud Protection plugin for WordPress is vulnerable to unauthorized access of data due to an improper capability check on the get_settings function in all versions up to, and including, 3.2.4. This makes it possible for authenticated attackers, with author access and above, to β¦
9.1
CVE-2024-4346 - Startklar Elementor Addons <= 1.7.13 - Unauthenticated Arbitrary File Deletion
The Startklar Elementor Addons plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to, and including, 1.7.13. This is due to the plugin not properly validating the path of an uploaded file prior to deleting it. This makes it possible for unauthenticated attackers to delβ¦
9.8
CVE-2024-4345 - Startklar Elementor Addons <= 1.7.13 - Unauthenticated Arbitrary File Upload
The Startklar Elementor Addons plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'process' function in the 'startklarDropZoneUploadProcess' class in versions up to, and including, 1.7.13. This makes it possible for unauthenticated attackersβ¦
6.5
CVE-2024-3759 - Hmdfs has a use after free vulnerability
in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in TCB through use after free.
6.5
CVE-2024-3758 - Hmdfs has a heap buffer overflow vulnerability
in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in TCB through heap buffer overflow.
3.3
CVE-2024-3757 - Arkcompiler runtime has an integer overflow vulnerability
in OpenHarmony v4.0.0 and prior versions allow a local attacker cause service crash through integer overflow.
3.3
CVE-2024-31078 - Bluetooth Service has a use after free vulnerability
in OpenHarmony v4.0.0 and prior versions allow a local attacker cause service crash through NULL pointer dereference.
5.2
CVE-2024-23808 - Arkcompiler ets frontend has an out-of-bounds read vulnerability
in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free or cause DOS through NULL pointer dereference.
6.5
CVE-2024-27217 - MSDP has a use after free vulnerability
in OpenHarmony v4.0.0 and prior versions allow a local attacker arbitrary code execution in pre-installed apps through use after free.