7.4
CVE-2024-34507 - mediawiki: cross-site scripting
An issue was discovered in includes/CommentFormatter/CommentParser.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1. XSS can occur because of mishandling of the 0x1b character, as demonstrated by Special:RecentChanges#%1b0000000.
7.5
CVE-2024-34506 - mediawiki: denial of service
An issue was discovered in includes/specials/SpecialMovePage.php in MediaWiki before 1.39.7, 1.40.x before 1.40.3, and 1.41.x before 1.41.1. If a user with the necessary rights to move the page opens Special:MovePage for a page with tens of thousands of subpages, then the page will exceed the maximβ¦
9.8
CVE-2024-34502 - mediawiki: MergeLexemes makes edits on GET requests without edit tokens
An issue was discovered in WikibaseLexeme in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. Loading Special:MergeLexemes will (attempt to) make an edit that merges the from-id to the to-id, even if the request was not a POST request, and even if it does not contain an editβ¦
6.1
CVE-2024-34500 - mediawiki: XSS through interface message in UnlinkedWikibase
An issue was discovered in the UnlinkedWikibase extension in MediaWiki before 1.39.6, 1.40.x before 1.40.2, and 1.41.x before 1.41.1. XSS can occur through an interface message. Error messages (in the $err var) are not escaped before being passed to Html::rawElement() in the getError() function in β¦
7.5
CVE-2024-34487 -
OFPFlowStats in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via inst.length=0.
4.3
CVE-2024-34508 -
dcmnet in DCMTK before 3.6.9 has a segmentation fault via an invalid DIMSE message.
4.8
CVE-2024-34529 -
Nebari through 2024.4.1 prints the temporary Keycloak root password.
5.3
CVE-2024-34484 -
OFPBucket in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via action.len=0.
8.8
CVE-2024-34515 -
image-optimizer before 1.7.3 allows PHAR deserialization, e.g., the phar:// protocol in arguments to file_exists().
7.5
CVE-2024-34486 -
OFPPacketQueue in parser.py in Faucet SDN Ryu 4.34 allows attackers to cause a denial of service (infinite loop) via OFPQueueProp.len=0.