7.5

CVSS3.1

CVE-2024-34475 -

Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: gmm_state_authentication in amf/gmm-sm.c for != OGS_ERROR.

πŸ“… Published: May 4, 2024, midnight πŸ”„ Last Modified: April 22, 2025, 5:53 p.m.

5.3

CVSS3.1

CVE-2024-34476 -

Open5GS before 2.7.1 is vulnerable to a reachable assertion that can cause an AMF crash via NAS messages from a UE: ogs_nas_encrypt in lib/nas/common/security.c for pkbuf->len.

πŸ“… Published: May 4, 2024, midnight πŸ”„ Last Modified: April 22, 2025, 5:52 p.m.

7.5

CVSS3.1

CVE-2023-52729 -

TCPServer.cpp in SimpleNetwork through 29bc615 has an off-by-one error that causes a buffer overflow when trying to add '\0' to the end of long msg data. It can be exploited via crafted TCP packets.

πŸ“… Published: May 4, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-34461 -

Zenario before 9.5.60437 uses Twig filters insecurely in the Twig Snippet plugin, and in the site-wide HEAD and BODY elements, enabling code execution by a designer or an administrator.

πŸ“… Published: May 4, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2024-34466 -

DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-34467. Reason: This candidate is a reservation duplicate of CVE-2024-34467. Notes: All CVE users should reference CVE-2024-34467 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidenta…

πŸ“… Published: May 4, 2024, midnight πŸ”„ Last Modified: May 6, 2024, 3:15 p.m.

6.1

CVSS3.1

CVE-2024-34462 -

Alinto SOGo through 5.10.0 allows XSS during attachment preview.

πŸ“… Published: May 4, 2024, midnight πŸ”„ Last Modified: June 10, 2025, 5:48 p.m.

6.5

CVSS3.1

CVE-2024-34460 -

The Tree Explorer tool from Organizer in Zenario before 9.5.60602 is affected by XSS. (This component was removed in 9.5.60602.)

πŸ“… Published: May 4, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.3

CVSS3.1

CVE-2023-40695 - IBM Cognos Controller session fixation

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 does not invalidate session after logout which could allow an authenticated user to impersonate another user on the system. IBM X-Force ID: 264938.

πŸ“… Published: May 3, 2024, 6:18 p.m. πŸ”„ Last Modified: Jan. 7, 2025, 8:26 p.m.

6

CVSS3.1

CVE-2021-20451 - IBM Cognos Controller SQL injection

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 196643.

πŸ“… Published: May 3, 2024, 6:16 p.m. πŸ”„ Last Modified: Jan. 7, 2025, 7:25 p.m.

5.3

CVSS3.1

CVE-2022-22364 - IBM Cognos Controller security bypass

IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to external service interaction attack, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to induce the application to perform server-side DNS lookups or HTTP requests to arbitrary …

πŸ“… Published: May 3, 2024, 6:14 p.m. πŸ”„ Last Modified: Jan. 7, 2025, 8:16 p.m.
Total resulsts: 349182
Page 9987 of 34,919
Β« previous page Β» next page
Filters