5.4

CVSS3.1

CVE-2024-56923 -

Stored Cross-Site Scripting (XSS) Vulnerability in the Categorization Option of My Subscriptions Functionality in Silverpeas Core 6.3.1 <= 6.4.1 allows a remote attacker to execute arbitrary JavaScript code. This is achieved by injecting a malicious payload into the Name field of a subscription. Th…

πŸ“… Published: Jan. 22, 2025, midnight πŸ”„ Last Modified: May 28, 2025, 8:41 p.m.

6.4

CVSS3.1

CVE-2024-42013 -

In GRAU DATA Blocky before 3.1, Blocky-Gui has a Client-Side Enforcement of Server-Side Security vulnerability. An attacker with Windows administrative or debugging privileges can patch a binary in memory or on disk to bypass the password login requirement and gain full access to all functions of t…

πŸ“… Published: Jan. 22, 2025, midnight πŸ”„ Last Modified: Feb. 4, 2025, 7:15 p.m.

8.6

CVSS3.1

CVE-2024-24429 -

A reachable assertion in the nas_eps_send_emm_to_esm function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NGAP packet.

πŸ“… Published: Jan. 22, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 5:27 p.m.

8.6

CVSS3.1

CVE-2023-37017 -

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send an `S1Setup Request` message missing a required `Global eNB ID` field to repeatedly crash the MME, resulting in denial of service.

πŸ“… Published: Jan. 22, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 5:15 p.m.

6.3

CVSS3.1

CVE-2023-37011 -

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `Handover Required` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.

πŸ“… Published: Jan. 22, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 5:13 p.m.

7.8

CVSS3.1

CVE-2024-55957 -

In Thermo Fisher Scientific Xcalibur before 4.7 SP1 and Thermo Foundation Instrument Control Software (ICSW) before 3.1 SP10, the driver packages have a local privilege escalation vulnerability due to improper access control permissions on Windows systems.

πŸ“… Published: Jan. 22, 2025, midnight πŸ”„ Last Modified: March 14, 2025, 4:15 p.m.

5.3

CVSS3.1

CVE-2023-37008 -

Open5GS MME versions <= 2.6.4 contain a buffer overflow in the ASN.1 deserialization function of the S1AP handler. This buffer overflow causes type confusion in decoded fields, leading to invalid parsing and freeing of memory. An attacker may use this to crash an MME or potentially execute code in …

πŸ“… Published: Jan. 22, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 5:14 p.m.

6.6

CVSS3.1

CVE-2025-0750 - Cri-o: cri-o path traversal in log handling functions allows arbitrary unmounting

A vulnerability was found in CRI-O. A path traversal issue in the log management functions (UnMountPodLogs and LinkContainerLogs) may allow an attacker with permissions to create and delete Pods to unmount arbitrary host paths, leading to node-level denial of service by unmounting critical system d…

πŸ“… Published: Jan. 22, 2025, midnight πŸ”„ Last Modified: Nov. 20, 2025, 8 p.m.

5.3

CVSS3.1

CVE-2023-37006 -

Open5GS MME versions <= 2.6.4 contain an assertion that can be remotely triggered via a malformed ASN.1 packet over the S1AP interface. An attacker may send a `Handover Request Ack` message missing a required `MME_UE_S1AP_ID` field to repeatedly crash the MME, resulting in denial of service.

πŸ“… Published: Jan. 22, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 5:14 p.m.

7.5

CVSS3.1

CVE-2024-24430 -

A reachable assertion in the mme_ue_find_by_imsi function of Open5GS <= 2.6.4 allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet.

πŸ“… Published: Jan. 22, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 5:27 p.m.
Total resulsts: 343040
Page 6397 of 34,304
Β« previous page Β» next page
Filters