7.5

CVSS3.1

CVE-2024-55629 - Suricata generic detection bypass using TCP urgent support

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.8, TCP streams with TCP urgent data (out of band data) can lead to Suricata analyzing data differently than the applications at the TCP endpoints, leading to possible e…

πŸ“… Published: Jan. 6, 2025, 6:04 p.m. πŸ”„ Last Modified: March 31, 2025, 12:54 p.m.

7.5

CVSS3.1

CVE-2024-55628 - Suricata oversized resource names utilizing DNS name compression can lead to resource starvation

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.8, DNS resource name compression can lead to small DNS messages containing very large hostnames which can be costly to decode, and lead to very large DNS log re…

πŸ“… Published: Jan. 6, 2025, 6:02 p.m. πŸ”„ Last Modified: March 31, 2025, 1:02 p.m.

5.9

CVSS3.1

CVE-2024-55627 - Suricata segfault on StreamingBufferSlideToOffsetWithRegions

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.8, a specially crafted TCP stream can lead to a very large buffer overflow while being zero-filled during initialization with memset due to an unsigned integer underflo…

πŸ“… Published: Jan. 6, 2025, 5:50 p.m. πŸ”„ Last Modified: March 31, 2025, 1:40 p.m.

3.3

CVSS3.1

CVE-2024-55626 - Suricata oversized bpf file can lead to buffer overflow

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.8, a large BPF filter file provided to Suricata at startup can lead to a buffer overflow at Suricata startup. The issue has been addressed in Suricata 7.0.8.

πŸ“… Published: Jan. 6, 2025, 5:47 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 8:16 p.m.

5

CVSS3.1

CVE-2024-47475 -

Dell PowerScale OneFS 8.2.2.x through 9.8.0.x contains an incorrect permission assignment for critical resource vulnerability. A locally authenticated attacker could potentially exploit this vulnerability, leading to denial of service.

πŸ“… Published: Jan. 6, 2025, 5:08 p.m. πŸ”„ Last Modified: Feb. 20, 2026, 6:38 p.m.

7.5

CVSS3.1

CVE-2024-55605 - Suricata allows stack overflow in transforms

Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.8, a large input buffer to the to_lowercase, to_uppercase, strip_whitespace, compress_whitespace, dotprefix, header_lowercase, strip_pseudo_headers, url_decode, or xor …

πŸ“… Published: Jan. 6, 2025, 5:07 p.m. πŸ”„ Last Modified: March 31, 2025, 1:53 p.m.

7.2

CVSS3.1

CVE-2023-6605 - Ffmpeg: dash playlist ssrf vulnerability in ffmpeg

A flaw was found in FFmpeg's DASH playlist support. This vulnerability allows arbitrary HTTP GET requests to be made on behalf of the machine running FFmpeg via a crafted DASH playlist containing malicious URLs.

πŸ“… Published: Jan. 6, 2025, 4:42 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 8:16 p.m.

5.3

CVSS3.1

CVE-2023-6604 - Ffmpeg: hls xbin demuxer dos amplification in ffmpeg

A flaw was found in FFmpeg. This vulnerability allows unexpected additional CPU load and storage consumption, potentially leading to degraded performance or denial of service via the demuxing of arbitrary data as XBIN-formatted data without proper format validation.

πŸ“… Published: Jan. 6, 2025, 4:41 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 8:16 p.m.

4.7

CVSS3.1

CVE-2023-6601 - Ffmpeg: hls unsafe file extension bypass in ffmpeg

A flaw was found in FFmpeg's HLS demuxer. This vulnerability allows bypassing unsafe file extension checks and triggering arbitrary demuxers via base64-encoded data URIs appended with specific file extensions.

πŸ“… Published: Jan. 6, 2025, 4:41 p.m. πŸ”„ Last Modified: Nov. 3, 2025, 8:16 p.m.

3.1

CVSS3.1

CVE-2024-51472 - IBM DevOps Deploy / IBM UrbanCode Deploy HTML injection

IBM UrbanCode Deploy (UCD) 7.2 through 7.2.3.13, 7.3 through 7.3.2.8, and IBM DevOps Deploy 8.0 through 8.0.1.3 are vulnerable to HTML injection. This vulnerability may allow a user to embed arbitrary HTML tags in the Web UI potentially leading to sensitive information disclosure.

πŸ“… Published: Jan. 6, 2025, 4:38 p.m. πŸ”„ Last Modified: Aug. 27, 2025, 9:33 p.m.
Total resulsts: 346623
Page 7015 of 34,663
Β« previous page Β» next page
Filters