5.3
CVE-2023-26280 - IBM Jazz Foundation improper access control
IBM Jazz Foundation 7.0.2 and 7.0.3Β could allow a user to change their dashboard using a specially crafted HTTP request due to improper access control.
6.1
CVE-2023-45181 - IBM Jazz Foundation cross-site scripting
IBM Jazz Foundation 7.0.2 and below are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
5.4
CVE-2024-11670 -
Incorrect authorization in the permission validation component of Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows a malicious authenticated user to bypass the "View Password" permission via specific actions.
5.4
CVE-2024-11671 -
Improper authentication in SQL data source MFA validation in Devolutions Remote Desktop Manager 2024.3.17 and earlier on Windows allows an authenticated user to bypass the MFA validation via data source switching.
4.3
CVE-2024-11672 -
Incorrect authorization in the add permission component in Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows an authenticated malicious user to bypass the "Add" permission via the import in vault feature.
7
CVE-2024-27134 - Excessive directory permissions in MLflow leads to local privilege escalation when using spark_udf
Excessive directory permissions in MLflow leads to local privilege escalation when using spark_udf. This behavior can be exploited by a local attacker to gain elevated permissions by using a ToCToU attack. The issue is only relevant when the spark_udf() MLflow API is called.
6.9
CVE-2024-11403 - Out of Bounds Memory Read/Write in libjxl
There exists an out of bounds read/write in LibJXL versions prior to commitΒ 9cc451b91b74ba470fd72bd48c121e9f33d24c99. The JPEG decoder used by the JPEG XL encoderΒ when doing JPEG recompression (i.e. if using JxlEncoderAddJPEGFrame on untrusted input) does not properly check bounds in the presence oβ¦
6.9
CVE-2024-11498 - Resource exhaustion via Stack overflow in libjxl
There exists a stack buffer overflow in libjxl.Β A specifically-crafted file can cause the JPEG XL decoder to use large amounts of stack space (up to 256mb is possible, maybe 512mb), potentially exhausting the stack. An attacker can craft a file that will cause excessive memory usage. We recommend uβ¦
1
CVE-2020-12492 - Wifi information acquisition vulnerability in Framework Services
Improper handling of WiFi information by framework services can allow certain malicious applications to obtain sensitive information.
4.8
CVE-2020-12491 - Framework Information Disclosure Vulnerability
Improper control of framework service permissions with possibility of some sensitive device information leakage.