4.3

CVSS3.1

CVE-2024-11672 -

Incorrect authorization in the add permission component in Devolutions Remote Desktop Manager 2024.2.21 and earlier on Windows allows an authenticated malicious user to bypass the "Add" permission via the import in vault feature.

πŸ“… Published: Nov. 25, 2024, 2:46 p.m. πŸ”„ Last Modified: March 28, 2025, 4:21 p.m.

7

CVSS3.1

CVE-2024-27134 - Excessive directory permissions in MLflow leads to local privilege escalation when using spark_udf

Excessive directory permissions in MLflow leads to local privilege escalation when using spark_udf. This behavior can be exploited by a local attacker to gain elevated permissions by using a ToCToU attack. The issue is only relevant when the spark_udf() MLflow API is called.

πŸ“… Published: Nov. 25, 2024, 1:48 p.m. πŸ”„ Last Modified: Feb. 3, 2025, 3:05 p.m.

6.9

CVSS4.0

CVE-2024-11403 - Out of Bounds Memory Read/Write in libjxl

There exists an out of bounds read/write in LibJXL versions prior to commitΒ 9cc451b91b74ba470fd72bd48c121e9f33d24c99. The JPEG decoder used by the JPEG XL encoderΒ when doing JPEG recompression (i.e. if using JxlEncoderAddJPEGFrame on untrusted input) does not properly check bounds in the presence o…

πŸ“… Published: Nov. 25, 2024, 1:08 p.m. πŸ”„ Last Modified: July 24, 2025, 1:25 p.m.

6.9

CVSS4.0

CVE-2024-11498 - Resource exhaustion via Stack overflow in libjxl

There exists a stack buffer overflow in libjxl.Β A specifically-crafted file can cause the JPEG XL decoder to use large amounts of stack space (up to 256mb is possible, maybe 512mb), potentially exhausting the stack. An attacker can craft a file that will cause excessive memory usage. We recommend u…

πŸ“… Published: Nov. 25, 2024, 1:08 p.m. πŸ”„ Last Modified: July 23, 2025, 7:58 p.m.

1

CVSS4.0

CVE-2020-12492 - Wifi information acquisition vulnerability in Framework Services

Improper handling of WiFi information by framework services can allow certain malicious applications to obtain sensitive information.

πŸ“… Published: Nov. 25, 2024, 10:11 a.m. πŸ”„ Last Modified: Nov. 25, 2024, 5:02 p.m.

4.8

CVSS4.0

CVE-2020-12491 - Framework Information Disclosure Vulnerability

Improper control of framework service permissions with possibility of some sensitive device information leakage.

πŸ“… Published: Nov. 25, 2024, 10:08 a.m. πŸ”„ Last Modified: Nov. 25, 2024, 5:03 p.m.

8.7

CVSS4.0

CVE-2024-11664 - eNMS TGZ File controller.py multiselect_filtering path traversal

A vulnerability, which was classified as critical, has been found in eNMS up to 4.2. Affected by this issue is the function multiselect_filtering of the file eNMS/controller.py of the component TGZ File Handler. The manipulation leads to path traversal. The attack may be launched remotely. The expl…

πŸ“… Published: Nov. 25, 2024, 9 a.m. πŸ”„ Last Modified: Dec. 4, 2024, 7:28 p.m.

6.7

CVSS3.1

CVE-2022-33862 - Improper access control mechanism in IPP

IPP software prior to v1.71 is vulnerable to default credential vulnerability. This could lead attackers to identify and access vulnerable systems.

πŸ“… Published: Nov. 25, 2024, 8:54 a.m. πŸ”„ Last Modified: Nov. 25, 2024, 1:56 p.m.

5.1

CVSS3.1

CVE-2022-33861 - Insufficient verification of authenticity in IPP

IPP software versions prior to v1.71 do not sufficiently verify the authenticity of data, in a way that causes it to accept invalid data.

πŸ“… Published: Nov. 25, 2024, 8:50 a.m. πŸ”„ Last Modified: Nov. 25, 2024, 1:57 p.m.

5.2

CVSS3.1

CVE-2021-23282 - Stored Cross-site Scripting reported in Intelligent Power Manager v1

Eaton Intelligent Power Manager (IPM) prior to 1.70 is vulnerable to stored Cross site scripting. The vulnerability exists due to insufficient validation of input from certain resources by the IPM software. The attacker would need access to the local Subnet and an administrator interaction to compr…

πŸ“… Published: Nov. 25, 2024, 8:36 a.m. πŸ”„ Last Modified: Nov. 25, 2024, 1:57 p.m.
Total resulsts: 343744
Page 7166 of 34,375
Β« previous page Β» next page
Filters