2.1

CVSS4.0

CVE-2024-54140 - sigstore-java has a vulnerability with bundle verification

sigstore-java is a sigstore java client for interacting with sigstore infrastructure. sigstore-java has insufficient verification for a situation where a bundle provides a invalid signature for a checkpoint. This bug impacts clients using any variation of KeylessVerifier.verify(). Currently checkpo…

📅 Published: Dec. 5, 2024, 10:08 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.7

CVSS3.1

CVE-2017-13308 -

In tscpu_write_GPIO_out and mtkts_Abts_write of mtk_ts_Abts.c, there is a possible buffer overflow in an sscanf due to improper input validation. This could lead to a local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.

📅 Published: Dec. 5, 2024, 10:05 p.m. 🔄 Last Modified: Dec. 19, 2024, 4:54 p.m.

4.1

CVSS4.0

CVE-2024-10933 - OpenBSD readdir directory traversal

In OpenBSD 7.5 before errata 009 and OpenBSD 7.4 before errata 022, exclude any '/' in readdir name validation to avoid unexpected directory traversal on untrusted file systems.

📅 Published: Dec. 5, 2024, 8:06 p.m. 🔄 Last Modified: Sept. 23, 2025, 12:54 p.m.

8.7

CVSS4.0

CVE-2024-11148 - OpenBSD httpd(8) null dereference

In OpenBSD 7.4 before errata 006 and OpenBSD 7.3 before errata 020, httpd(8) is vulnerable to a NULL dereference when handling a malformed fastcgi request.

📅 Published: Dec. 5, 2024, 7:50 p.m. 🔄 Last Modified: Sept. 23, 2025, 12:22 p.m.

8.5

CVSS4.0

CVE-2024-12130 - Rockwell Automation Arena® Out of Bounds Read Vulnerability

An “out of bounds read” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to read beyond the boundaries of an allocated memory. If exploited, a threat actor could leverage this vulnerability to execute …

📅 Published: Dec. 5, 2024, 5:47 p.m. 🔄 Last Modified: Dec. 17, 2024, 3:52 p.m.

8.5

CVSS4.0

CVE-2024-11158 - Rockwell Automation Arena® Uninitialized Vulnerability

An “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to access a variable before it being initialized. If exploited, a threat actor could leverage this vulnerability to execut…

📅 Published: Dec. 5, 2024, 5:41 p.m. 🔄 Last Modified: April 18, 2025, 6:15 p.m.

8.5

CVSS4.0

CVE-2024-11156 - Rockwell Automation Arena® Out of Bounds Write Vulnerability

An “out of bounds write” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit t…

📅 Published: Dec. 5, 2024, 5:37 p.m. 🔄 Last Modified: Dec. 17, 2024, 3:52 p.m.

8.5

CVSS4.0

CVE-2024-11155 - Rockwell Automation Arena® Use After Free Vulnerability

A “use after free” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to use a resource that was already used. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To …

📅 Published: Dec. 5, 2024, 5:32 p.m. 🔄 Last Modified: April 14, 2025, 5:17 p.m.

5.3

CVSS4.0

CVE-2024-12235 - Shenzhen Dashi Tongzhou Information Technology AgileBPM AuthorizationTokenCheckFilter.java doFilter…

A vulnerability was found in Shenzhen Dashi Tongzhou Information Technology AgileBPM up to 1.0.0. It has been declared as critical. Affected by this vulnerability is the function doFilter of the file \agile-bpm-basic-master\ab-auth\ab-auth-spring-security-oauth2\src\main\java\com\dstz\auth\filter\A…

📅 Published: Dec. 5, 2024, 5:31 p.m. 🔄 Last Modified: Nov. 12, 2025, 7:35 p.m.

5.5

CVSS3.1

CVE-2024-53846 - ssl fails to validate incorrect extened key usage

OTP is a set of Erlang libraries, which consists of the Erlang runtime system, a number of ready-to-use components mainly written in Erlang, and a set of design principles for Erlang programs. A regression was introduced into the ssl application of OTP starting at OTP-25.3.2.8, OTP-26.2, and OTP-27…

📅 Published: Dec. 5, 2024, 5:02 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 345152
Page 7208 of 34,516
« previous page » next page
Filters