5.3

CVSS4.0

CVE-2024-11046 - D-Link DI-8003 upgrade_filter.asp upgrade_filter_asp os command injection

A vulnerability was found in D-Link DI-8003 16.07.16A1. It has been classified as critical. Affected is the function upgrade_filter_asp of the file /upgrade_filter.asp. The manipulation of the argument path leads to os command injection. It is possible to launch the attack remotely. The exploit has…

πŸ“… Published: Nov. 10, 2024, 3 a.m. πŸ”„ Last Modified: Nov. 13, 2024, 9:01 p.m.

8.4

CVSS3.1

CVE-2024-46954 - ghostscript: Directory Traversal in Ghostscript via Overlong UTF-8 Encoding

An issue was discovered in decode_utf8 in base/gp_utf8.c in Artifex Ghostscript before 10.04.0. Overlong UTF-8 encoding leads to possible ../ directory traversal.

πŸ“… Published: Nov. 10, 2024, midnight πŸ”„ Last Modified: Aug. 15, 2025, 8:38 p.m.

8.4

CVSS3.1

CVE-2024-46952 - ghostscript: Buffer Overflow in Ghostscript PDF XRef Stream Handling

An issue was discovered in pdf/pdf_xref.c in Artifex Ghostscript before 10.04.0. There is a buffer overflow during handling of a PDF XRef stream (related to W array values).

πŸ“… Published: Nov. 10, 2024, midnight πŸ”„ Last Modified: Nov. 14, 2024, 2:01 a.m.

7.8

CVSS3.1

CVE-2024-46953 - ghostscript: Path Traversal and Code Execution via Integer Overflow in Ghostscript

An issue was discovered in base/gsdevice.c in Artifex Ghostscript before 10.04.0. An integer overflow when parsing the filename format string (for the output filename) results in path truncation, and possible path traversal and code execution.

πŸ“… Published: Nov. 10, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 11:16 p.m.

0.0

CVE-2023-40457 -

The BGP daemon in Extreme Networks ExtremeXOS (aka EXOS) 30.7.1.1 allows an attacker (who is not on a directly connected network) to cause a denial of service (BGP session reset) because of BGP attribute error mishandling (for attribute 21 and 25). NOTE: the vendor disputes this because it is "eval…

πŸ“… Published: Nov. 10, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.5

CVSS3.1

CVE-2020-10368 -

Certain Cypress (and Broadcom) Wireless Combo chips, when a January 2021 firmware update is not present, allow memory read access via a "Spectra" attack.

πŸ“… Published: Nov. 10, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2024-46956 - ghostscript: Out-of-Bounds Data Access in Ghostscript Leads to Arbitrary Code Execution

An issue was discovered in psi/zfile.c in Artifex Ghostscript before 10.04.0. Out-of-bounds data access in filenameforall can lead to arbitrary code execution.

πŸ“… Published: Nov. 10, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 11:16 p.m.

5.5

CVSS3.1

CVE-2024-46955 - ghostscript: Out-of-Bounds Read in Ghostscript Indexed Color Space

An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. There is an out-of-bounds read when reading color in Indexed color space.

πŸ“… Published: Nov. 10, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 11:16 p.m.

7.8

CVSS3.1

CVE-2024-46951 - ghostscript: Arbitrary Code Execution in Artifex Ghostscript Pattern Color Space

An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. An unchecked Implementation pointer in Pattern color space could lead to arbitrary code execution.

πŸ“… Published: Nov. 10, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 11:16 p.m.

5.5

CVSS3.1

CVE-2020-10369 -

Certain Cypress (and Broadcom) Wireless Combo chips, when a January 2021 firmware update is not present, allow inferences about memory content via a "Spectra" attack.

πŸ“… Published: Nov. 10, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 345187
Page 7557 of 34,519
Β« previous page Β» next page
Filters