Show filters
2,016 Total Results
Displaying 101-110 of 2,016
Sort by:
Attacker Value
Unknown
CVE-2024-3334
Disclosure Date: November 15, 2024 (last updated November 16, 2024)
A security bypass vulnerability exists in the Removable Media Encryption (RME)component of Digital Guardian Windows Agents prior to version 8.2.0. This allows a user to circumvent encryption controls by modifying metadata on the USB device thereby compromising the confidentiality of the stored data.
0
Attacker Value
Unknown
CVE-2024-9633
Disclosure Date: November 14, 2024 (last updated December 18, 2024)
An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.3 before 17.4.2, all versions starting from 17.5 before 17.5.4, all versions starting from 17.6 before 17.6.2. This issue allows an attacker to create a group with a name matching an existing unique Pages domain, potentially leading to domain confusion attacks.
0
Attacker Value
Unknown
CVE-2024-8648
Disclosure Date: November 14, 2024 (last updated December 18, 2024)
An issue has been discovered in GitLab CE/EE affecting all versions from 16 before 17.3.7, 17.4 before 17.4.4, and 17.5 before 17.5.2. The vulnerability could allow an attacker to inject malicious JavaScript code in Analytics Dashboards through a specially crafted URL.
0
Attacker Value
Unknown
CVE-2024-7404
Disclosure Date: November 14, 2024 (last updated December 18, 2024)
An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 prior to 17.3.7, starting from 17.4 prior to 17.4.4 and starting from 17.5 prior to 17.5.2, which could have allowed an attacker gaining full API access as the victim via the Device OAuth flow.
0
Attacker Value
Unknown
CVE-2024-9693
Disclosure Date: November 14, 2024 (last updated January 05, 2025)
An issue was discovered in GitLab CE/EE affecting all versions starting from 16.0 prior to 17.3.7, starting from 17.4 prior to 17.4.4, and starting from 17.5 prior to 17.5.2, which could have allowed unauthorized access to the Kubernetes agent in a cluster under specific configurations.
0
Attacker Value
Unknown
CVE-2024-8180
Disclosure Date: November 14, 2024 (last updated December 18, 2024)
An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.3.7, 17.4 before 17.4.4, and 17.5 before 17.5.2. Improper output encoding could lead to XSS if CSP is not enabled.
0
Attacker Value
Unknown
CVE-2024-51746
Disclosure Date: November 05, 2024 (last updated November 06, 2024)
Gitsign is a keyless Sigstore to signing tool for Git commits with your a GitHub / OIDC identity. gitsign may select the wrong Rekor entry to use during online verification when multiple entries are returned by the log. gitsign uses Rekor's search API to fetch entries that apply to a signature being verified. The parameters used for the search are the public key and the payload. The search API returns entries that match either condition rather than both. When gitsign's credential cache is used, there can be multiple entries that use the same ephemeral keypair / signing certificate. As gitsign assumes both conditions are matched by Rekor, there is no additional validation that the entry's hash matches the payload being verified, meaning that the wrong entry can be used to successfully pass verification. Impact is minimal as while gitsign does not match the payload against the entry, it does ensure that the certificate matches. This would need to be exploited during the certificate vali…
0
Attacker Value
Unknown
CVE-2024-43162
Disclosure Date: November 01, 2024 (last updated February 08, 2025)
Missing Authorization vulnerability in Easy Digital Downloads allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Digital Downloads: from n/a through 3.2.12.
0
Attacker Value
Unknown
CVE-2024-8312
Disclosure Date: October 24, 2024 (last updated December 18, 2024)
An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 17.3.6, 17.4 before 17.4.3, and 17.5 before 17.5.1. An attacker could inject HTML into the Global Search field on a diff view leading to XSS.
0
Attacker Value
Unknown
CVE-2024-6826
Disclosure Date: October 24, 2024 (last updated December 18, 2024)
An issue has been discovered in GitLab CE/EE affecting all versions from 11.2 before 17.3.6, 17.4 before 17.4.3, and 17.5 before 17.5.1. A denial of service could occur via importing a malicious crafted XML manifest file.
0