Show filters
1,189 Total Results
Displaying 111-120 of 1,189
Sort by:
Attacker Value
Unknown

CVE-2024-7358

Disclosure Date: August 01, 2024 (last updated February 26, 2025)
A vulnerability was found in Point B Ltd Getscreen Agent 2.19.6 on Windows. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file getscreen.msi of the component Installation. The manipulation leads to creation of temporary file with insecure permissions. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The identifier VDB-273337 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but was not able to provide a technical response in time.
0
Attacker Value
Unknown

CVE-2024-7014

Disclosure Date: July 23, 2024 (last updated February 26, 2025)
EvilVideo vulnerability allows sending malicious apps disguised as videos in Telegram for Android application affecting versions 10.14.4 and older.
0
Attacker Value
Unknown

CVE-2024-6744

Disclosure Date: July 15, 2024 (last updated February 26, 2025)
The SMTP Listener of Secure Email Gateway from Cellopoint does not properly validate user input, leading to a Buffer Overflow vulnerability. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands on the remote server.
Attacker Value
Unknown

CVE-2024-38536

Disclosure Date: July 11, 2024 (last updated February 26, 2025)
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. A memory allocation failure due to `http.memcap` being reached leads to a NULL-ptr reference leading to a crash. Upgrade to 7.0.6.
Attacker Value
Unknown

CVE-2024-38535

Disclosure Date: July 11, 2024 (last updated February 26, 2025)
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Suricata can run out of memory when parsing crafted HTTP/2 traffic. Upgrade to 6.0.20 or 7.0.6.
Attacker Value
Unknown

CVE-2024-38534

Disclosure Date: July 11, 2024 (last updated February 26, 2025)
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Crafted modbus traffic can lead to unlimited resource accumulation within a flow. Upgrade to 7.0.6. Set a limited stream.reassembly.depth to reduce the issue.
Attacker Value
Unknown

CVE-2024-37151

Disclosure Date: July 11, 2024 (last updated February 26, 2025)
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Mishandling of multiple fragmented packets using the same IP ID value can lead to packet reassembly failure, which can lead to policy bypass. Upgrade to 7.0.6 or 6.0.20. When using af-packet, enable `defrag` to reduce the scope of the problem.
Attacker Value
Unknown

CVE-2023-3290

Disclosure Date: July 09, 2024 (last updated February 26, 2025)
A BOLA vulnerability in POST /customers allows a low privileged user to create a low privileged user (customer) in the system. This results in unauthorized data manipulation.
Attacker Value
Unknown

CVE-2023-3289

Disclosure Date: July 09, 2024 (last updated February 26, 2025)
A BOLA vulnerability in POST /services allows a low privileged user to create a service for any user in the system (including admin). This results in unauthorized data manipulation.
Attacker Value
Unknown

CVE-2023-3288

Disclosure Date: July 09, 2024 (last updated February 26, 2025)
A BOLA vulnerability in POST /providers allows a low privileged user to create a privileged user (provider) in the system. This results in privilege escalation.