Show filters
1,189 Total Results
Displaying 111-120 of 1,189
Sort by:
Attacker Value
Unknown
CVE-2024-7358
Disclosure Date: August 01, 2024 (last updated February 26, 2025)
A vulnerability was found in Point B Ltd Getscreen Agent 2.19.6 on Windows. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file getscreen.msi of the component Installation. The manipulation leads to creation of temporary file with insecure permissions. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. The identifier VDB-273337 was assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but was not able to provide a technical response in time.
0
Attacker Value
Unknown
CVE-2024-7014
Disclosure Date: July 23, 2024 (last updated February 26, 2025)
EvilVideo vulnerability allows sending malicious apps disguised as videos in Telegram for Android application affecting
versions 10.14.4 and older.
0
Attacker Value
Unknown
CVE-2024-6744
Disclosure Date: July 15, 2024 (last updated February 26, 2025)
The SMTP Listener of Secure Email Gateway from Cellopoint does not properly validate user input, leading to a Buffer Overflow vulnerability. An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands on the remote server.
0
Attacker Value
Unknown
CVE-2024-38536
Disclosure Date: July 11, 2024 (last updated February 26, 2025)
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. A memory allocation failure due to `http.memcap` being reached leads to a NULL-ptr reference leading to a crash. Upgrade to 7.0.6.
0
Attacker Value
Unknown
CVE-2024-38535
Disclosure Date: July 11, 2024 (last updated February 26, 2025)
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Suricata can run out of memory when parsing crafted HTTP/2 traffic. Upgrade to 6.0.20 or 7.0.6.
0
Attacker Value
Unknown
CVE-2024-38534
Disclosure Date: July 11, 2024 (last updated February 26, 2025)
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Crafted modbus traffic can lead to unlimited resource accumulation within a flow. Upgrade to 7.0.6. Set a limited stream.reassembly.depth to reduce the issue.
0
Attacker Value
Unknown
CVE-2024-37151
Disclosure Date: July 11, 2024 (last updated February 26, 2025)
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine.
Mishandling of multiple fragmented packets using the same IP ID value can lead to packet reassembly failure, which can lead to policy bypass. Upgrade to 7.0.6 or 6.0.20. When using af-packet, enable `defrag` to reduce the scope of the problem.
0
Attacker Value
Unknown
CVE-2023-3290
Disclosure Date: July 09, 2024 (last updated February 26, 2025)
A BOLA vulnerability in POST /customers allows a low privileged user to create a low privileged user (customer) in the system. This results in unauthorized data manipulation.
0
Attacker Value
Unknown
CVE-2023-3289
Disclosure Date: July 09, 2024 (last updated February 26, 2025)
A BOLA vulnerability in POST /services allows a low privileged user to create a service for any user in the system (including admin). This results in unauthorized data manipulation.
0
Attacker Value
Unknown
CVE-2023-3288
Disclosure Date: July 09, 2024 (last updated February 26, 2025)
A BOLA vulnerability in POST /providers allows a low privileged user to create a privileged user (provider) in the system. This results in privilege escalation.
0