Show filters
1,987 Total Results
Displaying 121-130 of 1,987
Sort by:
Attacker Value
Unknown
CVE-2024-45308
Disclosure Date: September 02, 2024 (last updated September 03, 2024)
HedgeDoc is an open source, real-time, collaborative, markdown notes application. When using HedgeDoc 1 with MySQL or MariaDB, it is possible to create notes with an alias matching the ID of existing notes. The affected existing note can then not be accessed anymore and is effectively hidden by the new one. When the freeURL feature is enabled (by setting the `allowFreeURL` config option or the `CMD_ALLOW_FREEURL` environment variable to `true`), any user with the appropriate permissions can create a note with an arbitrary alias, e.g. by accessing it in the browser. When MySQL or MariaDB are used, it is possible to create a new note with an alias that matches the lower-cased ID of a different note. HedgeDoc then always presents the new note to users, as these databases perform case-insensitive matching and the lower-cased alias is found first. This issue only affects HedgeDoc instances that use MySQL or MariaDB. Depending on the permission settings of the HedgeDoc instance, the issue c…
0
Attacker Value
Unknown
CVE-2024-38304
Disclosure Date: August 29, 2024 (last updated December 21, 2024)
Dell PowerEdge Platform, 14G Intel BIOS version(s) prior to 2.22.x, contains an Access of Memory Location After End of Buffer vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
0
Attacker Value
Unknown
CVE-2024-38303
Disclosure Date: August 29, 2024 (last updated December 21, 2024)
Dell PowerEdge Platform, 14G Intel BIOS version(s) prior to 2.22.x, contains an Improper Input Validation vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.
0
Attacker Value
Unknown
CVE-2024-8105
Disclosure Date: August 26, 2024 (last updated August 27, 2024)
A vulnerability related to the use an insecure Platform Key (PK) has been discovered. An attacker with the compromised PK private key can create malicious UEFI software that is signed with a trusted key that has been compromised.
0
Attacker Value
Unknown
CVE-2024-41879
Disclosure Date: August 26, 2024 (last updated September 06, 2024)
Acrobat Reader versions 127.0.2651.105 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
0
Attacker Value
Unknown
CVE-2024-38207
Disclosure Date: August 23, 2024 (last updated August 28, 2024)
Microsoft Edge (HTML-based) Memory Corruption Vulnerability
0
Attacker Value
Unknown
CVE-2024-38210
Disclosure Date: August 22, 2024 (last updated August 30, 2024)
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
0
Attacker Value
Unknown
CVE-2024-38209
Disclosure Date: August 22, 2024 (last updated August 30, 2024)
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
0
Attacker Value
Unknown
CVE-2024-38208
Disclosure Date: August 22, 2024 (last updated August 30, 2024)
Microsoft Edge for Android Spoofing Vulnerability
0
Attacker Value
Unknown
CVE-2024-7971
Disclosure Date: August 21, 2024 (last updated January 07, 2025)
Type confusion in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
0