Show filters
591 Total Results
Displaying 161-170 of 591
Sort by:
Attacker Value
Unknown

CVE-2024-34707

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
Nautobot is a Network Source of Truth and Network Automation Platform. A Nautobot user with admin privileges can modify the `BANNER_TOP`, `BANNER_BOTTOM`, and `BANNER_LOGIN` configuration settings via the `/admin/constance/config/` endpoint. Normally these settings are used to provide custom banner text at the top and bottom of all Nautobot web pages (or specifically on the login page in the case of `BANNER_LOGIN`) but it was reported that an admin user can make use of these settings to inject arbitrary HTML, potentially exposing Nautobot users to security issues such as cross-site scripting (stored XSS). The vulnerability is fixed in Nautobot 1.6.22 and 2.2.4.
0
Attacker Value
Unknown

CVE-2024-34440

Disclosure Date: May 14, 2024 (last updated May 15, 2024)
Unrestricted Upload of File with Dangerous Type vulnerability in Jordy Meow AI Engine: ChatGPT Chatbot.This issue affects AI Engine: ChatGPT Chatbot: from n/a through 2.2.63.
0
Attacker Value
Unknown

CVE-2024-32700

Disclosure Date: May 14, 2024 (last updated May 17, 2024)
Unrestricted Upload of File with Dangerous Type vulnerability in Kognetiks Kognetiks Chatbot for WordPress.This issue affects Kognetiks Chatbot for WordPress: from n/a through 2.0.0.
0
Attacker Value
Unknown

CVE-2024-34380

Disclosure Date: May 06, 2024 (last updated May 07, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in QuantumCloud Conversational Forms for ChatBot allows Stored XSS.This issue affects Conversational Forms for ChatBot: from n/a through 1.2.0.
0
Attacker Value
Unknown

CVE-2024-23354

Disclosure Date: May 06, 2024 (last updated January 16, 2025)
Memory corruption when the IOCTL call is interrupted by a signal.
Attacker Value
Unknown

CVE-2024-23351

Disclosure Date: May 06, 2024 (last updated January 16, 2025)
Memory corruption as GPU registers beyond the last protected range can be accessed through LPAC submissions.
Attacker Value
Unknown

CVE-2024-21475

Disclosure Date: May 06, 2024 (last updated January 16, 2025)
Memory corruption when the payload received from firmware is not as per the expected protocol size.
0
Attacker Value
Unknown

CVE-2024-21471

Disclosure Date: May 06, 2024 (last updated January 16, 2025)
Memory corruption when IOMMU unmap of a GPU buffer fails in Linux.
Attacker Value
Unknown

CVE-2023-43530

Disclosure Date: May 06, 2024 (last updated January 16, 2025)
Memory corruption in HLOS while checking for the storage type.
Attacker Value
Unknown

CVE-2023-33119

Disclosure Date: May 06, 2024 (last updated January 16, 2025)
Memory corruption while loading a VM from a signed VM image that is not coherent in the processor cache.