Show filters
1,948 Total Results
Displaying 211-220 of 1,948
Sort by:
Attacker Value
Unknown
CVE-2024-23144
Disclosure Date: June 25, 2024 (last updated February 26, 2025)
A maliciously crafted CATPART file, when parsed in CC5Dll.dll and ASMBASE228A.dll through Autodesk AutoCAD, may force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
0
Attacker Value
Unknown
CVE-2024-23143
Disclosure Date: June 25, 2024 (last updated February 26, 2025)
A maliciously crafted 3DM, MODEL and X_B file, when parsed in ASMkern229A.dll and ASMBASE229A.dll through Autodesk applications, can force an Out-of-Bound Read and/or Out-of-Bound Write. A malicious actor can leverage this vulnerability to cause a crash,read sensitive data, or execute arbitrary code in the context of the current process.
0
Attacker Value
Unknown
CVE-2024-37280
Disclosure Date: June 13, 2024 (last updated February 26, 2025)
A flaw was discovered in Elasticsearch, affecting document ingestion when an index template contains a dynamic field mapping of “passthrough” type. Under certain circumstances, ingesting documents in this index would cause a StackOverflow exception to be thrown and ultimately lead to a Denial of Service. Note that passthrough fields is an experimental feature.
0
Attacker Value
Unknown
CVE-2024-4145
Disclosure Date: June 13, 2024 (last updated February 26, 2025)
The Search & Replace WordPress plugin before 3.2.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks (such as within a multi-site network).
0
Attacker Value
Unknown
CVE-2024-23445
Disclosure Date: June 12, 2024 (last updated February 26, 2025)
It was identified that if a cross-cluster API key https://www.elastic.co/guide/en/elasticsearch/reference/8.14/security-api-create-cross-cluster-api-key.html#security-api-create-cross-cluster-api-key-request-body restricts search for a given index using the query or the field_security parameter, and the same cross-cluster API key also grants replication for the same index, the search restrictions are not enforced during cross cluster search operations and search results may include documents and terms that should not be returned.
This issue only affects the API key based security model for remote clusters https://www.elastic.co/guide/en/elasticsearch/reference/8.14/remote-clusters.html#remote-clusters-security-models that was previously a beta feature and is released as GA with 8.14.0
0
Attacker Value
Unknown
CVE-2024-4190
Disclosure Date: June 11, 2024 (last updated February 26, 2025)
Stored Cross-Site Scripting (XSS) vulnerabilities have been identified in OpenText ArcSight Logger. The vulnerabilities could be remotely exploited.
0
Attacker Value
Unknown
CVE-2024-33565
Disclosure Date: June 09, 2024 (last updated February 26, 2025)
Missing Authorization vulnerability in UkrSolution Barcode Scanner with Inventory & Order Manager.This issue affects Barcode Scanner with Inventory & Order Manager: from n/a through 1.5.3.
0
Attacker Value
Unknown
CVE-2024-37407
Disclosure Date: June 08, 2024 (last updated February 26, 2025)
Libarchive before 3.7.4 allows name out-of-bounds access when a ZIP archive has an empty-name file and mac-ext is enabled. This occurs in slurp_central_directory in archive_read_support_format_zip.c.
0
Attacker Value
Unknown
CVE-2024-3049
Disclosure Date: June 06, 2024 (last updated February 26, 2025)
A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcry_md_get_algo_dlen(), it may allow an invalid HMAC to be accepted by the Booth server.
0
Attacker Value
Unknown
CVE-2023-26521
Disclosure Date: June 03, 2024 (last updated February 26, 2025)
Missing Authorization vulnerability in CodePeople Search in Place allows Functionality Misuse.This issue affects Search in Place: from n/a through 1.0.104.
0