Show filters
744 Total Results
Displaying 41-50 of 744
Sort by:
Attacker Value
Unknown

CVE-2024-42390

Disclosure Date: November 18, 2024 (last updated November 20, 2024)
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.
Attacker Value
Unknown

CVE-2024-42389

Disclosure Date: November 18, 2024 (last updated November 20, 2024)
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.
Attacker Value
Unknown

CVE-2024-42388

Disclosure Date: November 18, 2024 (last updated November 20, 2024)
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.
Attacker Value
Unknown

CVE-2024-42387

Disclosure Date: November 18, 2024 (last updated November 20, 2024)
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and force the application to read unintended heap memory space.
Attacker Value
Unknown

CVE-2024-42386

Disclosure Date: November 18, 2024 (last updated November 20, 2024)
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application.
Attacker Value
Unknown

CVE-2024-42385

Disclosure Date: November 18, 2024 (last updated November 20, 2024)
Improper Neutralization of Delimiters vulnerability in Cesanta Mongoose Web Server v7.14 allows to trigger an out-of-bound memory write if the PEM certificate contains unexpected characters.
Attacker Value
Unknown

CVE-2024-42384

Disclosure Date: November 18, 2024 (last updated November 20, 2024)
Integer Overflow or Wraparound vulnerability in Cesanta Mongoose Web Server v7.14 allows an attacker to send an unexpected TLS packet and produce a segmentation fault on the application.
Attacker Value
Unknown

CVE-2024-42383

Disclosure Date: November 18, 2024 (last updated November 20, 2024)
Use of Out-of-range Pointer Offset vulnerability in Cesanta Mongoose Web Server v7.14 allows to write a NULL byte value beyond the memory space dedicated for the hostname field.
Attacker Value
Unknown

CVE-2024-51997

Disclosure Date: November 08, 2024 (last updated November 09, 2024)
Trustee is a set of tools and components for attesting confidential guests and providing secrets to them. The ART (**Attestation Results Token**) token, generated by AS, could be manipulated by MITM attacker, but the verifier (CoCo Verification Demander like KBS) could still verify it successfully. In the payload of ART token, the ‘jwk’ could be replaced by attacker with his own pub key. Then attacker can use his own corresponding private key to sign the crafted ART token. Based on current code implementation (v0.8.0), such replacement and modification can not be detected. This issue has been addressed in version 0.8.2 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
0
Attacker Value
Unknown

CVE-2024-9626

Disclosure Date: October 26, 2024 (last updated October 26, 2024)
The Editorial Assistant by Sovrn plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ajax_zemanta_set_featured_image' function in versions up to, and including, 1.3.3. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload attachment files (such as jpg, png, txt, zip), and set the post featured image.
0