Show filters
590 Total Results
Displaying 51-60 of 590
Sort by:
Attacker Value
Unknown
CVE-2024-38923
Disclosure Date: December 06, 2024 (last updated December 18, 2024)
Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request to change the value of dynamic-parameter`/amcl odom_frame_id` .
0
Attacker Value
Unknown
CVE-2024-38922
Disclosure Date: December 06, 2024 (last updated December 18, 2024)
Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble version was discovered to contain a heap overflow in the nav2_amcl process. This vulnerability is triggered via sending a crafted message to the component /initialpose.
0
Attacker Value
Unknown
CVE-2024-38921
Disclosure Date: December 06, 2024 (last updated December 18, 2024)
Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request for change the value of dynamic-parameter`/amcl z_rand ` .
0
Attacker Value
Unknown
CVE-2024-30962
Disclosure Date: December 05, 2024 (last updated December 19, 2024)
Buffer Overflow vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via the nav2_amcl process
0
Attacker Value
Unknown
CVE-2024-30961
Disclosure Date: December 05, 2024 (last updated December 19, 2024)
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via the error-thrown mechanism in nav2_bt_navigator.
0
Attacker Value
Unknown
CVE-2024-53992
Disclosure Date: December 02, 2024 (last updated December 21, 2024)
unzip-bot is a Telegram bot to extract various types of archives. Users could exploit unsanitized inputs to inject malicious commands that are executed through subprocess.Popen with shell=True. Attackers can exploit this vulnerability using a crafted archive name, password, or video name. This vulnerability is fixed in 7.0.3a.
0
Attacker Value
Unknown
CVE-2024-33056
Disclosure Date: December 02, 2024 (last updated December 21, 2024)
Memory corruption when allocating and accessing an entry in an SMEM partition continuously.
0
Attacker Value
Unknown
CVE-2024-33044
Disclosure Date: December 02, 2024 (last updated December 21, 2024)
Memory corruption while Configuring the SMR/S2CR register in Bypass mode.
0
Attacker Value
Unknown
CVE-2024-52431
Disclosure Date: November 18, 2024 (last updated November 21, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pressaholic WordPress Video Robot - The Ultimate Video Importer allows SQL Injection.This issue affects WordPress Video Robot - The Ultimate Video Importer: from n/a through 1.20.0.
0
Attacker Value
Unknown
CVE-2024-9192
Disclosure Date: November 16, 2024 (last updated January 06, 2025)
The WordPress Video Robot - The Ultimate Video Importer plugin for WordPress is vulnerable to privilege escalation due to insufficient validation on user meta that can be updated in the wpvr_rate_request_result() function in all versions up to, and including, 1.20.0. This makes it possible for authenticated attackers, with subscriber-level access and above, to update their user meta on a WordPress site. This can be leveraged to update their capabilities to that of an administrator.
0