Show filters
590 Total Results
Displaying 81-90 of 590
Sort by:
Attacker Value
Unknown

CVE-2024-6722

Disclosure Date: September 04, 2024 (last updated October 08, 2024)
The Chatbot Support AI: Free ChatGPT Chatbot, Woocommerce Chatbot WordPress plugin through 1.0.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
Attacker Value
Unknown

CVE-2024-45307

Disclosure Date: September 03, 2024 (last updated September 07, 2024)
SudoBot, a Discord moderation bot, is vulnerable to privilege escalation and exploit of the `-config` command in versions prior to 9.26.7. Anyone is theoretically able to update any configuration of the bot and potentially gain control over the bot's settings. Every version of v9 before v9.26.7 is affected. Other versions (e.g. v8) are not affected. Users should upgrade to version 9.26.7 to receive a patch. A workaround would be to create a command permission overwrite in the Database. A SQL statement provided in the GitHub Security Advisor can be executed to create a overwrite that disallows users without `ManageGuild` permission to run the `-config` command. Run the SQL statement for every server the bot is in, and replace `<guild_id>` with the appropriate Guild ID each time.
Attacker Value
Unknown

CVE-2024-38402

Disclosure Date: September 02, 2024 (last updated September 06, 2024)
Memory corruption while processing IOCTL call for getting group info.
Attacker Value
Unknown

CVE-2024-33060

Disclosure Date: September 02, 2024 (last updated September 05, 2024)
Memory corruption when two threads try to map and unmap a single node simultaneously.
Attacker Value
Unknown

CVE-2024-33057

Disclosure Date: September 02, 2024 (last updated September 05, 2024)
Transient DOS while parsing the multi-link element Control field when common information length check is missing before updating the location.
Attacker Value
Unknown

CVE-2024-33052

Disclosure Date: September 02, 2024 (last updated September 05, 2024)
Memory corruption when user provides data for FM HCI command control operations.
Attacker Value
Unknown

CVE-2024-33051

Disclosure Date: September 02, 2024 (last updated September 05, 2024)
Transient DOS while processing TIM IE from beacon frame as there is no check for IE length.
Attacker Value
Unknown

CVE-2024-33050

Disclosure Date: September 02, 2024 (last updated September 05, 2024)
Transient DOS while parsing MBSSID during new IE generation in beacon/probe frame when IE length check is either missing or improper.
Attacker Value
Unknown

CVE-2024-33048

Disclosure Date: September 02, 2024 (last updated September 05, 2024)
Transient DOS while parsing the received TID-to-link mapping element of beacon/probe response frame.
Attacker Value
Unknown

CVE-2024-33045

Disclosure Date: September 02, 2024 (last updated September 05, 2024)
Memory corruption when BTFM client sends new messages over Slimbus to ADSP.