Show filters
381 Total Results
Displaying 91-100 of 381
Sort by:
Attacker Value
Unknown

CVE-2024-21479

Disclosure Date: August 05, 2024 (last updated January 05, 2025)
Transient DOS during music playback of ALAC content.
Attacker Value
Unknown

CVE-2024-21467

Disclosure Date: August 05, 2024 (last updated January 05, 2025)
Information disclosure while handling beacon probe frame during scan entry generation in client side.
Attacker Value
Unknown

CVE-2024-21459

Disclosure Date: August 05, 2024 (last updated January 05, 2025)
Information disclosure while handling beacon or probe response frame in STA.
Attacker Value
Unknown

CVE-2024-20396

Disclosure Date: July 17, 2024 (last updated July 18, 2024)
A vulnerability in the protocol handlers of Cisco Webex App could allow an unauthenticated, remote attacker to gain access to sensitive information. This vulnerability exists because the affected application does not safely handle file protocol handlers. An attacker could exploit this vulnerability by persuading a user to follow a link that is designed to cause the application to send requests. If the attacker can observe transmitted traffic in a privileged network position, a successful exploit could allow the attacker to capture sensitive information, including credential information, from the requests.
0
Attacker Value
Unknown

CVE-2024-20395

Disclosure Date: July 17, 2024 (last updated July 18, 2024)
A vulnerability in the media retrieval functionality of Cisco Webex App could allow an unauthenticated, adjacent attacker to gain access to sensitive session information. This vulnerability is due to insecure transmission of requests to backend services when the app accesses embedded media, such as images. An attacker could exploit this vulnerability by sending a message with embedded media that is stored on a messaging server to a targeted user. If the attacker can observe transmitted traffic in a privileged network position, a successful exploit could allow the attacker to capture session token information from insecurely transmitted requests and possibly reuse the captured session information to take further actions as the targeted user.
0
Attacker Value
Unknown

CVE-2024-3653

Disclosure Date: July 08, 2024 (last updated November 25, 2024)
A vulnerability was found in Undertow. This issue requires enabling the learning-push handler in the server's config, which is disabled by default, leaving the maxAge config in the handler unconfigured. The default is -1, which makes the handler vulnerable. If someone overwrites that config, the server is not subject to the attack. The attacker needs to be able to reach the server with a normal HTTP request.
0
Attacker Value
Unknown

CVE-2024-23380

Disclosure Date: July 01, 2024 (last updated July 03, 2024)
Memory corruption while handling user packets during VBO bind operation.
Attacker Value
Unknown

CVE-2024-23373

Disclosure Date: July 01, 2024 (last updated July 03, 2024)
Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released.
Attacker Value
Unknown

CVE-2024-23372

Disclosure Date: July 01, 2024 (last updated July 03, 2024)
Memory corruption while invoking IOCTL call for GPU memory allocation and size param is greater than expected size.
Attacker Value
Unknown

CVE-2024-23368

Disclosure Date: July 01, 2024 (last updated July 03, 2024)
Memory corruption when allocating and accessing an entry in an SMEM partition.