|
249011
|
5.9 |
MEDIUM
Network
|
mudler
|
localai
|
mudler/localai version 2.17.1 is vulnerable to a Timing Attack. This type of side-channel attack allows an attacker to compromise the cryptosystem by analyzing the time taken to execute cryptographic…
|
CWE-203
Information Exposure Through Discrepancy
|
CVE-2024-7010
|
2024-11-14 23:15 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249012
|
5.5 |
MEDIUM
Local
|
adobe
|
bridge
|
Bridge versions 13.0.9, 14.1.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypa…
|
CWE-125
Out-of-bounds Read
|
CVE-2024-45147
|
2024-11-14 22:58 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249013
|
6.8 |
MEDIUM
Adjacent
|
zyxel
|
gs1900-8_firmware gs1900-8hp_firmware gs1900-10hp_firmware gs1900-16_firmware gs1900-24_firmware gs1900-24e_firmware gs1900-24ep_firmware gs1900-24hpv2_firmware gs1900-48_firm…
|
A post-authentication command injection vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version V2.80(AAHN.1)C0 and earlier could allow an authenticated, LAN-based attacker wi…
|
CWE-78
OS Command
|
CVE-2024-8881
|
2024-11-14 22:51 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249014
|
4.5 |
MEDIUM
Adjacent
|
zyxel
|
gs1900-8_firmware gs1900-8hp_firmware gs1900-10hp_firmware gs1900-16_firmware gs1900-24_firmware gs1900-24e_firmware gs1900-24ep_firmware gs1900-24hpv2_firmware gs1900-48_firm…
|
A buffer overflow vulnerability in the CGI program in the Zyxel GS1900-48 switch firmware version V2.80(AAHN.1)C0 and earlier could allow an authenticated, LAN-based attacker with administrator privi…
|
CWE-120
Classic Buffer Overflow
|
CVE-2024-8882
|
2024-11-14 22:42 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249015
|
5.3 |
MEDIUM
Network
|
neomutt mutt redhat
|
neomutt mutt enterprise_linux
|
In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing which allows an attacker to reuse an unencrypted but signed email message to impersonate the original …
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2024-49394
|
2024-11-14 22:38 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249016
|
5.3 |
MEDIUM
Network
|
neomutt mutt redhat
|
neomutt mutt enterprise_linux
|
In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field by inferring from the recipients info.
|
NVD-CWE-noinfo
|
CVE-2024-49395
|
2024-11-14 22:33 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249017
|
5.4 |
MEDIUM
Network
|
leevio
|
happy_addons_for_elementor
|
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the before_label parameter in the Image Comparison widget in all versions up to, and including, 3.…
|
CWE-79
Cross-site Scripting
|
CVE-2024-10538
|
2024-11-14 22:27 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249018
|
9.8 |
CRITICAL
Network
|
oretnom23
|
simple_music_cloud_community_system
|
A vulnerability classified as critical was found in SourceCodester Simple Music Cloud Community System 1.0. This vulnerability affects unknown code of the file /music/ajax.php?action=signup. The mani…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-11054
|
2024-11-14 11:43 |
2024-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249019
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
wifi: cfg80211: clear wdev->cqm_config pointer on free
When we free wdev->cqm_config when unregistering, we also
need to clear ou…
|
CWE-415
Double Free
|
CVE-2024-50235
|
2024-11-14 11:26 |
2024-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249020
|
7.0 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
wifi: iwlegacy: Clear stale interrupts before resuming device
iwl4965 fails upon resume from hibernation on my laptop. The reason…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2024-50234
|
2024-11-14 11:25 |
2024-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|