|
249701
|
7.5 |
HIGH
Network
|
mozilla
|
thunderbird firefox
|
A permission leak could have occurred from a trusted site to an untrusted site via `embed` or `object` elements. This vulnerability affects Firefox < 132, Firefox ESR < 128.4, Firefox ESR < 115.17, T…
|
NVD-CWE-noinfo
|
CVE-2024-10458
|
2024-11-1 00:03 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249702
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
vrf: revert "vrf: Remove unnecessary RCU-bh critical section"
This reverts commit 504fc6f4f7f681d2a03aa5f68aad549d90eab853.
dev_…
|
CWE-667
Improper Locking
|
CVE-2024-49980
|
2024-10-31 23:58 |
2024-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249703
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
iommu/vt-d: Fix PCI device refcount leak in has_external_pci()
for_each_pci_dev() is implemented by pci_get_device(). The comment…
|
NVD-CWE-Other
|
CVE-2022-49000
|
2024-10-31 23:56 |
2024-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249704
|
6.1 |
MEDIUM
Network
|
foxskav
|
bet_wc_2018_russia
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Foxskav Bet WC 2018 Russia allows Reflected XSS.This issue affects Bet WC 2018 Russia: fro…
|
CWE-79
Cross-site Scripting
|
CVE-2024-49637
|
2024-10-31 23:52 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249705
|
6.1 |
MEDIUM
Network
|
prashantmavinkurve
|
agile_video_player_lite
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Prashant Mavinkurve Agile Video Player Lite allows Reflected XSS.This issue affects Agile …
|
CWE-79
Cross-site Scripting
|
CVE-2024-49636
|
2024-10-31 23:51 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249706
|
4.3 |
MEDIUM
Network
|
hitachienergy
|
tro610_firmware tro620_firmware tro670_firmware
|
Profile files from TRO600 series radios are extracted in plain-text
and encrypted file formats. Profile files provide potential attackers
valuable configuration information about the Tropos network. …
|
CWE-212
Improper Removal of Sensitive Information Before Storage or Transfer
|
CVE-2024-41156
|
2024-10-31 23:49 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249707
|
7.1 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
ipv4: Handle attempt to delete multipath route when fib_info contains an nh reference
Gwangun Jung reported a slab-out-of-bounds …
|
CWE-125
Out-of-bounds Read
|
CVE-2022-48999
|
2024-10-31 23:44 |
2024-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249708
|
7.2 |
HIGH
Network
|
hitachienergy
|
tro610_firmware tro620_firmware tro670_firmware
|
Command injection vulnerability in the Edge Computing UI for the
TRO600 series radios that allows for the execution of arbitrary system commands. If exploited, an attacker with write access to the
we…
|
CWE-77
Command Injection
|
CVE-2024-41153
|
2024-10-31 23:37 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249709
|
5.5 |
MEDIUM
Local
|
cisco
|
ata_191_firmware ata_192_firmware
|
A vulnerability in the web-based management interface of Cisco ATA 190 Series Multiplatform Analog Telephone Adapter firmware could allow an authenticated, local attacker with low privileges to view …
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2024-20462
|
2024-10-31 23:35 |
2024-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249710
|
8.8 |
HIGH
Network
|
cisco
|
ata_191_firmware ata_192_firmware
|
A vulnerability in the web-based management interface of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an authenticated, remote attacker with low privileges to run commands as an…
|
NVD-CWE-Other
|
CVE-2024-20420
|
2024-10-31 23:35 |
2024-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|