|
308741
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
An issue was addressed with improved handling of temporary files. This issue is fixed in macOS Ventura 13.7, macOS Sonoma 14.7, macOS Sequoia 15. An app may be able to read sensitive location informa…
|
NVD-CWE-noinfo
|
CVE-2024-44181
|
2024-09-25 03:39 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308742
|
7.5 |
HIGH
Network
|
apple
|
macos
|
The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15. A logic issue existed where a process may be able to capture screen contents without user consent.
|
NVD-CWE-noinfo
|
CVE-2024-44189
|
2024-09-25 03:33 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308743
|
2.4 |
LOW
Physics
|
apple
|
iphone_os ipad_os
|
The issue was addressed with improved checks. This issue is fixed in iOS 18 and iPadOS 18. An attacker with physical access may be able to access contacts from the lock screen.
|
NVD-CWE-noinfo
|
CVE-2024-44139
|
2024-09-25 03:30 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308744
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
This issue was addressed with improved redaction of sensitive information. This issue is fixed in macOS Sequoia 15. An app may be able to read sensitive location information.
|
NVD-CWE-noinfo
|
CVE-2024-44134
|
2024-09-25 03:26 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308745
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
This issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15. On MDM managed devices, an app may be able to bypass certain Privacy preferences.
|
NVD-CWE-noinfo
|
CVE-2024-44133
|
2024-09-25 03:24 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308746
|
9.8 |
CRITICAL
Network
|
tenda
|
ac15_firmware
|
Command Injection vulnerability in goform/SetIPTVCfg interface of Tenda AC15 V15.03.05.20 allows remote attackers to run arbitrary commands via crafted POST request.
|
CWE-77
Command Injection
|
CVE-2023-36103
|
2024-09-25 03:10 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308747
|
4.3 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2024.3.44799 user without appropriate permissions could restore workflows attached to a project
|
CWE-863
Incorrect Authorization
|
CVE-2024-47159
|
2024-09-25 03:09 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308748
|
7.8 |
HIGH
Local
|
samsung
|
exynos_1480_firmware exynos_2400_firmware
|
An issue was discovered in Samsung Mobile Processor Exynos 1480, Exynos 2400. The xclipse amdgpu driver has a reference count bug. This can lead to a use after free.
|
CWE-416
Use After Free
|
CVE-2024-31960
|
2024-09-25 03:08 |
2024-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308749
|
5.3 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2024.3.44799 access to global app config data without appropriate permissions was possible
|
CWE-863
Incorrect Authorization
|
CVE-2024-47160
|
2024-09-25 03:03 |
2024-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308750
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
An access issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15. An app may be able to access protected user data.
|
NVD-CWE-noinfo
|
CVE-2024-44186
|
2024-09-25 03:03 |
2024-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|