|
309031
|
5.4 |
MEDIUM
Network
|
microfocus
|
netiq_access_manager
|
Improper Input Validation vulnerability in OpenText NetIQ Access Manager leads to Cross-Site Scripting (XSS) attack. This issue affects NetIQ Access Manager before 5.0.4.1 and 5.1.
|
CWE-79
Cross-site Scripting
|
CVE-2024-4554
|
2024-09-20 03:15 |
2024-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309032
|
7.1 |
HIGH
Local
|
stripe
|
stripe-cli
|
stripe-cli is a command-line tool for the payment processor Stripe. A vulnerability exists in stripe-cli starting in version 1.11.1 and prior to version 1.21.3 where a plugin package containing a man…
|
CWE-22
Path Traversal
|
CVE-2024-45401
|
2024-09-20 03:12 |
2024-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309033
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
pktgen: use cpus_read_lock() in pg_net_init()
I have seen the WARN_ON(smp_processor_id() != cpu) firing
in pktgen_thread_worker()…
|
NVD-CWE-noinfo
|
CVE-2024-46681
|
2024-09-20 03:10 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309034
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
binfmt_elf_fdpic: fix AUXV size calculation when ELF_HWCAP2 is defined
create_elf_fdpic_tables() does not correctly account the s…
|
CWE-131
Incorrect Calculation of Buffer Size
|
CVE-2024-46684
|
2024-09-20 03:04 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309035
|
6.1 |
MEDIUM
Network
|
mlewand
|
open_link
|
ckeditor-plugin-openlink is a plugin for the CKEditor JavaScript text editor that extends the context menu with a possibility to open a link in a new tab. A vulnerability in versions of the plugin pr…
|
CWE-79
Cross-site Scripting
|
CVE-2024-45400
|
2024-09-20 03:04 |
2024-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309036
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
erofs: fix out-of-bound access when z_erofs_gbuf_growsize() partially fails
If z_erofs_gbuf_growsize() partially fails on a globa…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-46688
|
2024-09-20 03:01 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309037
|
5.3 |
MEDIUM
Network
|
apple
|
visionos
|
The issue was addressed by suspending Persona when the virtual keyboard is active. This issue is fixed in visionOS 1.3. Inputs to the virtual keyboard may be inferred from Persona.
|
NVD-CWE-noinfo
|
CVE-2024-40865
|
2024-09-20 02:58 |
2024-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309038
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
nfsd: ensure that nfsd4_fattr_args.context is zeroed out
If nfsd4_encode_fattr4 ends up doing a "goto out" before we get to
check…
|
CWE-665
Improper Initialization
|
CVE-2024-46697
|
2024-09-20 02:53 |
2024-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309039
|
9.8 |
CRITICAL
Network
|
flycass
|
flycass
|
FlyCASS CASS and KCM systems did not correctly filter SQL queries, which
made them vulnerable to attack by outside attackers with no
authentication.
|
CWE-89
SQL Injection
|
CVE-2024-8395
|
2024-09-20 02:53 |
2024-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309040
|
4.4 |
MEDIUM
Local
|
tcpdump
|
libpcap
|
In affected libpcap versions during the setup of a remote packet capture the internal function sock_initaddress() calls getaddrinfo() and possibly freeaddrinfo(), but does not clearly indicate to the…
|
CWE-415
Double Free
|
CVE-2023-7256
|
2024-09-20 02:53 |
2024-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|