|
309341
|
7.8 |
HIGH
Local
|
google
|
android
|
In ppmp_unprotect_buf of drm/code/drm_fw.c, there is a possible memory corruption due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privi…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-44093
|
2024-09-18 22:42 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309342
|
7.8 |
HIGH
Local
|
google
|
android
|
In ppmp_protect_mfcfw_buf of code/drm_fw.c, there is a possible memory corruption due to improper input validation. This could lead to local escalation of privilege with no additional execution privi…
|
CWE-787
Out-of-bounds Write
|
CVE-2024-44094
|
2024-09-18 22:37 |
2024-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309343
|
7.5 |
HIGH
Network
|
gitlab
|
gitlab
|
ReDoS flaw in RefMatcher when matching branch names using wildcards in GitLab EE/CE affecting all versions from 11.3 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2 allows denial of s…
|
CWE-1333
Inefficient Regular Expression Complexity
|
CVE-2024-2800
|
2024-09-18 21:42 |
2024-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309344
|
5.4 |
MEDIUM
Network
|
gitlab
|
gitlab
|
A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 prior 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2. When view…
|
CWE-79
Cross-site Scripting
|
CVE-2024-4207
|
2024-09-18 21:41 |
2024-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309345
|
8.8 |
HIGH
Network
|
google microsoft
|
chrome edge_chromium
|
Inappropriate implementation in V8 in Google Chrome prior to 128.0.6613.84 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
|
CWE-787
Out-of-bounds Write
|
CVE-2024-7965
|
2024-09-18 21:40 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309346
|
8.8 |
HIGH
Network
|
redhat
|
openshift_data_science openshift_ai
|
A vulnerability was found in OpenShift AI that allows for authentication bypass and privilege escalation across models within the same namespace. When deploying AI models, the UI provides the option …
|
NVD-CWE-Other
|
CVE-2024-7557
|
2024-09-18 16:15 |
2024-08-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309347
|
6.7 |
MEDIUM
Local
|
microsoft
|
windows_10_1507 windows_10_1809 windows_server_2019 windows_server_2022 windows_11_21h2 windows_10_21h2 windows_11_22h2 windows_10_22h2 windows_11_23h2 windows_server_2022_…
|
Summary:
Microsoft was notified that an elevation of privilege vulnerability exists in Windows based systems supporting Virtualization Based Security (VBS), including a subset of Azure Virtual Machin…
|
NVD-CWE-Other
|
CVE-2024-21302
|
2024-09-18 09:15 |
2024-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309348
|
7.5 |
HIGH
Network
|
containers
|
aardvark-dns
|
A flaw was found in Aardvark-dns, which is vulnerable to a Denial of Service attack due to the serial processing of TCP DNS queries. An attacker can exploit this flaw by keeping a TCP connection open…
|
NVD-CWE-noinfo
|
CVE-2024-8418
|
2024-09-18 05:15 |
2024-09-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309349
|
4.3 |
MEDIUM
Network
|
imagerecycle
|
imagerecycle_pdf_\&_image_compression
|
The ImageRecycle pdf & image compression plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.14. This is due to missing or incorrect nonce valid…
|
CWE-352
Origin Validation Error
|
CVE-2024-8120
|
2024-09-18 05:07 |
2024-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309350
|
4.8 |
MEDIUM
Network
|
cleversoft
|
clever_addons_for_elementor
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in CleverSoft Clever Addons for Elementor allows Stored XSS.This issue affects Clever Addons …
|
CWE-79
Cross-site Scripting
|
CVE-2024-43324
|
2024-09-18 05:04 |
2024-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|