|
304931
|
5.3 |
MEDIUM
Network
|
neomutt mutt redhat
|
neomutt mutt enterprise_linux
|
In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing which allows an attacker to reuse an unencrypted but signed email message to impersonate the original …
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2024-49394
|
2024-11-14 22:38 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304932
|
5.3 |
MEDIUM
Network
|
neomutt mutt redhat
|
neomutt mutt enterprise_linux
|
In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field by inferring from the recipients info.
|
NVD-CWE-noinfo
|
CVE-2024-49395
|
2024-11-14 22:33 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304933
|
5.4 |
MEDIUM
Network
|
leevio
|
happy_addons_for_elementor
|
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the before_label parameter in the Image Comparison widget in all versions up to, and including, 3.…
|
CWE-79
Cross-site Scripting
|
CVE-2024-10538
|
2024-11-14 22:27 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304934
|
9.8 |
CRITICAL
Network
|
oretnom23
|
simple_music_cloud_community_system
|
A vulnerability classified as critical was found in SourceCodester Simple Music Cloud Community System 1.0. This vulnerability affects unknown code of the file /music/ajax.php?action=signup. The mani…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-11054
|
2024-11-14 11:43 |
2024-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304935
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
wifi: cfg80211: clear wdev->cqm_config pointer on free
When we free wdev->cqm_config when unregistering, we also
need to clear ou…
|
CWE-415
Double Free
|
CVE-2024-50235
|
2024-11-14 11:26 |
2024-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304936
|
7.0 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
wifi: iwlegacy: Clear stale interrupts before resuming device
iwl4965 fails upon resume from hibernation on my laptop. The reason…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2024-50234
|
2024-11-14 11:25 |
2024-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304937
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.7.1, macOS Sonoma 14.7.1. A malicious app may be able to cause a denial-of-service.
|
NVD-CWE-noinfo
|
CVE-2024-44197
|
2024-11-14 11:16 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304938
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Ventura 13.7.1, macOS Sonoma 14.7.1. An app may be able to modify protected parts of the file system.
|
NVD-CWE-noinfo
|
CVE-2024-44196
|
2024-11-14 11:15 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304939
|
7.8 |
HIGH
Local
|
artifex debian suse
|
ghostscript debian_linux linux_enterprise_high_performance_computing linux_enterprise_server linux_enterprise_server_for_sap
|
An issue was discovered in psi/zcolor.c in Artifex Ghostscript before 10.04.0. An unchecked Implementation pointer in Pattern color space could lead to arbitrary code execution.
|
CWE-824
Access of Uninitialized Pointer
|
CVE-2024-46951
|
2024-11-14 11:13 |
2024-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304940
|
7.8 |
HIGH
Local
|
artifex debian suse
|
ghostscript debian_linux linux_enterprise_high_performance_computing linux_enterprise_server linux_enterprise_server_for_sap
|
An issue was discovered in base/gsdevice.c in Artifex Ghostscript before 10.04.0. An integer overflow when parsing the filename format string (for the output filename) results in path truncation, and…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2024-46953
|
2024-11-14 11:01 |
2024-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|