|
311601
|
7.8 |
HIGH
Local
|
microsoft
|
windows_server_2012 windows_server_2016 windows_server_2022 windows_server_2019
|
Windows Kernel Elevation of Privilege Vulnerability
|
NVD-CWE-noinfo
|
CVE-2024-37979
|
2024-10-17 02:41 |
2024-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311602
|
5.5 |
MEDIUM
Local
|
openatom
|
openharmony
|
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS by memory leak.
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2024-43696
|
2024-10-17 02:38 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311603
|
- |
|
-
|
-
|
In TP-Link TL-WDR7660 v1.0, the guestRuleJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.
|
-
|
CVE-2024-48714
|
2024-10-17 02:35 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311604
|
- |
|
-
|
-
|
In TP-Link TL-WDR7660 1.0, the wacWhitelistJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.
|
-
|
CVE-2024-48713
|
2024-10-17 02:35 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311605
|
- |
|
-
|
-
|
In TP-Link TL-WDR7660 1.0, the rtRuleJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.
|
-
|
CVE-2024-48712
|
2024-10-17 02:35 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311606
|
- |
|
-
|
-
|
In TP-Link TL-WDR7660 1.0, the wlanTimerRuleJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.
|
-
|
CVE-2024-48710
|
2024-10-17 02:35 |
2024-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311607
|
9.8 |
CRITICAL
Network
|
xerox
|
freeflow_core
|
Pre-Auth RCE via Path Traversal
|
CWE-22
Path Traversal
|
CVE-2024-47556
|
2024-10-17 02:34 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311608
|
6.1 |
MEDIUM
Local
|
qualcomm
|
wsa8835_firmware wsa8830_firmware wcd9380_firmware snapdragon_8\+_gen_2_mobile_platform_firmware snapdragon_8\+_gen_1_mobile_platform_firmware snapdragon_8_gen_3_mobile_platform_firmwa…
|
Information disclosure while sending implicit broadcast containing APP launch information.
|
CWE-863
Incorrect Authorization
|
CVE-2024-38425
|
2024-10-17 02:34 |
2024-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311609
|
9.8 |
CRITICAL
Network
|
xerox
|
freeflow_core
|
Pre-Auth RCE via Path Traversal
|
CWE-22
Path Traversal
|
CVE-2024-47557
|
2024-10-17 02:33 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311610
|
6.8 |
MEDIUM
Adjacent
|
netgear
|
ex3700_firmware ex6100_firmware ex6120_firmware
|
Netgear EX6120 v1.0.0.68, Netgear EX6100 v1.0.2.28, and Netgear EX3700 v1.0.0.96 are vulnerable to command injection in operating_mode.cgi via the ap_mode parameter.
|
CWE-77
Command Injection
|
CVE-2024-35519
|
2024-10-17 02:17 |
2024-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|