A vulnerability was found in Sympa. It has been declared as critical. This vulnerability affects unknown code of the component SSO. The manipulation leads to improper authentication.
This vulnerability was named CVE-2024-55919. The attack can be initiated remotely. There is no exploit available.
A vulnerability was found in KWHotel 0.47. It has been classified as problematic. This affects an unknown part. The manipulation leads to csv injection.
This vulnerability is uniquely identified as CVE-2023-46401. The attack can only be done within the local network. There is no exploit available.
A vulnerability was found in GPAC 2.4 and classified as critical. Affected by this issue is the function isom_cenc_get_sai_by_saiz_saio of the file src/isomedia/drm_sample.c of the component MP4Box. The manipulation leads to memory corruption.
This vulnerability is handled as CVE-2024-50665. The attack needs to be approached within the local network. There is no exploit available.
A vulnerability has been found in KWHotel 0.47 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Add Guest. The manipulation leads to csv injection.
This vulnerability is known as CVE-2023-46400. Access to the local network is required for this attack to succeed. There is no exploit available.
A vulnerability, which was classified as problematic, was found in OpenImageIO 3.1.0.0dev. Affected is an unknown function of the file /imagebuf.cpp. The manipulation leads to denial of service.
This vulnerability is traded as CVE-2024-55195. Access to the local network is required for this attack. There is no exploit available.
A vulnerability classified as critical was found in GPAC 2.4. This vulnerability affects the function gf_isom_new_mpha_description of the file isomedia/sample_descs.c of the component MP4Box. The manipulation leads to heap-based buffer overflow.
This vulnerability was named CVE-2024-50664. The attack needs to be done within the local network. There is no exploit available.
A vulnerability, which was classified as problematic, has been found in nbubna store up to 2.14.2. This issue affects some unknown processing of the file store.deep.js. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-57556. The attack may be initiated remotely. There is no exploit available.
A vulnerability classified as problematic has been found in Wallos 2.41.0. This affects an unknown part of the component Profile Picture Handler. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-57386. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability was found in iTop VPN 16.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file \ProgramData\iTop VPN\Downloader\vpn6 of the component DLL Handler. The manipulation leads to uncontrolled search path.
This vulnerability is handled as CVE-2024-53588. The attack needs to be approached locally. There is no exploit available.
Also: US Prosecutors Charge Suspected North Korean IT Worker Collaborators This week, researchers spied Palo Alto firewall flaws, a North Korean IT worker conspiracy, ChatGPT as DDoS vector. Chinese hackers targeted a VPN maker, a fake PyPi package and a Russian threat actor shifted tactics. BreachForums admin faces prison and scammers used the release of Ross Ulbricht.
Hackers Unlikely to Exploit Flaws in the Wild Security researchers found an unpatchable flaw in the system that prevents commercial aircraft from crashing into each other, the U.S. federal government said in a Tuesday advisory that called the likelihood of its exploitation "unlikely" outside of a laboratory setting.
California User's Class Action Suit Says LinkedIn Violated Contract, Privacy Regs A LinkedIn user has sued the company for flouting privacy requirements by allowing third-party companies to access user data - including Premium users' private messages - to train their artificial intelligence models. A LinkedIn spokesperson called the lawsuit "false claims with no merit."
A vulnerability was found in OpenImageIO 3.1.0.0dev. It has been declared as critical. Affected by this vulnerability is an unknown functionality in the library /OpenImageIO/string_view.h. The manipulation leads to memory corruption.
This vulnerability is known as CVE-2024-55193. The attack needs to be approached within the local network. There is no exploit available.
A vulnerability was found in OpenImageIO 3.1.0.0dev. It has been classified as critical. Affected is the function OpenImageIO_v3_1_0::farmhash::inlined::Fetch64. The manipulation leads to heap-based buffer overflow.
This vulnerability is traded as CVE-2024-55192. Access to the local network is required for this attack to succeed. There is no exploit available.
A vulnerability was found in OpenImageIO 3.1.0.0dev and classified as critical. This issue affects some unknown processing in the library /OpenImageIO/fmath.h. The manipulation leads to heap-based buffer overflow.
The identification of this vulnerability is CVE-2024-55194. Access to the local network is required for this attack. There is no exploit available.