Aggregator
CVE-2019-8660 | Apple tvOS up to 12.3 Core Data memory corruption (HT210351 / EDB-47193)
10 months 4 weeks ago
A vulnerability, which was classified as critical, has been found in Apple tvOS up to 12.3. This issue affects some unknown processing of the component Core Data. The manipulation leads to memory corruption.
The identification of this vulnerability is CVE-2019-8660. The attack may be initiated remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
Hackers use Windows RID hijacking to create hidden admin account
10 months 4 weeks ago
A North Korean threat group has been using a technique called RID hijacking that tricks Windows into treating a low-privileged account as one with administrator permissions. [...]
Bill Toulas
CVE-2024-3385 | Palo Alto Networks PAN-OS up to 9.0.17-h3/10.1.11/10.2.7/11.0.2 Packet denial of service
10 months 4 weeks ago
A vulnerability has been found in Palo Alto Networks PAN-OS up to 9.0.17-h3/10.1.11/10.2.7/11.0.2 and classified as critical. Affected by this vulnerability is an unknown functionality of the component Packet Handler. The manipulation leads to denial of service.
This vulnerability is known as CVE-2024-3385. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-3386 | Palo Alto Networks PAN-OS prior 11.1.0 interpretation conflict
10 months 4 weeks ago
A vulnerability was found in Palo Alto Networks PAN-OS up to 9.0.17-h1/10.0.12/10.1.9-h2/10.2.4-h1/11.0.1-h1. It has been classified as problematic. This affects an unknown part. The manipulation leads to interpretation conflict.
This vulnerability is uniquely identified as CVE-2024-3386. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-3388 | Palo Alto Networks PAN-OS up to 8.1.25/9.0.17-h3/10.1.11-h3/10.2.7-h2 GlobalProtect Gateway privileges management
10 months 4 weeks ago
A vulnerability was found in Palo Alto Networks PAN-OS up to 8.1.25/9.0.17-h3/10.1.11-h3/10.2.7-h2. It has been declared as critical. This vulnerability affects unknown code of the component GlobalProtect Gateway. The manipulation leads to improper privilege management.
This vulnerability was named CVE-2024-3388. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-4318 | Tutor LMS Plugin up to 2.7.0 on WordPress sql injection
10 months 4 weeks ago
A vulnerability has been found in Tutor LMS Plugin up to 2.7.0 on WordPress and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation leads to sql injection.
This vulnerability is known as CVE-2024-4318. The attack can be launched remotely. There is no exploit available.
vuldb.com
CVE-2024-4279 | Tutor LMS Plugin up to 2.7.0 on WordPress Course resource injection
10 months 4 weeks ago
A vulnerability was found in Tutor LMS Plugin up to 2.7.0 on WordPress. It has been declared as problematic. This vulnerability affects unknown code of the component Course Handler. The manipulation leads to improper control of resource identifiers.
This vulnerability was named CVE-2024-4279. The attack can be initiated remotely. There is no exploit available.
vuldb.com
CVE-2021-47315 | Linux Kernel up to 5.13.3 drivers/memory/fsl_ifc.c fsl_ifc_ctrl_probe memory leak
10 months 4 weeks ago
A vulnerability was found in Linux Kernel up to 5.13.3. It has been classified as critical. This affects the function fsl_ifc_ctrl_probe of the file drivers/memory/fsl_ifc.c. The manipulation leads to memory leak.
This vulnerability is uniquely identified as CVE-2021-47315. The attack can only be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-26920 | Linux Kernel up to 6.7.5 register_snapshot_trigger Privilege Escalation (Nessus ID 210815)
10 months 4 weeks ago
A vulnerability has been found in Linux Kernel up to 6.7.5 and classified as problematic. Affected by this vulnerability is the function register_snapshot_trigger. The manipulation leads to Privilege Escalation.
This vulnerability is known as CVE-2024-26920. The attack needs to be done within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2006-4253 | Mozilla Firefox up to 1.5.0.6 Text Display access control (MFSA2006-59 / EDB-28380)
10 months 4 weeks ago
A vulnerability was found in Mozilla Firefox. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Text Display Handler. The manipulation leads to improper access controls.
This vulnerability is known as CVE-2006-4253. The attack can be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-24966 | F5 F5OS LDAP Remote Authentication authorization (K000133111)
10 months 4 weeks ago
A vulnerability was found in F5 F5OS. It has been rated as problematic. This issue affects some unknown processing of the component LDAP Remote Authentication. The manipulation leads to incorrect authorization.
The identification of this vulnerability is CVE-2024-24966. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-23607 | F5 F5OS-A/F5OS-C QKView Utility path traversal (K000132800)
10 months 4 weeks ago
A vulnerability, which was classified as problematic, has been found in F5 F5OS-A and F5OS-C. Affected by this issue is some unknown functionality of the component QKView Utility. The manipulation leads to path traversal.
This vulnerability is handled as CVE-2024-23607. It is possible to launch the attack on the local host. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-24989 | F5 NGINX Plus/NGINX Open Source QUIC Module null pointer dereference (K000138444)
10 months 4 weeks ago
A vulnerability, which was classified as critical, was found in F5 NGINX Plus and NGINX Open Source. This affects an unknown part of the component QUIC Module. The manipulation leads to null pointer dereference.
This vulnerability is uniquely identified as CVE-2024-24989. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-24990 | F5 NGINX Plus/NGINX Open Source QUIC Module use after free (K000138445)
10 months 4 weeks ago
A vulnerability classified as critical has been found in F5 NGINX Plus and NGINX Open Source. This affects an unknown part of the component QUIC Module. The manipulation leads to use after free.
This vulnerability is uniquely identified as CVE-2024-24990. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-3131 | SourceCodester Computer Laboratory Management System 1.0 Master.php?f=save_category id sql injection
10 months 4 weeks ago
A vulnerability was found in SourceCodester Computer Laboratory Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /classes/Master.php?f=save_category. The manipulation of the argument id leads to sql injection.
This vulnerability was named CVE-2024-3131. The attack can be initiated remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-3139 | SourceCodester Computer Laboratory Management System 1.0 Users.php?f=save save_users id improper authorization
10 months 4 weeks ago
A vulnerability, which was classified as critical, has been found in SourceCodester Computer Laboratory Management System 1.0. Affected by this issue is the function save_users of the file /classes/Users.php?f=save. The manipulation of the argument id leads to improper authorization.
This vulnerability is handled as CVE-2024-3139. The attack may be launched remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-3140 | SourceCodester Computer Laboratory Management System 1.0 Users.php?f=save middlename cross site scripting
10 months 4 weeks ago
A vulnerability, which was classified as problematic, was found in SourceCodester Computer Laboratory Management System 1.0. This affects an unknown part of the file /classes/Users.php?f=save. The manipulation of the argument middlename leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-3140. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
vuldb.com
CVE-2024-28951 | OpenHarmony up to 4.0.0 Pre-installed Apps use after free
10 months 4 weeks ago
A vulnerability was found in OpenHarmony up to 4.0.0 and classified as problematic. This issue affects some unknown processing of the component Pre-installed Apps. The manipulation leads to use after free.
The identification of this vulnerability is CVE-2024-28951. Local access is required to approach this attack. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-29834 | Apache Pulsar up to 2.10.6/2.11.4/3.0.3/3.1.3/3.2.1 Topic improper authorization
10 months 4 weeks ago
A vulnerability classified as critical was found in Apache Pulsar up to 2.10.6/2.11.4/3.0.3/3.1.3/3.2.1. This vulnerability affects unknown code of the component Topic Handler. The manipulation leads to improper authorization.
This vulnerability was named CVE-2024-29834. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com