Aggregator
CVE-2024-1656 | Octopus Server up to 2024.2.2075 Content Security Policy ui layer
1 year 6 months ago
A vulnerability classified as problematic has been found in Octopus Server. Affected is an unknown function of the component Content Security Policy. The manipulation leads to improper restriction of rendered ui layers.
This vulnerability is traded as CVE-2024-1656. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-43690 | Gallagher Command Centre Server inclusion of functionality from untrusted control sphere
1 year 6 months ago
A vulnerability was found in Gallagher Command Centre Server. It has been rated as critical. This issue affects some unknown processing. The manipulation leads to inclusion of functionality from untrusted control sphere.
The identification of this vulnerability is CVE-2024-43690. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
DockerSpy: Search for images on Docker Hub, extract sensitive information
1 year 6 months ago
DockerSpy scans Docker Hub for images and retrieves sensitive information, including authentication secrets, private keys, and other confidential data. “DockerSpy was created to address the growing concern of sensitive data leaks within Docker images, especially those publicly available on DockerHub. Many developers unknowingly publish images containing secrets such as API keys, credentials, or other sensitive information. DockerSpy automates the process of fetching these images and scanning them for secrets, offering a layer of security and … More →
The post DockerSpy: Search for images on Docker Hub, extract sensitive information appeared first on Help Net Security.
Mirko Zorz
CVE-2024-31336 | Google Android PowerVR-GPU Privilege Escalation (A-337949672)
1 year 6 months ago
A vulnerability was found in Google Android. It has been declared as problematic. This vulnerability affects unknown code of the component PowerVR-GPU. The manipulation leads to Privilege Escalation.
This vulnerability was named CVE-2024-31336. The attack needs to be done within the local network. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-40652 | Google Android 12/12L/13/14 SettingsHomepageActivity.java onCreate permission
1 year 6 months ago
A vulnerability was found in Google Android 12/12L/13/14. It has been classified as critical. This affects the function onCreate of the file SettingsHomepageActivity.java. The manipulation leads to permission issues.
This vulnerability is uniquely identified as CVE-2024-40652. The attack needs to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-43040 | Renwoxing Enterprise Intelligent Management System up to 2.x /fx/baseinfo/SearchInfo parid sql injection
1 year 6 months ago
A vulnerability was found in Renwoxing Enterprise Intelligent Management System up to 2.x and classified as critical. Affected by this issue is some unknown functionality of the file /fx/baseinfo/SearchInfo. The manipulation of the argument parid leads to sql injection.
This vulnerability is handled as CVE-2024-43040. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-39808 | Gallagher Controller 6000/Controller 7000 OSDP Message buffer size
1 year 6 months ago
A vulnerability has been found in Gallagher Controller 6000 and Controller 7000 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component OSDP Message Handler. The manipulation leads to incorrect calculation of buffer size.
This vulnerability is known as CVE-2024-39808. It is possible to launch the attack on the physical device. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-40655 | Google Android 12/12L/13/14 CallScreeningServiceHelper.java bindAndGetCallIdentification permission
1 year 6 months ago
A vulnerability, which was classified as critical, was found in Google Android 12/12L/13/14. Affected is the function bindAndGetCallIdentification of the file CallScreeningServiceHelper.java. The manipulation leads to permission issues.
This vulnerability is traded as CVE-2024-40655. Local access is required to approach this attack. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-40662 | Google Android 12/12L/13/14 Uri.java scheme input validation
1 year 6 months ago
A vulnerability, which was classified as problematic, has been found in Google Android 12/12L/13/14. This issue affects the function scheme of the file Uri.java. The manipulation leads to improper input validation.
The identification of this vulnerability is CVE-2024-40662. An attack has to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-40658 | Google Android 12/12L/13/14 SoftVideoDecoderOMXComponent.cpp getConfig out-of-bounds write
1 year 6 months ago
A vulnerability classified as critical was found in Google Android 12/12L/13/14. This vulnerability affects the function getConfig of the file SoftVideoDecoderOMXComponent.cpp. The manipulation leads to out-of-bounds write.
This vulnerability was named CVE-2024-40658. The attack needs to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-24972 | Gallagher Controller 6000/Controller 7000 Web Interface buffer overflow
1 year 6 months ago
A vulnerability was found in Gallagher Controller 6000 and Controller 7000. It has been rated as critical. Affected by this issue is some unknown functionality of the component Web Interface. The manipulation leads to buffer overflow.
This vulnerability is handled as CVE-2024-24972. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-23906 | Gallagher Controller 6000/Controller 7000 cross site scripting
1 year 6 months ago
A vulnerability classified as problematic has been found in Gallagher Controller 6000 and Controller 7000. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2024-23906. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-40657 | Google Android 12/12L/13/14 AccountTypePreferenceLoader.java addPreferencesForType denial of service
1 year 6 months ago
A vulnerability was found in Google Android 12/12L/13/14. It has been declared as problematic. Affected by this vulnerability is the function addPreferencesForType of the file AccountTypePreferenceLoader.java. The manipulation leads to denial of service.
This vulnerability is known as CVE-2024-40657. Local access is required to approach this attack. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-40654 | Google Android 12/12L/13/14 permission
1 year 6 months ago
A vulnerability was found in Google Android 12/12L/13/14. It has been classified as critical. Affected is an unknown function. The manipulation leads to permission issues.
This vulnerability is traded as CVE-2024-40654. An attack has to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-40650 | Google Android 12/12L/13/14 FRP styles.xml wifi_item_edit_content state issue
1 year 6 months ago
A vulnerability was found in Google Android 12/12L/13/14 and classified as problematic. This issue affects the function wifi_item_edit_content of the file styles.xml of the component FRP. The manipulation leads to state issue.
The identification of this vulnerability is CVE-2024-40650. The attack needs to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-45596 | Directus up to 10.13.2 OpenId/Oauth2 cache containing sensitive information (GHSA-cff8-x7jv-4fm8)
1 year 6 months ago
A vulnerability has been found in Directus up to 10.13.2 and classified as problematic. This vulnerability affects unknown code of the component OpenId/Oauth2. The manipulation leads to use of cache containing sensitive information.
This vulnerability was named CVE-2024-45596. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2024-40659 | Google Android 14 RemoteProvisioningService.java getRegistration denial of service
1 year 6 months ago
A vulnerability, which was classified as problematic, was found in Google Android 14. This affects the function getRegistration of the file RemoteProvisioningService.java. The manipulation leads to denial of service.
This vulnerability is uniquely identified as CVE-2024-40659. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2024-40656 | Google Android 12/12L/13/14 ConnectionServiceWrapper.java handleCreateConferenceComplete information disclosure
1 year 6 months ago
A vulnerability, which was classified as problematic, has been found in Google Android 12/12L/13/14. Affected by this issue is the function handleCreateConferenceComplete of the file ConnectionServiceWrapper.java. The manipulation leads to information disclosure.
This vulnerability is handled as CVE-2024-40656. Local access is required to approach this attack. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
丈八网安获5000万元B轮融资 加速网络仿真技术创新及应用实践
1 year 6 months ago
丈八网安资本化之路快速迈入新阶段