Total
9398 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2024-24984 | 2024-11-15 | N/A | N/A | ||
Improper input validation for some Intel(R) Wireless Bluetooth(R) products for Windows before version 23.40 may allow an unauthenticated user to potentially enable denial of service via adjacent access. | |||||
CVE-2024-39811 | 2024-11-15 | N/A | N/A | ||
Improper input validation in firmware for some Intel(R) Server M20NTP Family UEFI may allow a privileged user to potentially enable escalation of privilege via local access. | |||||
CVE-2024-37027 | 2024-11-15 | N/A | N/A | ||
Improper Input validation in some Intel(R) VTune(TM) Profiler software before version 2024.2.0 may allow an authenticated user to potentially enable denial of service via local access. | |||||
CVE-2024-32048 | 2024-11-15 | N/A | N/A | ||
Improper input validation in the Intel(R) Distribution of OpenVINO(TM) Model Server software before version 2024.0 may allow an unauthenticated user to potentially enable denial of service via adjacent access. | |||||
CVE-2024-31158 | 2024-11-15 | N/A | N/A | ||
Improper input validation in UEFI firmware in some Intel(R) Server Board S2600BP Family may allow a privileged user to potentially enable escalation of privilege via local access. | |||||
CVE-2022-2232 | 2024-11-15 | N/A | 7.5 HIGH | ||
A flaw was found in the Keycloak package. This flaw allows an attacker to utilize an LDAP injection to bypass the username lookup or potentially perform other malicious actions. | |||||
CVE-2024-8936 | 2024-11-13 | N/A | N/A | ||
CWE-20: Improper Input Validation vulnerability exists that could lead to loss of confidentiality of controller memory after a successful Man-In-The-Middle attack followed by sending a crafted Modbus function call used to tamper with memory. | |||||
CVE-2024-50343 | 2024-11-08 | N/A | N/A | ||
symfony/validator is a module for the Symphony PHP framework which provides tools to validate values. It is possible to trick a `Validator` configured with a regular expression using the `$` metacharacters, with an input ending with `\n`. Symfony as of versions 5.4.43, 6.4.11, and 7.1.4 now uses the `D` regex modifier to match the entire input. Users are advised to upgrade. There are no known workarounds for this vulnerability. | |||||
CVE-2014-9907 | 1 Imagemagick | 1 Imagemagick | 2024-11-04 | 4.3 MEDIUM | 6.5 MEDIUM |
coders/dds.c in ImageMagick allows remote attackers to cause a denial of service via a crafted DDS file. | |||||
CVE-2014-9815 | 1 Imagemagick | 1 Imagemagick | 2024-10-31 | 4.3 MEDIUM | 5.5 MEDIUM |
ImageMagick allows remote attackers to cause a denial of service (application crash) via a crafted wpg file. | |||||
CVE-2014-9811 | 1 Imagemagick | 1 Imagemagick | 2024-10-31 | 4.3 MEDIUM | 5.5 MEDIUM |
The xwd file handler in ImageMagick allows remote attackers to cause a denial of service (segmentation fault and application crash) via a malformed xwd file. | |||||
CVE-2014-9809 | 1 Imagemagick | 1 Imagemagick | 2024-10-31 | 4.3 MEDIUM | 5.5 MEDIUM |
ImageMagick allows remote attackers to cause a denial of service (segmentation fault and application crash) via a crafted xwd image. | |||||
CVE-2014-9810 | 1 Imagemagick | 1 Imagemagick | 2024-10-31 | 4.3 MEDIUM | 5.5 MEDIUM |
The dpx file handler in ImageMagick allows remote attackers to cause a denial of service (segmentation fault and application crash) via a malformed dpx file. | |||||
CVE-2014-9813 | 1 Imagemagick | 1 Imagemagick | 2024-10-31 | 4.3 MEDIUM | 5.5 MEDIUM |
ImageMagick allows remote attackers to cause a denial of service (application crash) via a crafted viff file. | |||||
CVE-2014-9805 | 1 Imagemagick | 1 Imagemagick | 2024-10-31 | 4.3 MEDIUM | 5.5 MEDIUM |
ImageMagick allows remote attackers to cause a denial of service (segmentation fault and application crash) via a crafted pnm file. | |||||
CVE-2014-9806 | 1 Imagemagick | 1 Imagemagick | 2024-10-31 | 4.3 MEDIUM | 5.5 MEDIUM |
ImageMagick allows remote attackers to cause a denial of service (file descriptor consumption) via a crafted file. | |||||
CVE-2014-9808 | 1 Imagemagick | 1 Imagemagick | 2024-10-31 | 4.3 MEDIUM | 5.5 MEDIUM |
ImageMagick allows remote attackers to cause a denial of service (segmentation fault and application crash) via a crafted dpc image. | |||||
CVE-2024-49753 | 2024-10-28 | N/A | N/A | ||
Zitadel is open-source identity infrastructure software. Versions prior to 2.64.1, 2.63.6, 2.62.8, 2.61.4, 2.60.4, 2.59.5, and 2.58.7 have a flaw in the URL validation mechanism of Zitadel actions allows bypassing restrictions intended to block requests to localhost (127.0.0.1). The isHostBlocked check, designed to prevent such requests, can be circumvented by creating a DNS record that resolves to 127.0.0.1. This enables actions to send requests to localhost despite the intended security measures. This vulnerability potentially allows unauthorized access to unsecured internal endpoints, which may contain sensitive information or functionalities. Versions 2.64.1, 2.63.6, 2.62.8, 2.61.4, 2.60.4, 2.59.5, and 2.58.7 contain a patch. No known workarounds are available. | |||||
CVE-2024-0127 | 2024-10-28 | N/A | N/A | ||
NVIDIA vGPU software contains a vulnerability in the GPU kernel driver of the vGPU Manager for all supported hypervisors, where a user of the guest OS can cause an improper input validation by compromising the guest OS kernel. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure. | |||||
CVE-2024-0126 | 2024-10-28 | N/A | N/A | ||
NVIDIA GPU Display Driver for Windows and Linux contains a vulnerability which could allow a privileged attacker to escalate permissions. A successful exploit of this vulnerability might lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering. |