Количество 26 125
Количество 26 125
CVE-2024-35235
CVE-2024-35195
Requests `Session` object does not verify requests after making first request with verify=False
CVE-2024-35176
CVE-2024-3516
Chromium: CVE-2024-3516 Heap buffer overflow in ANGLE
CVE-2024-3515
Chromium: CVE-2024-3515 Use after free in Dawn
CVE-2024-3447
Qemu: sdhci: heap buffer overflow in sdhci_write_dataport()
CVE-2024-34459
CVE-2024-34403
An issue was discovered in uriparser through 0.9.7. ComposeQueryMallocExMm in UriQuery.c has an integer overflow via a long string.
CVE-2024-34402
An issue was discovered in uriparser through 0.9.7. ComposeQueryEngine in UriQuery.c has an integer overflow via long keys or values, with a resultant buffer overflow.
CVE-2024-34397
An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can send spoofed D-Bus signals that the GDBus-based client will wrongly interpret as having been sent by the trusted system service. This could lead to the GDBus-based client behaving incorrectly, with an application-dependent impact.
CVE-2024-34251
An out-of-bound memory read vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cause a denial of service via the "block_type_get_arity" function in core/iwasm/interpreter/wasm.h.
CVE-2024-34250
CVE-2024-34158
Stack exhaustion in Parse in go/build/constraint
CVE-2024-34156
Stack exhaustion in Decoder.Decode in encoding/gob
CVE-2024-34155
Stack exhaustion in all Parse functions in go/parser
CVE-2024-34122
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
CVE-2024-34088
CVE-2024-34069
Werkzeug's improper usage of a pathname and improper CSRF protection results in the remote command execution
CVE-2024-34064
Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter
CVE-2024-34062
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVSS3: 4.4 | 2% Низкий | больше 1 года назад | ||
CVE-2024-35195 Requests `Session` object does not verify requests after making first request with verify=False | CVSS3: 5.6 | 0% Низкий | около 2 лет назад | |
CVSS3: 5.3 | 2% Низкий | больше 2 лет назад | ||
CVE-2024-3516 Chromium: CVE-2024-3516 Heap buffer overflow in ANGLE | 1% Низкий | больше 2 лет назад | ||
CVE-2024-3515 Chromium: CVE-2024-3515 Use after free in Dawn | 1% Низкий | больше 2 лет назад | ||
CVE-2024-3447 Qemu: sdhci: heap buffer overflow in sdhci_write_dataport() | CVSS3: 6 | 1% Низкий | больше 1 года назад | |
CVSS3: 7.5 | 2% Низкий | больше 2 лет назад | ||
CVE-2024-34403 An issue was discovered in uriparser through 0.9.7. ComposeQueryMallocExMm in UriQuery.c has an integer overflow via a long string. | CVSS3: 5.9 | 1% Низкий | больше 1 года назад | |
CVE-2024-34402 An issue was discovered in uriparser through 0.9.7. ComposeQueryEngine in UriQuery.c has an integer overflow via long keys or values, with a resultant buffer overflow. | CVSS3: 8.6 | 1% Низкий | больше 1 года назад | |
CVE-2024-34397 An issue was discovered in GNOME GLib before 2.78.5, and 2.79.x and 2.80.x before 2.80.1. When a GDBus-based client subscribes to signals from a trusted system service such as NetworkManager on a shared computer, other users of the same computer can send spoofed D-Bus signals that the GDBus-based client will wrongly interpret as having been sent by the trusted system service. This could lead to the GDBus-based client behaving incorrectly, with an application-dependent impact. | CVSS3: 5.2 | 1% Низкий | 7 дней назад | |
CVE-2024-34251 An out-of-bound memory read vulnerability was discovered in Bytecode Alliance wasm-micro-runtime v2.0.0 which allows a remote attacker to cause a denial of service via the "block_type_get_arity" function in core/iwasm/interpreter/wasm.h. | 1% Низкий | 7 дней назад | ||
CVSS3: 6.2 | 0% Низкий | больше 2 лет назад | ||
CVE-2024-34158 Stack exhaustion in Parse in go/build/constraint | CVSS3: 7.5 | 1% Низкий | 7 дней назад | |
CVE-2024-34156 Stack exhaustion in Decoder.Decode in encoding/gob | 1% Низкий | 7 дней назад | ||
CVE-2024-34155 Stack exhaustion in all Parse functions in go/parser | CVSS3: 4.3 | 1% Низкий | 6 месяцев назад | |
CVE-2024-34122 Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability | 0% Низкий | около 2 лет назад | ||
CVSS3: 7.5 | 1% Низкий | больше 1 года назад | ||
CVE-2024-34069 Werkzeug's improper usage of a pathname and improper CSRF protection results in the remote command execution | CVSS3: 7.5 | 3% Низкий | 6 месяцев назад | |
CVE-2024-34064 Jinja vulnerable to HTML attribute injection when passing user input as keys to xmlattr filter | CVSS3: 5.4 | 1% Низкий | больше 1 года назад | |
CVSS3: 4.8 | 0% Низкий | почти 2 года назад |
Уязвимостей на страницу