Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In November 2024
Memory corruption while parsing IPC frequency table parameters for LPLH that has size greater than expected size.
CVSS Score
6.7
EPSS Score
0.001
Published
2024-11-04
Memory corruption while processing the update SIM PB records request.
CVSS Score
6.7
EPSS Score
0.001
Published
2024-11-04
Memory corruption when the user application modifies the same shared memory asynchronously when kernel is accessing it.
CVSS Score
6.7
EPSS Score
0.001
Published
2024-11-04
Memory corruption while invoking IOCTL command from user-space, when a user modifies the original packet size of the command after system properties have been already sent to the EVA driver.
CVSS Score
6.7
EPSS Score
0.001
Published
2024-11-04
Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE.
CVSS Score
7.5
EPSS Score
0.003
Published
2024-11-04
memory corruption when WiFi display APIs are invoked with large random inputs.
CVSS Score
6.7
EPSS Score
0.001
Published
2024-11-04
Session Fixation vulnerability in Apache Kylin. This issue affects Apache Kylin: from 2.0.0 through 4.x. Users are recommended to upgrade to version 5.0.0 or above, which fixes the issue.
CVSS Score
9.1
EPSS Score
0.007
Published
2024-11-04
A vulnerability was found in Umbraco CMS up to 10.7.7/12.3.6/13.5.2/14.3.1/15.1.1. It has been classified as problematic. Affected is an unknown function of the file /Umbraco/preview/frame?id{} of the component Dashboard. The manipulation of the argument culture leads to cross site scripting. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 10.8.8, 13.5.3, 14.3.2 and 15.1.2 is able to address this issue. It is recommended to upgrade the affected component.
CVSS Score
6.9
EPSS Score
0.006
Published
2024-11-04
A vulnerability was found in code-projects University Event Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /dodelete.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
CVSS Score
5.3
EPSS Score
0.005
Published
2024-11-04
A vulnerability has been found in itsourcecode Farm Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /edit-pig.php. The manipulation of the argument pigno/weight/arrived/breed/remark/status leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The initial researcher advisory only mentions the parameter "pigno" to be affected. But it must be assumed that other parameters are affected as well.
CVSS Score
5.3
EPSS Score
0.005
Published
2024-11-04


Contact Us

Shodan ® - All rights reserved