CVE-2024-28219
- EPSS 0.17%
- Veröffentlicht 03.04.2024 03:15:09
- Zuletzt bearbeitet 21.11.2024 09:06:02
In _imagingcms.c in Pillow before 10.3.0, a buffer overflow exists because strcpy is used instead of strncpy.
CVE-2024-3209
- EPSS 0.27%
- Veröffentlicht 02.04.2024 23:15:55
- Zuletzt bearbeitet 25.04.2025 14:33:54
A vulnerability was found in UPX up to 4.2.2. It has been rated as critical. This issue affects the function get_ne64 of the file bele.h. The manipulation leads to heap-based buffer overflow. The exploit has been disclosed to the public and may be us...
CVE-2024-28960
- EPSS 0.22%
- Veröffentlicht 29.03.2024 06:15:07
- Zuletzt bearbeitet 28.05.2025 17:42:17
An issue was discovered in Mbed TLS 2.18.0 through 2.28.x before 2.28.8 and 3.x before 3.6.0, and Mbed Crypto. The PSA Crypto API mishandles shared memory.
CVE-2024-2004
- EPSS 0.91%
- Veröffentlicht 27.03.2024 08:15:41
- Zuletzt bearbeitet 30.07.2025 19:42:14
When a protocol selection parameter option disables all protocols without adding any then the default set of protocols would remain in the allowed set due to an error in the logic for removing protocols. The below command would perform a request to c...
CVE-2024-2398
- EPSS 1.96%
- Veröffentlicht 27.03.2024 08:15:41
- Zuletzt bearbeitet 30.07.2025 19:42:27
When an application tells libcurl it wants to allow HTTP/2 server push, and the amount of received headers for the push surpasses the maximum allowed limit (1000), libcurl aborts the server push. When aborting, libcurl inadvertently does not free all...
CVE-2024-2883
- EPSS 0.18%
- Veröffentlicht 26.03.2024 21:15:53
- Zuletzt bearbeitet 14.03.2025 02:15:13
Use after free in ANGLE in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
CVE-2024-2885
- EPSS 0.14%
- Veröffentlicht 26.03.2024 21:15:53
- Zuletzt bearbeitet 18.03.2025 16:15:21
Use after free in Dawn in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2024-2886
- EPSS 0.63%
- Veröffentlicht 26.03.2024 21:15:53
- Zuletzt bearbeitet 22.03.2025 14:15:14
Use after free in WebCodecs in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
CVE-2024-2887
- EPSS 4.66%
- Veröffentlicht 26.03.2024 21:15:53
- Zuletzt bearbeitet 28.03.2025 20:15:22
Type Confusion in WebAssembly in Google Chrome prior to 123.0.6312.86 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
CVE-2024-2955
- EPSS 0.06%
- Veröffentlicht 26.03.2024 20:15:11
- Zuletzt bearbeitet 06.08.2025 14:52:35
T.38 dissector crash in Wireshark 4.2.0 to 4.0.3 and 4.0.0 to 4.0.13 allows denial of service via packet injection or crafted capture file