CVE-2024-25713
- EPSS 2.39%
- Published 29.02.2024 01:44:16
- Last modified 17.09.2025 20:29:23
yyjson through 0.8.0 has a double free, leading to remote code execution in some cases, because the pool_free function lacks loop checks. (pool_free is part of the pool series allocator, along with pool_malloc and pool_realloc.)
CVE-2024-1938
- EPSS 0.31%
- Published 29.02.2024 01:43:57
- Last modified 19.12.2024 20:20:38
Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2024-1939
- EPSS 29.66%
- Published 29.02.2024 01:43:57
- Last modified 19.12.2024 20:20:25
Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2024-27285
- EPSS 2.7%
- Published 28.02.2024 20:15:41
- Last modified 14.02.2025 15:31:24
YARD is a Ruby Documentation tool. The "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb"...
CVE-2024-27507
- EPSS 0.07%
- Published 27.02.2024 15:15:07
- Last modified 12.05.2025 13:07:50
libLAS 1.8.1 contains a memory leak vulnerability in /libLAS/apps/ts2las.cpp.
CVE-2024-25711
- EPSS 3.16%
- Published 27.02.2024 02:15:06
- Last modified 28.05.2025 16:15:32
diffoscope before 256 allows directory traversal via an embedded filename in a GPG file. Contents of any file, such as ../.ssh/id_rsa, may be disclosed to an attacker. This occurs because the value of the gpg --use-embedded-filenames option is truste...
CVE-2024-23839
- EPSS 0.21%
- Published 26.02.2024 16:27:58
- Last modified 19.12.2024 19:38:28
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.3, specially crafted traffic can cause a heap use after free if the ruleset uses the http.request_header or http.respo...
CVE-2024-24568
- EPSS 0.06%
- Published 26.02.2024 16:27:58
- Last modified 19.12.2024 19:30:33
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.3, the rules inspecting HTTP2 headers can get bypassed by crafted traffic. The vulnerability has been patched in 7.0.3...
CVE-2024-25081
- EPSS 0.05%
- Published 26.02.2024 16:27:58
- Last modified 23.04.2025 16:18:17
Splinefont in FontForge through 20230101 allows command injection via crafted filenames.
CVE-2024-25082
- EPSS 0.65%
- Published 26.02.2024 16:27:58
- Last modified 23.04.2025 16:18:54
Splinefont in FontForge through 20230101 allows command injection via crafted archives or compressed files.