CVE-2024-24246
- EPSS 0.07%
- Veröffentlicht 29.02.2024 20:15:41
- Zuletzt bearbeitet 04.11.2025 22:15:58
Heap Buffer Overflow vulnerability in qpdf 11.9.0 allows attackers to crash the application via the std::__shared_count() function at /bits/shared_ptr_base.h.
CVE-2024-22871
- EPSS 0.6%
- Veröffentlicht 29.02.2024 02:15:09
- Zuletzt bearbeitet 04.11.2025 22:15:58
An issue in Clojure versions 1.20 to 1.12.0-alpha5 allows an attacker to cause a denial of service (DoS) via the clojure.core$partial$fn__5920 function.
CVE-2024-25713
- EPSS 3.06%
- Veröffentlicht 29.02.2024 01:44:16
- Zuletzt bearbeitet 04.11.2025 22:15:58
yyjson through 0.8.0 has a double free, leading to remote code execution in some cases, because the pool_free function lacks loop checks. (pool_free is part of the pool series allocator, along with pool_malloc and pool_realloc.)
CVE-2024-1938
- EPSS 0.29%
- Veröffentlicht 29.02.2024 01:43:57
- Zuletzt bearbeitet 19.12.2024 20:20:38
Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2024-1939
- EPSS 39.33%
- Veröffentlicht 29.02.2024 01:43:57
- Zuletzt bearbeitet 19.12.2024 20:20:25
Type Confusion in V8 in Google Chrome prior to 122.0.6261.94 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2024-27285
- EPSS 2.47%
- Veröffentlicht 28.02.2024 20:15:41
- Zuletzt bearbeitet 14.02.2025 15:31:24
YARD is a Ruby Documentation tool. The "frames.html" file within the Yard Doc's generated documentation is vulnerable to Cross-Site Scripting (XSS) attacks due to inadequate sanitization of user input within the JavaScript segment of the "frames.erb"...
CVE-2024-27507
- EPSS 0.1%
- Veröffentlicht 27.02.2024 15:15:07
- Zuletzt bearbeitet 04.11.2025 19:17:03
libLAS 1.8.1 contains a memory leak vulnerability in /libLAS/apps/ts2las.cpp.
CVE-2024-25711
- EPSS 4.08%
- Veröffentlicht 27.02.2024 02:15:06
- Zuletzt bearbeitet 04.11.2025 19:17:00
diffoscope before 256 allows directory traversal via an embedded filename in a GPG file. Contents of any file, such as ../.ssh/id_rsa, may be disclosed to an attacker. This occurs because the value of the gpg --use-embedded-filenames option is truste...
CVE-2024-23839
- EPSS 0.21%
- Veröffentlicht 26.02.2024 16:27:58
- Zuletzt bearbeitet 19.12.2024 19:38:28
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.3, specially crafted traffic can cause a heap use after free if the ruleset uses the http.request_header or http.respo...
CVE-2024-24568
- EPSS 0.07%
- Veröffentlicht 26.02.2024 16:27:58
- Zuletzt bearbeitet 19.12.2024 19:30:33
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 7.0.3, the rules inspecting HTTP2 headers can get bypassed by crafted traffic. The vulnerability has been patched in 7.0.3...