CVE-2024-34402
- EPSS 0.31%
- Veröffentlicht 03.05.2024 01:15:48
- Zuletzt bearbeitet 17.06.2025 15:24:01
An issue was discovered in uriparser through 0.9.7. ComposeQueryEngine in UriQuery.c has an integer overflow via long keys or values, with a resultant buffer overflow.
CVE-2024-34403
- EPSS 0.17%
- Veröffentlicht 03.05.2024 01:15:48
- Zuletzt bearbeitet 17.06.2025 15:20:17
An issue was discovered in uriparser through 0.9.7. ComposeQueryMallocExMm in UriQuery.c has an integer overflow via a long string.
CVE-2024-4140
- EPSS 0.37%
- Veröffentlicht 02.05.2024 20:15:07
- Zuletzt bearbeitet 26.08.2025 17:21:28
An excessive memory use issue (CWE-770) exists in Email-MIME, before version 1.954, which can cause denial of service when parsing multipart MIME messages. The patch set (from 2020 and 2024) limits excessive depth and the total number of parts.
CVE-2024-4215
- EPSS 0.03%
- Veröffentlicht 02.05.2024 18:15:07
- Zuletzt bearbeitet 19.09.2025 13:37:32
pgAdmin <= 8.5 is affected by a multi-factor authentication bypass vulnerability. This vulnerability allows an attacker with knowledge of a legitimate account’s username and password may authenticate to the application and perform sensitive actions w...
CVE-2024-4216
- EPSS 0.23%
- Veröffentlicht 02.05.2024 18:15:07
- Zuletzt bearbeitet 19.09.2025 13:27:28
pgAdmin <= 8.5 is affected by XSS vulnerability in /settings/store API response json payload. This vulnerability allows attackers to execute malicious script at the client end.
CVE-2023-47212
- EPSS 0.36%
- Veröffentlicht 01.05.2024 16:15:07
- Zuletzt bearbeitet 22.08.2025 14:35:34
A heap-based buffer overflow vulnerability exists in the comment functionality of stb _vorbis.c v1.22. A specially crafted .ogg file can lead to an out-of-bounds write. An attacker can provide a malicious file to trigger this vulnerability.
CVE-2024-4058
- EPSS 3.9%
- Veröffentlicht 01.05.2024 13:15:52
- Zuletzt bearbeitet 14.03.2025 15:15:44
Type confusion in ANGLE in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
CVE-2024-4059
- EPSS 0.08%
- Veröffentlicht 01.05.2024 13:15:52
- Zuletzt bearbeitet 27.03.2025 20:15:27
Out of bounds read in V8 API in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to leak cross-site data via a crafted HTML page. (Chromium security severity: High)
CVE-2024-4060
- EPSS 0.1%
- Veröffentlicht 01.05.2024 13:15:52
- Zuletzt bearbeitet 19.12.2024 18:54:01
Use after free in Dawn in Google Chrome prior to 124.0.6367.78 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
CVE-2024-4331
- EPSS 0.6%
- Veröffentlicht 01.05.2024 13:15:52
- Zuletzt bearbeitet 20.12.2024 17:22:46
Use after free in Picture In Picture in Google Chrome prior to 124.0.6367.118 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)