NA - CVE-2024-12669 - A maliciously crafted DWFX file, when parsed...
A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can be used to cause a Heap-based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a...
NA - CVE-2024-12670 - A maliciously crafted DWF file, when parsed...
A maliciously crafted DWF file, when parsed through Autodesk Navisworks, can be used to cause a Heap-based Overflow vulnerability. A malicious actor can leverage this vulnerability to cause a...
NA - CVE-2024-12671 - A maliciously crafted DWFX file, when parsed...
A maliciously crafted DWFX file, when parsed through Autodesk Navisworks, can force an Out-of-Bounds Write vulnerability. A malicious actor can leverage this vulnerability to cause a crash, cause...
NA - CVE-2024-53144 - In the Linux kernel, the following...
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_event: Align BR/EDR JUST_WORKS paring with LE This aligned BR/EDR JUST_WORKS method with LE which since...
NA - CVE-2024-42194 - An improper handling of insufficient...
An improper handling of insufficient permissions or privileges affects HCL BigFix Inventory. An attacker having access via a read-only account can possibly change certain configuration parameters...
Medium - CVE-2024-49816 - IBM Security Guardium Key Lifecycle Manager...
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores potentially sensitive information in log files that could be read by a local privileged user.
Medium - CVE-2024-49817 - IBM Security Guardium Key Lifecycle Manager...
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 stores user credentials in configuration files which can be read by a local privileged user.
Medium - CVE-2024-49818 - IBM Security Guardium Key Lifecycle Manager...
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the...
Medium - CVE-2024-49819 - IBM Security Guardium Key Lifecycle Manager...
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information in cleartext in a communication channel that can be sniffed by...
Low - CVE-2024-49820 - IBM Security Guardium Key Lifecycle Manager...
IBM Security Guardium Key Lifecycle Manager 4.1, 4.1.1, 4.2.0, and 4.2.1 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict...