NA - CVE-2024-35288 - Nitro PDF Pro before 13.70.8.82 and 14.x before...
Nitro PDF Pro before 13.70.8.82 and 14.x before 14.26.1.0 allows Local Privilege Escalation in the MSI Installer because custom actions occur unsafely in repair mode. CertUtil is run in a...
NA - CVE-2024-45179 - An issue was discovered in za-internet C-MOR...
An issue was discovered in za-internet C-MOR Video Surveillance 5.2401 and 6.00PL01. Due to insufficient input validation, the C-MOR web interface is vulnerable to OS command injection attacks. It...
NA - CVE-2024-32608 - HDF5 library through 1.14.3 has memory...
HDF5 library through 1.14.3 has memory corruption in H5A__close resulting in the corruption of the instruction pointer and causing denial of service or potential code execution.
NA - CVE-2024-42934 - OpenIPMI before 2.0.36 has an out-of-bounds...
OpenIPMI before 2.0.36 has an out-of-bounds array access (for authentication type) in the ipmi_sim simulator, resulting in denial of service or (with very low probability) authentication bypass or...
NA - CVE-2024-45160 - Incorrect credential validation in...
Incorrect credential validation in LemonLDAP::NG 2.18.x and 2.19.x before 2.19.2 allows attackers to bypass OAuth2 client authentication via an empty client_password parameter (client secret).
NA - CVE-2024-47191 - pam_oath.so in oath-toolkit 2.6.7 through...
pam_oath.so in oath-toolkit 2.6.7 through 2.6.11 before 2.6.12 allows root privilege escalation because, in the context of PAM code running as root, it mishandles usersfile access, such as by...
NA - CVE-2023-36325 - i2p before 2.3.0 (Java) allows de-anonymizing...
i2p before 2.3.0 (Java) allows de-anonymizing the public IPv4 and IPv6 addresses of i2p hidden services (aka eepsites) via a correlation attack across the IPv4 and IPv6 addresses that occurs when a...
NA - CVE-2023-37154 - check_by_ssh in Nagios nagios-plugins 2.4.5...
check_by_ssh in Nagios nagios-plugins 2.4.5 allows arbitrary command execution via ProxyCommand, LocalCommand, and PermitLocalCommand with \${IFS}. This has been categorized both as fixed in...
NA - CVE-2023-45359 - An issue was discovered in the Vector Skin...
An issue was discovered in the Vector Skin component for MediaWiki before 1.39.5 and 1.40.x before 1.40.1. vector-toc-toggle-button-label is not escaped, but should be, because the line param can...
NA - CVE-2023-45361 - An issue was discovered in...
An issue was discovered in VectorComponentUserLinks.php in the Vector Skin component in MediaWiki before 1.39.5 and 1.40.x before 1.40.1. vector-intro-page MalformedTitleException is uncaught if it...