NA - CVE-2024-52794 - Discourse is an open source platform for...
Discourse is an open source platform for community discussion. Users clicking on the lightbox thumbnails could be affected. This problem is patched in the latest version of Discourse. Users are...
NA - CVE-2024-53991 - Discourse is an open source platform for...
Discourse is an open source platform for community discussion. This vulnerability only impacts Discourse instances configured to use `FileStore::LocalStore` which means uploads and backups are...
NA - CVE-2024-7137 - The L2CAP receive data buffer for L2CAP packets...
The L2CAP receive data buffer for L2CAP packets is restricted to packet sizes smaller than the maximum supported packet size. Receiving a packet that exceeds the restricted buffer length may cause...
NA - CVE-2024-7138 - An assert may be triggered, causing a temporary...
An assert may be triggered, causing a temporary denial of service when a peer device sends a specially crafted malformed L2CAP packet. If a watchdog timer is not enabled, a hard reset is required...
NA - CVE-2024-7139 - Due to an unchecked buffer length, a specially...
Due to an unchecked buffer length, a specially crafted L2CAP packet can cause a buffer overflow. This buffer overflow triggers an assert, which results in a temporary denial of service. If a...
NA - CVE-2024-11157 - A third-party vulnerability exists in the...
A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor...
NA - CVE-2024-11364 - Another “uninitialized variable” code execution...
Another “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to access a...
NA - CVE-2024-12175 - Another “use after free” code execution...
Another “use after free” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to use a resource that was...
NA - CVE-2024-12672 - A third-party vulnerability exists in the...
A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor...
NA - CVE-2024-12727 - A pre-auth SQL injection vulnerability in the...
A pre-auth SQL injection vulnerability in the email protection feature of Sophos Firewall versions older than 21.0 MR1 (21.0.1) allows access to the reporting database and can lead to remote code...