NA - CVE-2024-47191 - pam_oath.so in oath-toolkit 2.6.7 through...
pam_oath.so in oath-toolkit 2.6.7 through 2.6.11 before 2.6.12 allows root privilege escalation because, in the context of PAM code running as root, it mishandles usersfile access, such as by...
NA - CVE-2023-36325 - i2p before 2.3.0 (Java) allows de-anonymizing...
i2p before 2.3.0 (Java) allows de-anonymizing the public IPv4 and IPv6 addresses of i2p hidden services (aka eepsites) via a correlation attack across the IPv4 and IPv6 addresses that occurs when a...
NA - CVE-2023-37154 - check_by_ssh in Nagios nagios-plugins 2.4.5...
check_by_ssh in Nagios nagios-plugins 2.4.5 allows arbitrary command execution via ProxyCommand, LocalCommand, and PermitLocalCommand with \${IFS}. This has been categorized both as fixed in...
NA - CVE-2023-45359 - An issue was discovered in the Vector Skin...
An issue was discovered in the Vector Skin component for MediaWiki before 1.39.5 and 1.40.x before 1.40.1. vector-toc-toggle-button-label is not escaped, but should be, because the line param can...
NA - CVE-2023-45361 - An issue was discovered in...
An issue was discovered in VectorComponentUserLinks.php in the Vector Skin component in MediaWiki before 1.39.5 and 1.40.x before 1.40.1. vector-intro-page MalformedTitleException is uncaught if it...
NA - CVE-2023-45872 - An issue was discovered in Qt before 6.2.11 and...
An issue was discovered in Qt before 6.2.11 and 6.3.x through 6.6.x before 6.6.1. When a QML image refers to an image whose content is not known yet, there is an assumption that it is an SVG...
NA - CVE-2024-5968 - The Photo Gallery by 10Web WordPress plugin...
The Photo Gallery by 10Web WordPress plugin before 1.8.28 does not properly sanitise and escape some of its Gallery settings, which could allow high privilege users such as admin to perform Stored...
NA - CVE-2024-39436 - In linkturbonative service, there is a possible...
In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed.
NA - CVE-2024-39437 - In linkturbonative service, there is a possible...
In linkturbonative service, there is a possible command injection due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed.