NA - CVE-2024-52579 - Misskey is an open source, federated social...
Misskey is an open source, federated social media platform. Some APIs using `HttpRequestService` do not properly check the target host. This vulnerability allows an attacker to send POST or GET...
NA - CVE-2024-52590 - Misskey is an open source, federated social...
Misskey is an open source, federated social media platform. In affected versions missing validation in `ApRequestService.signedGet` allows an attacker to create fake user profiles that appear to be...
NA - CVE-2024-52591 - Misskey is an open source, federated social...
Misskey is an open source, federated social media platform. In affected versions missing validation in `ApRequestService.signedGet` and `HttpRequestService.getActivityJson` allows an attacker to...
NA - CVE-2024-52592 - Misskey is an open source, federated social...
Misskey is an open source, federated social media platform. In affected versions missing validation in `ApInboxService.update` allows an attacker to modify the result of polls belonging to another...
NA - CVE-2024-52593 - Misskey is an open source, federated social...
Misskey is an open source, federated social media platform.In affected versions missing validation in `NoteCreateService.insertNote`, `ApPersonService.createPerson`, and...
NA - CVE-2024-53269 - Envoy is a cloud-native high-performance...
Envoy is a cloud-native high-performance edge/middle/service proxy. When additional address are not ip addresses, then the Happy Eyeballs sorting algorithm will crash in data plane. This issue has...
NA - CVE-2024-53270 - Envoy is a cloud-native high-performance...
Envoy is a cloud-native high-performance edge/middle/service proxy. In affected versions `sendOverloadError` is going to assume the active request exists when...
NA - CVE-2024-53271 - Envoy is a cloud-native high-performance...
Envoy is a cloud-native high-performance edge/middle/service proxy. In affected versions envoy does not properly handle http 1.1 non-101 1xx responses. This can lead to downstream failures in...
NA - CVE-2024-12686 - A vulnerability has been discovered in...
A vulnerability has been discovered in Privileged Remote Access (PRA) and Remote Support (RS) which can allow an attacker with existing administrative privileges to inject commands and run as a...
NA - CVE-2024-45338 - An attacker can craft an input to the Parse...
An attacker can craft an input to the Parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow parsing. This could cause a denial of service.