NA - CVE-2024-25659 - In Infinera TNMS (Transcend Network Management...
In Infinera TNMS (Transcend Network Management System) 19.10.3, an insecure default configuration of the internal SFTP server on Linux servers allows remote attacker to access files and directories...
NA - CVE-2024-25660 - The WebDAV service in Infinera TNMS (Transcend...
The WebDAV service in Infinera TNMS (Transcend Network Management System) 19.10.3 allows a low-privileged remote attacker to conduct unauthorized file operations, because of execution with...
NA - CVE-2024-47071 - OSS Endpoint Manager is an endpoint manager...
OSS Endpoint Manager is an endpoint manager module for FreePBX. OSS Endpoint Manager module activation can allow authenticated web users unauthorized access to read system files with the...
NA - CVE-2024-47534 - go-tuf is a Go implementation of The Update...
go-tuf is a Go implementation of The Update Framework (TUF). The go-tuf client inconsistently traces the delegations. For example, if targets delegate to "A", and to "B", and "B" delegates to "C",...
NA - CVE-2024-47604 - NuGet Gallery is a package repository that...
NuGet Gallery is a package repository that powers nuget.org. The NuGetGallery has a security vulnerability in its handling of HTML element attributes, which allows an attacker to execute arbitrary...
NA - CVE-2024-9391 - A user who enables full-screen mode on a...
A user who enables full-screen mode on a specially crafted web page could potentially be prevented from exiting full screen mode. This may allow spoofing of other sites as the address bar is no...
NA - CVE-2024-9392 - A compromised content process could have...
A compromised content process could have allowed for the arbitrary loading of cross-origin pages. This vulnerability affects Firefox < 131, Firefox ESR < 128.3, Firefox ESR < 115.16, Thunderbird
NA - CVE-2024-9393 - An attacker could, via a specially crafted...
An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://pdf.js` origin. This could allow them to access cross-origin PDF content. This...
NA - CVE-2024-9394 - An attacker could, via a specially crafted...
An attacker could, via a specially crafted multipart response, execute arbitrary JavaScript under the `resource://devtools` origin. This could allow them to access cross-origin JSON content. This...
NA - CVE-2024-9395 - A specially crafted filename containing a large...
A specially crafted filename containing a large number of spaces could obscure the file's extension when displayed in the download dialog. *This bug only affects Firefox for Android. Other...