NA - CVE-2024-27113 - An unauthenticated Insecure Direct Object...
An unauthenticated Insecure Direct Object Reference (IDOR) to the database has been found in the SO Planning tool that occurs when the public view setting is enabled. An attacker could use this...
NA - CVE-2024-27114 - A unauthenticated Remote Code Execution (RCE)...
A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. If the public view setting is enabled, a attacker can upload a PHP-file that will be...
NA - CVE-2024-27115 - A unauthenticated Remote Code Execution (RCE)...
A unauthenticated Remote Code Execution (RCE) vulnerability is found in the SO Planning online planning tool. With this vulnerability, an attacker can upload executable files that are moved to a...
High - CVE-2024-8636 - Heap buffer overflow in Skia in Google Chrome...
Heap buffer overflow in Skia in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
High - CVE-2024-8637 - Use after free in Media Router in Google Chrome...
Use after free in Media Router in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security...
High - CVE-2024-8638 - Type Confusion in V8 in Google Chrome prior to...
Type Confusion in V8 in Google Chrome prior to 128.0.6613.137 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
High - CVE-2024-8639 - Use after free in Autofill in Google Chrome on...
Use after free in Autofill in Google Chrome on Android prior to 128.0.6613.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity:...
NA - CVE-2024-8642 - In Eclipse Dataspace Components, from version...
In Eclipse Dataspace Components, from version 0.5.0 and before version 0.9.0, the ConsumerPullTransferTokenValidationApiController does not check for token validity (expiry, not-before, issuance...
NA - CVE-2024-8646 - In Eclipse Glassfish versions prior to 7.0.10,...
In Eclipse Glassfish versions prior to 7.0.10, a URL redirection vulnerability to untrusted sites existed. This vulnerability is caused by the vulnerability (CVE-2023-41080) in the Apache code...