Category: CVE

CVE-2024-52318 | Apache Tomcat up to 9.0.96/10.1.31/11.0.0 Object

A vulnerability was found in Apache Tomcat up to 9.0.96/10.1.31/11.0.0. It has been rated as problematic. This issue affects some unknown processing of the component Object Handler. The manipulation leads to an unknown weakness. The identification of this vulnerability is CVE-2024-52318. The attack may be initiated remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-52317 | Apache Tomcat up to 9.0.95/10.1.30/11.0.0-M26 HTTP/2 Request

A vulnerability was found in Apache Tomcat up to 9.0.95/10.1.30/11.0.0-M26. It has been declared as problematic. This vulnerability affects unknown code of the component HTTP2 Request Handler. The manipulation leads to an unknown weakness. This vulnerability was named CVE-2024-52317. The attack can be initiated remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-11319 | Django CMS up to 3.11.7/3.11.8/4.1.2/4.1.3 cross site scripting

A vulnerability was found in Django CMS up to 3.11.7/3.11.8/4.1.2/4.1.3. It has been classified as problematic. This affects an unknown part. The manipulation leads to cross site scripting. This vulnerability is uniquely identified as CVE-2024-11319. It is possible to initiate the attack remotely. Furthermore, there is an exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-11023 | Firebase JavaScript SDK up to 10.8.x Cookie _authTokenSyncURL cross site scripting

A vulnerability was found in Firebase JavaScript SDK up to 10.8.x and classified as problematic. Affected by this issue is some unknown functionality of the component Cookie Handler. The manipulation of the argument _authTokenSyncURL leads to cross site scripting. This vulnerability is handled as CVE-2024-11023. The attack may be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-52316 | Apache Tomcat up to 9.0.95/10.1.30/11.0.0-M26 ServerAuthContext Component error condition

A vulnerability has been found in Apache Tomcat up to 9.0.95/10.1.30/11.0.0-M26 and classified as critical. Affected by this vulnerability is an unknown functionality of the component ServerAuthContext Component. The manipulation leads to unchecked error condition. This vulnerability is known as CVE-2024-52316. The attack can be launched remotely. There is no exploit available. It is recommended to upgrade the affected...

Read More

CVE-2024-42391 | Cesanta Mongoose Web Server up to 7.14 TLS Packet out-of-range pointer offset

A vulnerability, which was classified as problematic, has been found in Cesanta Mongoose Web Server up to 7.14. This issue affects some unknown processing of the component TLS Packet Handler. The manipulation leads to use of out-of-range pointer offset. The identification of this vulnerability is CVE-2024-42391. The attack may be initiated remotely. There is no exploit...

Read More

CVE-2024-42389 | Cesanta Mongoose Web Server up to 7.14 TLS Packet out-of-range pointer offset

A vulnerability classified as problematic has been found in Cesanta Mongoose Web Server up to 7.14. This affects an unknown part of the component TLS Packet Handler. The manipulation leads to use of out-of-range pointer offset. This vulnerability is uniquely identified as CVE-2024-42389. It is possible to initiate the attack remotely. There is no exploit...

Read More

CVE-2024-42388 | Cesanta Mongoose Web Server up to 7.14 TLS Packet out-of-range pointer offset

A vulnerability was found in Cesanta Mongoose Web Server up to 7.14. It has been rated as problematic. Affected by this issue is some unknown functionality of the component TLS Packet Handler. The manipulation leads to use of out-of-range pointer offset. This vulnerability is handled as CVE-2024-42388. The attack may be launched remotely. There is no exploit...

Read More

CVE-2024-41973 | WAGO 8000-0002 File path traversal (VDE-2024-047)

A vulnerability was found in WAGO CC100 0751-9×01, PFC100 G2 0750-811x-xxxx-xxxx, PFC200 G2 750-821x-xxx-xxx, TP600 0762-420x, 8000-000x, TP600 0762-430x, TP600 0762-520x, TP600 0762-530x, TP600 0762-620x, TP600 0762-630x, Edge Controller 0752-8303 and 8000-0002. It has been classified as problematic. Affected is an unknown function of the component File Handler. The manipulation leads to path traversal: ‘…/…//’. This vulnerability is traded as CVE-2024-41973. It is possible to launch the attack remotely. There is no exploit...

Read More
Loading