CVE Notify
17.9K subscribers
4 photos
155K links
Alert on the latest CVEs

Partner channel: @malwr
Download Telegram
๐Ÿšจ CVE-2024-11317
Session Fixation vulnerabilities allow an attacker to fix a users session identifier before login providing an opportunity for session takeover on a product. 
Affected products:


ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-12094
This vulnerability exists in the Tinxy mobile app due to storage of logged-in user information in plaintext on the device database. An attacker with physical access to the rooted device could exploit this vulnerability by accessing its database leading to unauthorized access of user information such as username, email address and mobile number.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-48839
Improper Input Validation vulnerability allows Remote Code Execution. 
Affected products:


ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-48840
Unauthorized Access vulnerabilities allow Remote Code Execution. 
Affected products:


ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-48843
Denial of Service vulnerabilities where found providing a potiential for device service disruptions. 
Affected products:


ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-48844
Denial of Service vulnerabilities where found providing a potiential for device service disruptions. 
Affected products:


ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-48845
Weak Password Reset Rules vulnerabilities where found providing a potiential for the storage of weak passwords that could facilitate unauthorized admin/application access. 
Affected products:


ABB ASPECT - Enterprise v3.07.02;
NEXUS Series v3.07.02;
MATRIX Series v3.07.02

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-48846
Cross Site Request Forgery vulnerabilities where found providing a potiential for exposing sensitive information or changing system settings. 
Affected products:


ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-48847
MD5 Checksum Bypass vulnerabilities where found exploiting a weakness in the way an application dependency calculates or validates MD5 checksum hashes. 
Affected products:


ABB ASPECT - Enterprise v3.08.01;
NEXUS Series v3.08.01;
MATRIX Series v3.08.01

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-51541
Local File Inclusion vulnerabilities allow access to sensitive system information. 
Affected products:


ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-51542
Configuration Download vulnerabilities allow access to dependency configuration information. 
Affected products:


ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-51543
Information Disclosure vulnerabilities allow access to application configuration information. 
Affected products:


ABB ASPECT - Enterprise v3.08.02;
NEXUS Series v3.08.02;
MATRIX Series v3.08.02

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-20772
Media Encoder versions 24.2.1, 23.6.4 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-20771
Bridge versions 13.0.6, 14.0.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2024-20798
Illustrator versions 28.3, 27.9.2 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2023-34672
Improper Access Control leads to adding a high-privilege user affecting Elenos ETG150 FM transmitter running on version 3.12 by exploiting user's role within the admin profile. An attack could occur over the public Internet in some cases.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2023-36664
Artifex Ghostscript through 10.01.2 mishandles permission validation for pipe devices (with the %pipe% prefix or the | pipe character prefix).

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2023-30902
A privilege escalation vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to unintentionally delete privileged Trend Micro registry keys including its own protected registry keys on affected installations.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2023-32525
Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains widget vulnerabilities that could allow a remote attacker to create arbitrary files on affected installations.

Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

This is similar to, but not identical to CVE-2023-32526.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2021-30205
Incorrect access control in the component /index.php?mod=system&op=orgtree of dzzoffice 2.02.1_SC_UTF8 allows unauthenticated attackers to browse departments and usernames.

๐ŸŽ–@cveNotify
๐Ÿšจ CVE-2023-28826
This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, macOS Monterey 12.7.4, macOS Sonoma 14.1, macOS Ventura 13.6.5. An app may be able to access sensitive user data.

๐ŸŽ–@cveNotify