π¨ CVE-2024-38999
jrburke requirejs v2.3.6 was discovered to contain a prototype pollution via the function s.contexts._.configure. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
π@cveNotify
jrburke requirejs v2.3.6 was discovered to contain a prototype pollution via the function s.contexts._.configure. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
π@cveNotify
Gist
[CVE-2024-38998] Vulnerability Advisory: Prototype Pollution in requirejs, versions <= 2.3.6
[CVE-2024-38998] Vulnerability Advisory: Prototype Pollution in requirejs, versions <= 2.3.6 - Advisory_jrburke.md
π¨ CVE-2024-39000
adolph_dudu ratio-swiper v0.0.2 was discovered to contain a prototype pollution via the function parse. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
π@cveNotify
adolph_dudu ratio-swiper v0.0.2 was discovered to contain a prototype pollution via the function parse. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
π@cveNotify
Gist
[CVE-2024-38997] Vulnerability Advisory: Prototype Pollution in @adolph_dudu/ratio-swiper, version <= 0.0.2
[CVE-2024-38997] Vulnerability Advisory: Prototype Pollution in @adolph_dudu/ratio-swiper, version <= 0.0.2 - Advisory_Adophlidu.md
π¨ CVE-2024-39001
ag-grid-enterprise v31.3.2 was discovered to contain a prototype pollution via the component _ModuleSupport.jsonApply. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
π@cveNotify
ag-grid-enterprise v31.3.2 was discovered to contain a prototype pollution via the component _ModuleSupport.jsonApply. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
π@cveNotify
Gist
[CVE-2024-38996] Vulnerability Advisory: Prototype Pollution, version 31.3.2
[CVE-2024-38996] Vulnerability Advisory: Prototype Pollution, version 31.3.2 - Advisory_ag-grid.md
π¨ CVE-2024-39002
rjrodger jsonic-next v2.12.1 was discovered to contain a prototype pollution via the function util.clone. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
π@cveNotify
rjrodger jsonic-next v2.12.1 was discovered to contain a prototype pollution via the function util.clone. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
π@cveNotify
Gist
[CVE-2024-38993] Vulnerability Advisory Prototype Pollution in @jsonic/jsonic-next, version 2.12.1
[CVE-2024-38993] Vulnerability Advisory Prototype Pollution in @jsonic/jsonic-next, version 2.12.1 - Advisory_rjrodger.md
π¨ CVE-2024-39003
amoyjs amoy common v1.0.10 was discovered to contain a prototype pollution via the function setValue. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
π@cveNotify
amoyjs amoy common v1.0.10 was discovered to contain a prototype pollution via the function setValue. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
π@cveNotify
Gist
[CVE-2024-38994] Vulnerability Advisory: Prototype Pollution in @amoy/common, version 1.0.10
[CVE-2024-38994] Vulnerability Advisory: Prototype Pollution in @amoy/common, version 1.0.10 - Advisory_amoyjs.md
π¨ CVE-2024-39008
robinweser fast-loops v1.1.3 was discovered to contain a prototype pollution via the function objectMergeDeep. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
π@cveNotify
robinweser fast-loops v1.1.3 was discovered to contain a prototype pollution via the function objectMergeDeep. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
π@cveNotify
Gist
[CVE-2024-39008] Vulnerability Advisory: Prototype Pollution in fast-loops@1.1.3
[CVE-2024-39008] Vulnerability Advisory: Prototype Pollution in fast-loops@1.1.3 - Advisory_robinweser.md
π¨ CVE-2024-39013
2o3t-utility v0.1.2 was discovered to contain a prototype pollution via the function extend. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
π@cveNotify
2o3t-utility v0.1.2 was discovered to contain a prototype pollution via the function extend. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
π@cveNotify
Gist
[CVE-2024-39013] Vulnerability Advisory Prototype Pollution in 2o3t-utility, version 0.1.2
[CVE-2024-39013] Vulnerability Advisory Prototype Pollution in 2o3t-utility, version 0.1.2 - Advisory_2o3t.md
π¨ CVE-2024-39014
ahilfoley cahil/utils v2.3.2 was discovered to contain a prototype pollution via the function set. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
π@cveNotify
ahilfoley cahil/utils v2.3.2 was discovered to contain a prototype pollution via the function set. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
π@cveNotify
Gist
[CVE-2024-39014] Vulnerability Advisory Prototype Pollution in @cahil/utils, version 2.3.2
[CVE-2024-39014] Vulnerability Advisory Prototype Pollution in @cahil/utils, version 2.3.2 - Advisory_cahilfoley.md
π¨ CVE-2024-39015
cafebazaar hod v0.4.14 was discovered to contain a prototype pollution via the function request. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
π@cveNotify
cafebazaar hod v0.4.14 was discovered to contain a prototype pollution via the function request. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
π@cveNotify
Gist
[CVE-2024-39015] Vulnerability Advisory Prototype Pollution in @cafebazaar/hod, version 0.4.14
[CVE-2024-39015] Vulnerability Advisory Prototype Pollution in @cafebazaar/hod, version 0.4.14 - Advisory_cafebazaar.md
π¨ CVE-2024-39016
che3vinci c3/utils-1 1.0.131 was discovered to contain a prototype pollution via the function assign. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
π@cveNotify
che3vinci c3/utils-1 1.0.131 was discovered to contain a prototype pollution via the function assign. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
π@cveNotify
Gist
[CVE-2024-39016] Vulnerability Advisory Prototype Pollution in @c3/utils-1, version <= 1.0.131
[CVE-2024-39016] Vulnerability Advisory Prototype Pollution in @c3/utils-1, version <= 1.0.131 - Advisory_che3vinci.md
π¨ CVE-2024-39017
agreejs shared v0.0.1 was discovered to contain a prototype pollution via the function mergeInternalComponents. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
π@cveNotify
agreejs shared v0.0.1 was discovered to contain a prototype pollution via the function mergeInternalComponents. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
π@cveNotify
Gist
[CVE-2024-39017] Vulnerability Advisory: @agreejs/shared, version 0.0.1
[CVE-2024-39017] Vulnerability Advisory: @agreejs/shared, version 0.0.1 - Advisory_agreejs.md
π¨ CVE-2024-38987
aofl cli-lib v3.14.0 was discovered to contain a prototype pollution via the component defaultsDeep. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
π@cveNotify
aofl cli-lib v3.14.0 was discovered to contain a prototype pollution via the component defaultsDeep. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
π@cveNotify
Gist
[CVE-2024-38987] Prototype Pollution vulnerability affecting aofl/cli-lib module, versions <= 3.14.0
[CVE-2024-38987] Prototype Pollution vulnerability affecting aofl/cli-lib module, versions <= 3.14.0 - aofl-cli-lib-pp.md
π¨ CVE-2024-38990
Tada5hi sp-common v0.5.4 was discovered to contain a prototype pollution via the function mergeDeep. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
π@cveNotify
Tada5hi sp-common v0.5.4 was discovered to contain a prototype pollution via the function mergeDeep. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
π@cveNotify
Gist
[CVE-2024-38990] Vulnerability Advisory: @abip/sp-common, version 0.5.4
[CVE-2024-38990] Vulnerability Advisory: @abip/sp-common, version 0.5.4 - Advisory_Tada5hi.md
π¨ CVE-2024-38991
akbr patch-into v1.0.1 was discovered to contain a prototype pollution via the function patchInto. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
π@cveNotify
akbr patch-into v1.0.1 was discovered to contain a prototype pollution via the function patchInto. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
π@cveNotify
Gist
[CVE-2024-38991] Vulnerability Advisory: Prototype Pollution in @akbr/patch-into, version 1.0.1
[CVE-2024-38991] Vulnerability Advisory: Prototype Pollution in @akbr/patch-into, version 1.0.1 - Advisory_akbr.md
π¨ CVE-2024-38992
airvertco frappejs v0.0.11 was discovered to contain a prototype pollution via the function registerView. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
π@cveNotify
airvertco frappejs v0.0.11 was discovered to contain a prototype pollution via the function registerView. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
π@cveNotify
Gist
[CVE-2024-38992] Vulnerability Advisory: Prototype Pollution in @airvertco/frappejs, 0.0.11
[CVE-2024-38992] Vulnerability Advisory: Prototype Pollution in @airvertco/frappejs, 0.0.11 - Advisory_frappe.md
π¨ CVE-2024-38993
rjrodger jsonic-next v2.12.1 was discovered to contain a prototype pollution via the function empty. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
π@cveNotify
rjrodger jsonic-next v2.12.1 was discovered to contain a prototype pollution via the function empty. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
π@cveNotify
Gist
[CVE-2024-38993] Vulnerability Advisory Prototype Pollution in @jsonic/jsonic-next, version 2.12.1
[CVE-2024-38993] Vulnerability Advisory Prototype Pollution in @jsonic/jsonic-next, version 2.12.1 - Advisory_rjrodger.md
π¨ CVE-2024-38994
amoyjs amoy common v1.0.10 was discovered to contain a prototype pollution via the function extend. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
π@cveNotify
amoyjs amoy common v1.0.10 was discovered to contain a prototype pollution via the function extend. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.
π@cveNotify
Gist
[CVE-2024-38994] Vulnerability Advisory: Prototype Pollution in @amoy/common, version 1.0.10
[CVE-2024-38994] Vulnerability Advisory: Prototype Pollution in @amoy/common, version 1.0.10 - Advisory_amoyjs.md
π¨ CVE-2024-6387
A signal handler race condition was found in OpenSSH's server (sshd), where a client does not authenticate within LoginGraceTime seconds (120 by default, 600 in old OpenSSH versions), then sshd's SIGALRM handler is called asynchronously. However, this signal handler calls various functions that are not async-signal-safe, for example, syslog().
π@cveNotify
A signal handler race condition was found in OpenSSH's server (sshd), where a client does not authenticate within LoginGraceTime seconds (120 by default, 600 in old OpenSSH versions), then sshd's SIGALRM handler is called asynchronously. However, this signal handler calls various functions that are not async-signal-safe, for example, syslog().
π@cveNotify
π¨ CVE-2024-20399
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying operating system of an affected device.
This vulnerability is due to insufficient validation of arguments that are passed to specific configuration CLI commands. An attacker could exploit this vulnerability by including crafted input as the argument of an affected configuration CLI command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of root.
Note: To successfully exploit this vulnerability on a Cisco NX-OS device, an attacker must have Administrator credentials.
π@cveNotify
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying operating system of an affected device.
This vulnerability is due to insufficient validation of arguments that are passed to specific configuration CLI commands. An attacker could exploit this vulnerability by including crafted input as the argument of an affected configuration CLI command. A successful exploit could allow the attacker to execute arbitrary commands on the underlying operating system with the privileges of root.
Note: To successfully exploit this vulnerability on a Cisco NX-OS device, an attacker must have Administrator credentials.
π@cveNotify
Cisco
Cisco Security Advisory: Cisco NX-OS Software CLI Command Injection Vulnerability
A vulnerability in the CLI of Cisco NX-OS Software could allow an authenticated user in possession of Administrator credentials to execute arbitrary commands as root on the underlying operating system of an affected device.
This vulnerability is due to insufficientβ¦
This vulnerability is due to insufficientβ¦
π¨ CVE-2024-21586
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).
If an SRX Series device receives specific valid traffic destined to the device, it will cause the PFE to crash and restart. Continued receipt and processing of this traffic will create a sustained DoS condition.
This issue affects Junos OS on SRX Series:
* 21.4 versions before 21.4R3-S7.9,
* 22.1 versions before 22.1R3-S5.3,
* 22.2 versions before 22.2R3-S4.11,
* 22.3 versions before 22.3R3,
* 22.4 versions before 22.4R3.
Junos OS versions prior to 21.4R1 are not affected by this issue.
π@cveNotify
An Improper Check for Unusual or Exceptional Conditions vulnerability in the Packet Forwarding Engine (PFE) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS).
If an SRX Series device receives specific valid traffic destined to the device, it will cause the PFE to crash and restart. Continued receipt and processing of this traffic will create a sustained DoS condition.
This issue affects Junos OS on SRX Series:
* 21.4 versions before 21.4R3-S7.9,
* 22.1 versions before 22.1R3-S5.3,
* 22.2 versions before 22.2R3-S4.11,
* 22.3 versions before 22.3R3,
* 22.4 versions before 22.4R3.
Junos OS versions prior to 21.4R1 are not affected by this issue.
π@cveNotify
π¨ CVE-2024-36982
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109 and 9.1.2308.207, an attacker could trigger a null pointer reference on the cluster/config REST endpoint, which could result in a crash of the Splunk daemon.
π@cveNotify
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109 and 9.1.2308.207, an attacker could trigger a null pointer reference on the cluster/config REST endpoint, which could result in a crash of the Splunk daemon.
π@cveNotify
Splunk Vulnerability Disclosure
Denial of Service through null pointer reference in βcluster/configβ REST endpoint
In Splunk Enterprise versions below 9.2.2, 9.1.5, and 9.0.10 and Splunk Cloud Platform versions below 9.1.2312.109 and 9.1.2308.207, an attacker could trigger a null pointer reference on the βcluster/configβ REST endpoint, which could result in a crash ofβ¦