CVE-2024-27884
Lun, 29/07/2024 – 23:15
CVE-2024-27884
CVE-2024-27884
Lun, 29/07/2024 – 23:15
CVE-2024-27884
CVE-2024-40813
Lun, 29/07/2024 – 23:15
CVE-2024-40813
CVE-2023-42958
Lun, 29/07/2024 – 21:15
CVE-2023-42958
CVE-2023-42957
Lun, 29/07/2024 – 21:15
CVE-2023-42957
CVE-2023-42949
Lun, 29/07/2024 – 21:15
CVE-2023-42949
CVE-2024-3219
Lun, 29/07/2024 – 22:15
CVE-2024-3219
The
“socket” module provides a pure-Python fallback to the
socket.socketpair() function for platforms that don’t support AF_UNIX,
such as Windows. This pure-Python implementation uses AF_INET or
AF_INET6 to create a local connected pair of sockets. The connection
between the two sockets was not verified before passing the two sockets
back to the user, which leaves the server socket vulnerable to a
connection race from a malicious local peer.
Platforms that support AF_UNIX such as Linux and macOS are not affected by this vulnerability. Versions prior to CPython 3.5 are not affected due to the vulnerable API not being included.
CVE-2024-7249
Lun, 29/07/2024 – 22:15
CVE-2024-7249
The specific flaw exists within the cmdagent executable. By creating a symbolic link, an attacker can abuse the application to delete a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-21794.
CVE-2024-7248
Lun, 29/07/2024 – 22:15
CVE-2024-7248
The specific flaw exists within the update mechanism. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-19055.
CVE-2024-7252
Lun, 29/07/2024 – 22:15
CVE-2024-7252
The specific flaw exists within the cmdagent executable. By creating a symbolic link, an attacker can abuse the agent to delete a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-22831.
CVE-2024-7251
Lun, 29/07/2024 – 22:15
CVE-2024-7251
The specific flaw exists within the cmdagent executable. By creating a symbolic link, an attacker can abuse the agent to create a file. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-22832.