CVE-2024-12839
Mar, 31/12/2024 – 02:15
CVE-2024-12839
CVE-2024-12839
Mar, 31/12/2024 – 02:15
CVE-2024-12839
CVE-2024-13045
Lun, 30/12/2024 – 21:15
CVE-2024-13045
The specific flaw exists within the parsing of AR files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24848.
CVE-2024-13044
Lun, 30/12/2024 – 21:15
CVE-2024-13044
The specific flaw exists within the parsing of AR files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24870.
CVE-2024-13043
Lun, 30/12/2024 – 21:15
CVE-2024-13043
The specific flaw exists within the Hotspot Shield. By creating a junction, an attacker can abuse the application to delete arbitrary files. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM. Was ZDI-CAN-23478.
CVE-2024-13051
Lun, 30/12/2024 – 21:15
CVE-2024-13051
The specific flaw exists within the parsing of VC6 files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24977.
CVE-2024-13050
Lun, 30/12/2024 – 21:15
CVE-2024-13050
The specific flaw exists within the parsing of VC6 files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24976.
CVE-2024-13049
Lun, 30/12/2024 – 21:15
CVE-2024-13049
The specific flaw exists within the parsing of XE files. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24847.
CVE-2024-13048
Lun, 30/12/2024 – 21:15
CVE-2024-13048
The specific flaw exists within the parsing of XE files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24844.
CVE-2024-13047
Lun, 30/12/2024 – 21:15
CVE-2024-13047
The specific flaw exists within the parsing of CO files. The issue results from the lack of proper validation of user-supplied data, which can result in a type confusion condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24843.
CVE-2024-13046
Lun, 30/12/2024 – 21:15
CVE-2024-13046
The specific flaw exists within the parsing of CO files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-24867.