Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In August 2024
Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input and output can result in plaintext on an Intel Sandy Bridge processor. In Firefox this only affects the QUIC header protection feature when the connection is using the ChaCha20-Poly1305 cipher suite. The most likely outcome is connection failure, but if the connection persists despite the high packet loss it could be possible for a network observer to identify packets as coming from the same source despite a network path change. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, and Firefox ESR < 128.1.
CVSS Score
6.5
EPSS Score
0.001
Published
2024-08-06
A vulnerability was found in juzaweb CMS up to 3.4.2. It has been classified as problematic. Affected is an unknown function of the file /admin-cp/theme/editor/default of the component Theme Editor. The manipulation leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273696. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Score
2.7
EPSS Score
0.004
Published
2024-08-06
In JetBrains TeamCity before 2024.07.1 possible privilege escalation due to incorrect directory permissions
CVSS Score
7.5
EPSS Score
0.0
Published
2024-08-06
Insecure Direct Object Reference vulnerability identified in OpenText ArcSight Intelligence.
CVSS Score
6.3
EPSS Score
0.001
Published
2024-08-06
Incorrect Authorization vulnerability identified in OpenText ArcSight Intelligence.
CVSS Score
6.3
EPSS Score
0.001
Published
2024-08-06
Privilege escalation vulnerability identified in OpenText ArcSight Intelligence.
CVSS Score
6.4
EPSS Score
0.002
Published
2024-08-06
Select options could obscure the fullscreen notification dialog. This could be used by a malicious site to perform a spoofing attack. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.
CVSS Score
6.5
EPSS Score
0.003
Published
2024-08-06
Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the 'view' parameter in '/eventwinner/index.php'.
CVSS Score
7.1
EPSS Score
0.001
Published
2024-08-06
Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could exploit this vulnerability by sending a specially crafted query to the server and retrieve all the information stored in it through the 'view' parameter in '/student/index.php'.
CVSS Score
7.1
EPSS Score
0.001
Published
2024-08-06
Cross-Site Scripting (XSS) vulnerability in School Event Management System affecting version 1.0. An attacker could create a specially crafted URL and send it to a victim to obtain their session details via the 'view' parameter in /candidate/index.php'.
CVSS Score
7.1
EPSS Score
0.001
Published
2024-08-06


Contact Us

Shodan ® - All rights reserved