Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In August 2024
Incorrect garbage collection interaction in IndexedDB could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.
CVSS Score
8.8
EPSS Score
0.002
Published
2024-08-06
The date picker could partially obscure security prompts. This could be used by a malicious site to trick a user into granting permissions. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
CVSS Score
6.5
EPSS Score
0.001
Published
2024-08-06
Incorrect garbage collection interaction could have led to a use-after-free. This vulnerability affects Firefox < 129.
CVSS Score
8.8
EPSS Score
0.003
Published
2024-08-06
Calling `PK11_Encrypt()` in NSS using CKM_CHACHA20 and the same buffer for input and output can result in plaintext on an Intel Sandy Bridge processor. In Firefox this only affects the QUIC header protection feature when the connection is using the ChaCha20-Poly1305 cipher suite. The most likely outcome is connection failure, but if the connection persists despite the high packet loss it could be possible for a network observer to identify packets as coming from the same source despite a network path change. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, and Firefox ESR < 128.1.
CVSS Score
6.5
EPSS Score
0.001
Published
2024-08-06
A vulnerability was found in juzaweb CMS up to 3.4.2. It has been classified as problematic. Affected is an unknown function of the file /admin-cp/theme/editor/default of the component Theme Editor. The manipulation leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-273696. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Score
2.7
EPSS Score
0.004
Published
2024-08-06
In JetBrains TeamCity before 2024.07.1 possible privilege escalation due to incorrect directory permissions
CVSS Score
7.5
EPSS Score
0.0
Published
2024-08-06
Insecure Direct Object Reference vulnerability identified in OpenText ArcSight Intelligence.
CVSS Score
6.3
EPSS Score
0.001
Published
2024-08-06
Incorrect Authorization vulnerability identified in OpenText ArcSight Intelligence.
CVSS Score
6.3
EPSS Score
0.001
Published
2024-08-06
Privilege escalation vulnerability identified in OpenText ArcSight Intelligence.
CVSS Score
6.4
EPSS Score
0.002
Published
2024-08-06
Select options could obscure the fullscreen notification dialog. This could be used by a malicious site to perform a spoofing attack. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.
CVSS Score
6.5
EPSS Score
0.003
Published
2024-08-06


Contact Us

Shodan ® - All rights reserved