Skip to content

Instantly share code, notes, and snippets.

@1047524396
1047524396 / CVE-2024-24479
Created February 20, 2024 08:00
CVE-2024-24479
[CVE ID]
CVE-2024-24479
[PRODUCT]
wireshark
[VERSION]
wireshark-4.2.0
[PROBLEM TYPE]
Buffer Overflow
[DESCRIPTION]
Buffer Overflow vulnerability in Wireshark before v4.2.0 allows a remote attacker to cause a denial of service via the wsutil/to_str.c, and format_fractional_part_nsecs components.
@1047524396
1047524396 / CVE-2024-24478
Last active February 20, 2024 08:01
CVE-2024-24478
[CVE ID]
CVE-2024-24478
[PRODUCT]
wireshark
[VERSION]
wireshark-4.2.0
[PROBLEM TYPE]
Integer Overflow
[DESCRIPTION]
An issue in Wireshark before v4.2.0 allows a remote attacker to cause a denial of service via the packet-bgp.c, dissect_bgp_open(tvbuff_t*tvb, proto_tree*tree, packet_info*pinfo), optlen components.
@1047524396
1047524396 / CVE-2024-24476
Created February 20, 2024 07:05
CVE-2024-24476
[CVE ID]
CVE-2024-24476
[PRODUCT]
wireshark
[VERSION]
wireshark-4.2.0
[PROBLEM TYPE]
Buffer Overflow
[DESCRIPTION]
Buffer Overflow vulnerability in Wireshark before v.4.2.0 allows a remote attacker to cause a denial of service via the pan/addr_resolv.c, and ws_manuf_lookup_str(), size components.
@1047524396
1047524396 / CVE-2024-24475
Created February 20, 2024 03:22
CVE-2024-24475
[CVE ID]
CVE-2024-24475
[PRODUCT]
Qemu
[VERSION]
Qemu v8.2.0
[PROBLEM TYPE]
CWE-125: Out-of-bounds Read
[DESCRIPTION]
An issue in Qemu before v.8.2.0 allows a remote attacker to execute arbitrary code via the contrib/elf2dmp/pdb.c, pdb_get_file_size(const struct pdb_reader *r, unsigned idx) component.
@1047524396
1047524396 / CVE-2024-24474
Created February 20, 2024 02:52
CVE-2024-24474
[CVE ID]
CVE-2024-24474
[PRODUCT]
Qemu
[VERSION]
Qemu v8.2.0
[PROBLEM TYPE]
Buffer Overflow
[DESCRIPTION]
Buffer Overflow vulnerability in Qemu before v.8.2.0 allows a remote attacker to execute arbitrary code via the async_len variable to the FIFO buffer component.
@1047524396
1047524396 / CVE-2024-22862
Last active January 25, 2024 13:49
CVE-2024-22862
[CVE ID]
CVE-2024-22862
[PRODUCT]
FFmpeg
[VERSION]
FFmpeg n6.1
[PROBLEM TYPE]
integer overflow
[DESCRIPTION]
The JPEG XL Parser in FFmpeg before n6.1 was discovered to contain an integer overflow.
@1047524396
1047524396 / CVE-2024-22861
Last active January 25, 2024 13:48
CVE-2024-22861
[CVE ID]
CVE-2024-22861
[PRODUCT]
FFmpeg
[VERSION]
FFmpeg n6.1
[PROBLEM TYPE]
Integer Overflow
[DESCRIPTION]
FFmpeg before n6.1 was discovered to contain an integer overflow via the avcodec/osq module.
@1047524396
1047524396 / CVE-2024-22860
Last active January 25, 2024 13:52
CVE-2024-22860
[CVE ID]
CVE-2024-22860
[PRODUCT]
FFmpeg
[VERSION]
FFmpeg n6.1
[PROBLEM TYPE]
Buffer Overflow
[DESCRIPTION]
The JPEG XL Animation decoder in FFmpeg before n6.1 was discovered to contain an integer overflow to buffer overflow.
@1047524396
1047524396 / CVE-2024-22859
Created January 25, 2024 13:40
CVE-2024-22859
[CVE ID]
CVE-2024-22859
[PRODUCT]
livewire
[VERSION]
from v3.0.4 to v3.3.5
[PROBLEM TYPE]
Cross Site Request Forgery (CSRF)
[DESCRIPTION]
livewire fixed from v3.0.4 to v3.3.5 was discovered to contain a Cross-Site Request Forgery (CSRF).
@1047524396
1047524396 / CVE-2023-52071
Last active January 25, 2024 13:32
CVE-2023-52071
[CVE ID]
CVE-2023-52071
[PRODUCT]
curl
[VERSION]
curl-8_4_0 and curl-8_5_0
[PROBLEM TYPE]
CWE-193: Off-by-one Error
[DESCRIPTION]
tiny-curl-8_4_0 and curl curl-8_5_0 were discovered to contain an off-by-one out-of-bounds array index via the component tool_cb_wrt.