Latest CVE Feed
-
6.1
MEDIUMCVE-2024-21263
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 7.0.22 and prior to 7.1.2. Easily exploitable vulnerability allows low privileged attacker with logon to the ... Read more
Affected Products : vm_virtualbox- Published: Oct. 15, 2024
- Modified: Oct. 18, 2024
-
7.5
HIGHCVE-2024-21215
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access v... Read more
- Published: Oct. 15, 2024
- Modified: Oct. 18, 2024
-
5.5
MEDIUMCVE-2024-20787
Substance3D - Painter versions 10.0.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this... Read more
Affected Products : substance_3d_painter- Published: Oct. 09, 2024
- Modified: Oct. 18, 2024
-
7.8
HIGHCVE-2024-45144
Substance3D - Stager versions 3.0.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim mu... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 18, 2024
-
7.8
HIGHCVE-2024-45143
Substance3D - Stager versions 3.0.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a vic... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 18, 2024
-
7.8
HIGHCVE-2024-45142
Substance3D - Stager versions 3.0.3 and earlier are affected by a Write-what-where Condition vulnerability that could allow an attacker to execute arbitrary code in the context of the current user. This vulnerability allows an attacker to write a controll... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 18, 2024
-
7.8
HIGHCVE-2024-45141
Substance3D - Stager versions 3.0.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim mu... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 18, 2024
-
7.8
HIGHCVE-2024-45140
Substance3D - Stager versions 3.0.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim mu... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 18, 2024
-
7.8
HIGHCVE-2024-45139
Substance3D - Stager versions 3.0.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a vic... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 18, 2024
-
7.8
HIGHCVE-2024-45138
Substance3D - Stager versions 3.0.3 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must ope... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 18, 2024
-
7.8
HIGHCVE-2024-45152
Substance3D - Stager versions 3.0.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim mu... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 18, 2024
-
7.8
HIGHCVE-2024-45146
Dimension versions 4.0.3 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicio... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 18, 2024
-
7.8
HIGHCVE-2024-45150
Dimension versions 4.0.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a m... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 18, 2024
-
5.5
MEDIUMCVE-2024-45145
Lightroom Desktop versions 7.4.1, 13.5, 12.5.1 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitatio... Read more
Affected Products : lightroom- Published: Oct. 09, 2024
- Modified: Oct. 18, 2024
-
7.8
HIGHCVE-2024-45136
InCopy versions 19.4, 18.5.3 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution by an attacker. An attacker could exploit this vulnerability by uploading a malicious f... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 18, 2024
-
7.8
HIGHCVE-2024-45137
InDesign Desktop versions 19.4, 18.5.3 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by uploading a malicious file w... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 18, 2024
-
4.9
MEDIUMCVE-2024-21193
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: PS). Supported versions that are affected are 8.0.39 and prior, 8.4.2 and prior and 9.0.1 and prior. Easily exploitable vulnerability allows high privileged attacker with netw... Read more
- Published: Oct. 15, 2024
- Modified: Oct. 18, 2024
-
4.4
MEDIUMCVE-2024-21192
Vulnerability in the Oracle Enterprise Manager for Fusion Middleware product of Oracle Fusion Middleware (component: WebLogic Mgmt). The supported version that is affected is 12.2.1.4.0. Easily exploitable vulnerability allows high privileged attacker w... Read more
- Published: Oct. 15, 2024
- Modified: Oct. 18, 2024
-
7.8
HIGHCVE-2024-47424
Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in ... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 18, 2024
-
7.8
HIGHCVE-2024-47423
Adobe Framemaker versions 2020.6, 2022.4 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution. An attacker could exploit this vulnerability by uploading a malicious file... Read more
- Published: Oct. 09, 2024
- Modified: Oct. 18, 2024