Latest CVE Feed
-
7.8
HIGHCVE-2024-44291
A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. A malicious app may be able to gain root privileges.... Read more
Affected Products : macos- Published: Dec. 12, 2024
- Modified: Dec. 16, 2024
-
3.3
LOWCVE-2024-44290
This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.1 and iPadOS 18.1, watchOS 11.1. An app may be able to determine a user’s current location.... Read more
- Published: Dec. 12, 2024
- Modified: Dec. 16, 2024
-
6.5
MEDIUMCVE-2024-44248
This issue was addressed through improved state management. This issue is fixed in macOS Ventura 13.7.2, macOS Sonoma 14.7.2. A user with screen sharing access may be able to view another user's screen.... Read more
Affected Products : macos- Published: Dec. 12, 2024
- Modified: Dec. 16, 2024
-
5.3
MEDIUMCVE-2024-44246
The issue was addressed with improved routing of Safari-originated requests. This issue is fixed in macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2, Safari 18.2, iPadOS 17.7.3. On a device with Private Relay enabled, adding a website to the Safari Reading Li... Read more
- Published: Dec. 12, 2024
- Modified: Dec. 18, 2024
-
7.1
HIGHCVE-2024-44245
The issue was addressed with improved memory handling. This issue is fixed in iPadOS 17.7.3, visionOS 2.2, macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2, macOS Sonoma 14.7.2. An app may be able to cause unexpected system termination or corrupt kernel memor... Read more
- Published: Dec. 12, 2024
- Modified: Dec. 20, 2024
-
5.5
MEDIUMCVE-2024-44243
A configuration issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.2. An app may be able to modify protected parts of the file system.... Read more
Affected Products : macos- Published: Dec. 12, 2024
- Modified: Dec. 20, 2024
-
9.8
CRITICALCVE-2024-44242
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1. An attacker may be able to cause unexpected system termination or arbitrary code execution in DCP firmware.... Read more
- Published: Dec. 12, 2024
- Modified: Dec. 18, 2024
-
9.8
CRITICALCVE-2024-44241
The issue was addressed with improved bounds checks. This issue is fixed in iOS 18.1 and iPadOS 18.1. An attacker may be able to cause unexpected system termination or arbitrary code execution in DCP firmware.... Read more
- Published: Dec. 12, 2024
- Modified: Dec. 18, 2024
-
7.8
HIGHCVE-2024-44225
A logic issue was addressed with improved checks. This issue is fixed in iPadOS 17.7.3, watchOS 11.2, tvOS 18.2, macOS Sequoia 15.2, iOS 18.2 and iPadOS 18.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. An app may be able to gain elevated privileges.... Read more
- Published: Dec. 12, 2024
- Modified: Dec. 20, 2024
-
7.8
HIGHCVE-2024-44224
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.2, macOS Ventura 13.7.2, macOS Sonoma 14.7.2. A malicious app may be able to gain root privileges.... Read more
Affected Products : macos- Published: Dec. 12, 2024
- Modified: Dec. 20, 2024
-
6.5
MEDIUMCVE-2024-44220
The issue was addressed with improved memory handling. This issue is fixed in macOS Sequoia 15.2, macOS Sonoma 14.7.2. Parsing a maliciously crafted video file may lead to unexpected system termination.... Read more
Affected Products : macos- Published: Dec. 12, 2024
- Modified: Dec. 18, 2024
-
5.3
MEDIUMCVE-2024-44212
A cookie management issue was addressed with improved state management. This issue is fixed in Safari 18.1, visionOS 2.1, tvOS 18.1, iOS 18.1 and iPadOS 18.1, watchOS 11.1. Cookies belonging to one origin may be sent to another origin.... Read more
- Published: Dec. 12, 2024
- Modified: Dec. 20, 2024
-
5.5
MEDIUMCVE-2024-44201
The issue was addressed with improved memory handling. This issue is fixed in iPadOS 17.7.3, macOS Ventura 13.7.2, iOS 18.1 and iPadOS 18.1, macOS Sonoma 14.7.2. Processing a malicious crafted file may lead to a denial-of-service.... Read more
- Published: Dec. 12, 2024
- Modified: Dec. 13, 2024
-
5.5
MEDIUMCVE-2024-44200
This issue was addressed with improved redaction of sensitive information. This issue is fixed in iOS 18.1 and iPadOS 18.1. An app may be able to read sensitive location information.... Read more
- Published: Dec. 12, 2024
- Modified: Dec. 13, 2024
-
8.5
HIGHCVE-2024-42407
Insertion of Sensitive Information into Log File (CWE-532) in the Gallagher Command Centre Alarm Transmitter feature could allow an authenticated Operator to view some security sensitive information to which they have not been granted access. This issue... Read more
Affected Products :- Published: Dec. 12, 2024
- Modified: Dec. 12, 2024
-
4.6
MEDIUMCVE-2024-41146
Use of Multiple Resources with Duplicate Identifier (CWE-694) in the Controller 6000 and Controller 7000 Platforms could allow an attacker with physical access to HBUS communication cabling to perform a Denial-of-Service attack against HBUS connected devi... Read more
Affected Products :- Published: Dec. 12, 2024
- Modified: Dec. 12, 2024
-
5.4
MEDIUMCVE-2024-12536
A vulnerability, which was classified as problematic, has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0. Affected by this issue is some unknown functionality of the file /control/client_data.php. The manipulation of the ar... Read more
Affected Products : advocate_office_management_system- Published: Dec. 12, 2024
- Modified: Dec. 13, 2024
-
5.1
MEDIUMCVE-2024-12503
A vulnerability classified as problematic was found in ClassCMS 4.8. Affected by this vulnerability is an unknown functionality of the file /index.php/admin of the component Model Management Page. The manipulation of the argument URL leads to cross site s... Read more
Affected Products : classcms- Published: Dec. 12, 2024
- Modified: Dec. 13, 2024
-
9.8
CRITICALCVE-2024-12497
A vulnerability classified as critical has been found in 1000 Projects Attendance Tracking Management System 1.0. Affected is an unknown function of the file /admin/check_admin_login.php. The manipulation of the argument admin_user_name leads to sql injec... Read more
Affected Products : attendance_tracking_management_system- Published: Dec. 12, 2024
- Modified: Dec. 13, 2024
-
8.8
HIGHCVE-2024-12492
A vulnerability was found in code-projects Farmacia 1.0. It has been rated as critical. This issue affects some unknown processing of the file /visualizar-usuario.php. The manipulation of the argument id leads to sql injection. The attack may be initiated... Read more
- Published: Dec. 12, 2024
- Modified: Dec. 13, 2024