CVE-2024-5422 – Denial of Service
https://notcve.org/view.php?id=CVE-2024-5422
An uncontrolled resource consumption of file descriptors in SEH Computertechnik utnserver Pro, SEH Computertechnik utnserver ProMAX, SEH Computertechnik INU-100 allows DoS via HTTP.This issue affects utnserver Pro, utnserver ProMAX, INU-100 version 20.1.22 and below. Un consumo incontrolado de recursos de descriptores de archivos en SEH Computertechnik utnserver Pro, SEH Computertechnik utnserver ProMAX, SEH Computertechnik INU-100 permite DoS a través de HTTP. ... SEH utnserver Pro/ProMAX and INU-100 version 20.1.22 suffers from cross site scripting, denial of service, and file disclosure vulnerabilities. • http://seclists.org/fulldisclosure/2024/Jun/4 https://cyberdanube.com/en/en-multiple-vulnerabilities-in-seh-untserver-pro/index.html • CWE-400: Uncontrolled Resource Consumption •
CVE-2024-5421 – Authenticated Command Injection
https://notcve.org/view.php?id=CVE-2024-5421
SEH utnserver Pro/ProMAX and INU-100 version 20.1.22 suffers from cross site scripting, denial of service, and file disclosure vulnerabilities. • http://seclists.org/fulldisclosure/2024/Jun/4 https://cyberdanube.com/en/en-multiple-vulnerabilities-in-seh-untserver-pro/index.html • CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') •
CVE-2024-5420 – Stored Cross-Site Scripting in SEH Computertechnik utnserver Pro
https://notcve.org/view.php?id=CVE-2024-5420
SEH utnserver Pro/ProMAX and INU-100 version 20.1.22 suffers from cross site scripting, denial of service, and file disclosure vulnerabilities. • https://github.com/fa-rrel/CVE-2024-5420-XSS http://seclists.org/fulldisclosure/2024/Jun/4 https://cyberdanube.com/en/en-multiple-vulnerabilities-in-oring-iap420/index.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2024-36128 – Directus is soft-locked by providing a string value to random string util
https://notcve.org/view.php?id=CVE-2024-36128
This creates a denial of service situation where logged in sessions can no longer be refreshed as sessions depend on the capability to generate a random session ID. • https://github.com/directus/directus/commit/7d2a1392f43613094de700062aba168a9400dd3b https://github.com/directus/directus/security/advisories/GHSA-632p-p495-25m5 • CWE-754: Improper Check for Unusual or Exceptional Conditions •
CVE-2024-5197 – Integer overflow in libvpx
https://notcve.org/view.php?id=CVE-2024-5197
A successful full attack leads to the targeted application crashing, resulting in a denial of service or memory corruption, which results in data integrity issues. • https://g-issues.chromium.org/issues/332382766 https://lists.debian.org/debian-lts-announce/2024/06/msg00005.html https://access.redhat.com/security/cve/CVE-2024-5197 https://bugzilla.redhat.com/show_bug.cgi?id=2291198 • CWE-190: Integer Overflow or Wraparound •