CVE-2023-6361
https://notcve.org/view.php?id=CVE-2023-6361
This could allow attackers to execute arbitrary code via a long filename argument. • https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-winhex • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer •
CVE-2024-20103
https://notcve.org/view.php?id=CVE-2024-20103
This could lead to remote code execution with no additional execution privileges needed. • https://corp.mediatek.com/product-security-bulletin/October-2024 • CWE-787: Out-of-bounds Write •
CVE-2024-20101
https://notcve.org/view.php?id=CVE-2024-20101
This could lead to remote code execution with no additional execution privileges needed. • https://corp.mediatek.com/product-security-bulletin/October-2024 • CWE-787: Out-of-bounds Write •
CVE-2024-20100
https://notcve.org/view.php?id=CVE-2024-20100
This could lead to remote code execution with no additional execution privileges needed. • https://corp.mediatek.com/product-security-bulletin/October-2024 • CWE-787: Out-of-bounds Write •
CVE-2024-45933
https://notcve.org/view.php?id=CVE-2024-45933
OnlineNewsSite v1.0 is vulnerable to Cross Site Scripting (XSS) which allows attackers to execute arbitrary code via the Title and summary fields in the /admin/post/edit/ endpoint. • http://TobeReleased.com https://github.com/AslamMahi/CVE-Aslam-Mahi/blob/main/MobinaJafarian-OnlineNewsSite%20v%201.0/CVE-2024-45933.md • CWE-94: Improper Control of Generation of Code ('Code Injection') •