
CVE-2024-30275 – Adobe Aero Beta has an arbitrary code execution vulnerability when parsing svg files
https://notcve.org/view.php?id=CVE-2024-30275
16 May 2024 — Adobe Aero Desktop versions 23.4 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. • https://helpx.adobe.com/security/products/aero/apsb24-33.html • CWE-416: Use After Free •

CVE-2024-30307 – Adobe Substance 3D Painter BMP File Parsing Out Of Bounds Write Vulnerability
https://notcve.org/view.php?id=CVE-2024-30307
16 May 2024 — Substance3D - Painter versions 9.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. • https://helpx.adobe.com/security/products/substance3d_painter/apsb24-31.html • CWE-787: Out-of-bounds Write •

CVE-2024-30274 – Adobe Substance 3D Painter ABC File Parsing An Out-Of-Bounds Write Vulnerability
https://notcve.org/view.php?id=CVE-2024-30274
16 May 2024 — Substance3D - Painter versions 9.1.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. • https://helpx.adobe.com/security/products/substance3d_painter/apsb24-31.html • CWE-787: Out-of-bounds Write •

CVE-2024-20792 – Adobe Illustrator TIF File Parsing Use-After-Free Remote memory corruption
https://notcve.org/view.php?id=CVE-2024-20792
16 May 2024 — Illustrator versions 28.4, 27.9.3 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. • https://helpx.adobe.com/security/products/illustrator/apsb24-30.html • CWE-416: Use After Free •

CVE-2024-33871 – ghostscript: OPVP device arbitrary code execution via custom Driver library
https://notcve.org/view.php?id=CVE-2024-33871
16 May 2024 — An issue was discovered in Artifex Ghostscript before 10.03.1. contrib/opvp/gdevopvp.c allows arbitrary code execution via a custom Driver library, exploitable via a crafted PostScript document. ... This flaw allows a malicious user to send a specially crafted document that, when processed by Ghostscript, could potentially lead to arbitrary code execution with the privileges of the Ghostscript process on the system. • https://bugs.ghostscript.com/show_bug.cgi?id=707754 • CWE-20: Improper Input Validation CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-2024-4202 – Progress Telerik Reporting Local Instantiation Vulnerability
https://notcve.org/view.php?id=CVE-2024-4202
15 May 2024 — In Progress® Telerik® Reporting versions prior to 2024 Q2 (18.1.24.514), a code execution attack is possible through an insecure instantiation vulnerability. En las versiones de Progress® Telerik® Reporting anteriores al segundo trimestre de 2024 (18.1.24.514), es posible un ataque de ejecución de código a través de una vulnerabilidad de instanciación insegura. • https://docs.telerik.com/reporting/knowledge-base/instantiation-vulnerability-cve-2024-4202 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-2024-3892 – Local code execution vulnerability in Telerik UI for WinForms
https://notcve.org/view.php?id=CVE-2024-3892
15 May 2024 — A local code execution vulnerability is possible in Telerik UI for WinForms beginning in v2021.1.122 but prior to v2024.2.514. This vulnerability could allow an untrusted theme assembly to execute arbitrary code on the local Windows system. Es posible una vulnerabilidad de ejecución de código local en la interfaz de usuario de Telerik para WinForms a partir de v2021.1.122 pero antes de v2024.2.514. Esta vulnerabilidad podría permitir que un ensamblado de temas que no sea de confianza ejecute código arbitrar... • https://docs.telerik.com/devtools/winforms/knowledge-base/local-code-execution-vulnerability-cve-2024-3892 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-2023-5936 – Unsafe temporary data privileges on Unix systems in Arc before v1.6.0
https://notcve.org/view.php?id=CVE-2023-5936
15 May 2024 — By tampering with such file, a malicious local user in the system may be able to trigger arbitrary code execution with root privileges. • https://security.nozominetworks.com/NN-2023:14-01 • CWE-732: Incorrect Permission Assignment for Critical Resource •

CVE-2023-5935 – Missing authentication for local web interface in Arc before v1.6.0
https://notcve.org/view.php?id=CVE-2023-5935
15 May 2024 — This could also lead to arbitrary code execution if a malicious update package is installed. • https://security.nozominetworks.com/NN-2023:13-01 • CWE-306: Missing Authentication for Critical Function •

CVE-2024-35179 – Unprivileged Stalwart Mail Server user can read files as root
https://notcve.org/view.php?id=CVE-2024-35179
15 May 2024 — This issue affects admins who have set up to run stalwart with `RUN_AS_USER` who handed out admin credentials to the mail server but expect these to only grant access according to the `RUN_AS_USER` and are attacked where the attackers managed to achieve Arbitrary Code Execution using another vulnerability. • https://github.com/stalwartlabs/mail-server/security/advisories/GHSA-5pfx-j27j-4c6h • CWE-271: Privilege Dropping / Lowering Errors •