
CVE-2024-27277 – IBM Storage Protect Plus Server information disclosure
https://notcve.org/view.php?id=CVE-2024-27277
21 Mar 2024 — The private key for the IBM Storage Protect Plus Server 10.1.0 through 10.1.16 certificate can be disclosed, undermining the security of the certificate. IBM X-Force ID: 285205. La clave privada del certificado IBM Storage Protect Plus Server 10.1.0 a 10.1.16 se puede divulgar, lo que socava la seguridad del certificado. ID de IBM X-Force: 285205. • https://exchange.xforce.ibmcloud.com/vulnerabilities/285205 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2024-28834 – Gnutls: vulnerable to minerva side-channel information leak
https://notcve.org/view.php?id=CVE-2024-28834
21 Mar 2024 — A remote attacker could possibly use this issue to recover sensitive information. • http://www.openwall.com/lists/oss-security/2024/03/22/1 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-327: Use of a Broken or Risky Cryptographic Algorithm •

CVE-2024-2631 – Debian Security Advisory 5648-1
https://notcve.org/view.php?id=CVE-2024-2631
20 Mar 2024 — (Severidad de seguridad de Chrome: baja) Security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure. • https://chromereleases.googleblog.com/2024/03/stable-channel-update-for-desktop_19.html •

CVE-2024-2630 – Debian Security Advisory 5648-1
https://notcve.org/view.php?id=CVE-2024-2630
20 Mar 2024 — (Severidad de seguridad de Chromium: media) Security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure. • https://github.com/Roud-Roud-Agency/CVE-2024-26304-RCE-exploits • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2024-2629 – Debian Security Advisory 5648-1
https://notcve.org/view.php?id=CVE-2024-2629
20 Mar 2024 — (Severidad de seguridad de Chromium: media) Security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure. • https://chromereleases.googleblog.com/2024/03/stable-channel-update-for-desktop_19.html •

CVE-2024-2628 – Debian Security Advisory 5648-1
https://notcve.org/view.php?id=CVE-2024-2628
20 Mar 2024 — (Severidad de seguridad de Chromium: media) Security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure. • https://chromereleases.googleblog.com/2024/03/stable-channel-update-for-desktop_19.html • CWE-474: Use of Function with Inconsistent Implementations •

CVE-2024-2627 – Debian Security Advisory 5648-1
https://notcve.org/view.php?id=CVE-2024-2627
20 Mar 2024 — (Severidad de seguridad de Chromium: media) Security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure. • https://chromereleases.googleblog.com/2024/03/stable-channel-update-for-desktop_19.html • CWE-416: Use After Free •

CVE-2024-2626 – Debian Security Advisory 5648-1
https://notcve.org/view.php?id=CVE-2024-2626
20 Mar 2024 — (Severidad de seguridad de Chromium: media) Security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure. • https://chromereleases.googleblog.com/2024/03/stable-channel-update-for-desktop_19.html • CWE-125: Out-of-bounds Read •

CVE-2024-2625 – Debian Security Advisory 5648-1
https://notcve.org/view.php?id=CVE-2024-2625
20 Mar 2024 — (Severidad de seguridad de Chrome: alta) Security issues were discovered in Chromium, which could result in the execution of arbitrary code, denial of service or information disclosure. • https://chromereleases.googleblog.com/2024/03/stable-channel-update-for-desktop_19.html •

CVE-2023-35888 – IBM Security Verify Governance information disclosure
https://notcve.org/view.php?id=CVE-2023-35888
20 Mar 2024 — IBM Security Verify Governance 10.0.2 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. • https://exchange.xforce.ibmcloud.com/vulnerabilities/258375 • CWE-311: Missing Encryption of Sensitive Data •