CVE-2024-25947
https://notcve.org/view.php?id=CVE-2024-25947
01 Aug 2024 — Dell iDRAC Service Module version 5.3.0.0 and prior, contain an Out of bound Read Vulnerability. A privileged local attacker could execute arbitrary code potentially resulting in a denial of service event. Dell iDRAC Service Module versión 5.3.0.0 y anteriores contiene una vulnerabilidad de lectura fuera de los límites. • https://www.dell.com/support/kbdoc/en-us/000227444/dsa-2024-086-security-update-for-dell-idrac-service-module-for-memory-corruption-vulnerabilities • CWE-787: Out-of-bounds Write •
CVE-2024-23930 – Pioneer DMH-WT7600NEX Media Service Improper Handling of Exceptional Conditions Denial-of-Service Vulnerability
https://notcve.org/view.php?id=CVE-2024-23930
01 Aug 2024 — This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of Pioneer DMH-WT7600NEX devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Media service, which listens on TCP port 42000 by default. ... An attacker can leverage this vulnerability to create a denial-of-service condition on the system. •
CVE-2024-7392 – ChargePoint Home Flex Bluetooth Low Energy Denial-of-Service Vulnerability
https://notcve.org/view.php?id=CVE-2024-7392
01 Aug 2024 — ChargePoint Home Flex Bluetooth Low Energy Denial-of-Service Vulnerability. This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of ChargePoint Home Flex charging devices. This vulnerability allows network-adjacent attackers to create a denial-of-service condition on affected installations of ChargePoint Home Flex charging devices. ... An attacker can leverage this vulnerability t... • https://www.zerodayinitiative.com/advisories/ZDI-24-1047 • CWE-410: Insufficient Resource Pool •
CVE-2022-4003
https://notcve.org/view.php?id=CVE-2022-4003
31 Jul 2024 — A denial-of-service vulnerability could allow an authenticated user to trigger an internal service restart via a specially crafted API request. • https://en-us.support.motorola.com/app/answers/detail/a_id/176952/~/motorola-q14-mesh-router-vulnerabilities • CWE-400: Uncontrolled Resource Consumption •
CVE-2024-31203
https://notcve.org/view.php?id=CVE-2024-31203
31 Jul 2024 — A “CWE-121: Stack-based Buffer Overflow” in the wd210std.dll dynamic library packaged with the ThermoscanIP installer allows a local attacker to possibly trigger a Denial-of-Service (DoS) condition on the target component. • https://www.nozominetworks.com/labs/vulnerability-advisories-cve-2024-31203 • CWE-121: Stack-based Buffer Overflow •
CVE-2024-37281 – Kibana Denial of Service issue
https://notcve.org/view.php?id=CVE-2024-37281
30 Jul 2024 — An issue was discovered in Kibana where a user with Viewer role could cause a Kibana instance to crash by sending a large number of maliciously crafted requests to a specific endpoint. • https://discuss.elastic.co/t/kibana-7-17-23-8-14-0-security-update-esa-2024-16/364094 • CWE-400: Uncontrolled Resource Consumption •
CVE-2024-37299 – Discourse vulnerable to DoS via Tag Group
https://notcve.org/view.php?id=CVE-2024-37299
30 Jul 2024 — Discourse is an open source discussion platform. Prior to 3.2.5 and 3.3.0.beta5, crafting requests to submit very long tag group names can reduce the availability of a Discourse instance. This vulnerability is fixed in 3.2.5 and 3.3.0.beta5. • https://github.com/discourse/discourse/commit/188cb58daa833839c54c266ce22db150a3f3a210 • CWE-400: Uncontrolled Resource Consumption •
CVE-2024-42229 – crypto: aead,cipher - zeroize key buffer after use
https://notcve.org/view.php?id=CVE-2024-42229
30 Jul 2024 — A local attacker could possibly use this to cause a denial of service. • https://git.kernel.org/stable/c/89b9b6fa4463daf820e6a5ef65c3b0c2db239513 •
CVE-2024-42227 – drm/amd/display: Fix overlapping copy within dml_core_mode_programming
https://notcve.org/view.php?id=CVE-2024-42227
30 Jul 2024 — A local attacker could possibly use this to cause a denial of service. • https://git.kernel.org/stable/c/7966f319c66d9468623c6a6a017ecbc0dd79be75 •
CVE-2024-42225 – wifi: mt76: replace skb_put with skb_put_zero
https://notcve.org/view.php?id=CVE-2024-42225
30 Jul 2024 — A local attacker could possibly use this to cause a denial of service. • https://git.kernel.org/stable/c/7bc04215a66b60e198aecaee8418f6d79fa19faa • CWE-457: Use of Uninitialized Variable •