CVE-2024-7138 – Denial of Service in Silicon Labs RS9116 Bluetooth SDK
https://notcve.org/view.php?id=CVE-2024-7138
An assert may be triggered, causing a temporary denial of service when a peer device sends a specially crafted malformed L2CAP packet. • https://community.silabs.com/068Vm00000F9zre • CWE-617: Reachable Assertion •
CVE-2024-7137 – Denial of Service in Silicon Labs RS9116 Bluetooth SDK
https://notcve.org/view.php?id=CVE-2024-7137
The L2CAP receive data buffer for L2CAP packets is restricted to packet sizes smaller than the maximum supported packet size. Receiving a packet that exceeds the restricted buffer length may cause a crash. A hard reset is required to recover the crashed device. • https://community.silabs.com/068Vm00000F9zre • CWE-787: Out-of-bounds Write •
CVE-2024-51471 – IBM MQ Appliance denial of service
https://notcve.org/view.php?id=CVE-2024-51471
IBM MQ Appliance 9.3 LTS, 9.3 CD, and 9.4 LTS web console could allow an authenticated user to cause a denial-of-service when trace is enabled due to information being written into memory outside of the intended buffer size. • https://www.ibm.com/support/pages/node/7178243 • CWE-125: Out-of-bounds Read •
CVE-2024-4230
https://notcve.org/view.php?id=CVE-2024-4230
External Control of File Name or Path vulnerability in Edgecross Basic Software for Windows versions 1.00 and later and Edgecross Basic Software for Developers versions 1.00 and later allows a malicious local attacker to execute an arbitrary malicious code, resulting in information disclosure, tampering with and deletion, or a denial-of-service (DoS) condition. • https://jvn.jp/vu/JVNVU92857077/index.html https://www.edgecross.org/client_info/EDGECROSS/view/userweb/ext/en/data-download/pdf/ECD-TE10-0003-01-EN.pdf • CWE-73: External Control of File Name or Path •
CVE-2024-4229
https://notcve.org/view.php?id=CVE-2024-4229
Incorrect Default Permissions vulnerability in Edgecross Basic Software for Windows versions 1.00 and later and Edgecross Basic Software for Developers versions 1.00 and later allows a malicious local attacker to execute an arbitrary malicious code, resulting in information disclosure, tampering with and deletion, or a denial-of-service (DoS) condition, if the product is installed in a folder other than a folder that only users with administrative privilege have permission to modify. • https://jvn.jp/vu/JVNVU92857077/index.html https://www.edgecross.org/client_info/EDGECROSS/view/userweb/ext/en/data-download/pdf/ECD-TE10-0003-01-EN.pdf • CWE-276: Incorrect Default Permissions •