Page 67 of 12682 results (0.061 seconds)

CVSS: 3.1EPSS: 0%CPEs: 4EXPL: 0

08 Oct 2024 — TYPO3 is a free and open source Content Management Framework. Backend users could see items in the backend page tree without having access if the mounts pointed to pages restricted for their user/group, or if no mounts were configured but the pages allowed access to "everybody." However, affected users could not manipulate these pages. Users are advised to update to TYPO3 versions 10.4.46 ELTS, 11.5.40 LTS, 12.4.21 LTS, 13.3.1 that fix the problem described. There are no known workarounds for this vulnerabi... • https://github.com/TYPO3/typo3/security/advisories/GHSA-rf5m-h8q9-9w6q • CWE-863: Incorrect Authorization •

CVSS: 6.5EPSS: 0%CPEs: 25EXPL: 0

08 Oct 2024 — Windows Kerberos Information Disclosure Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43547 • CWE-325: Missing Cryptographic Step •

CVSS: 5.6EPSS: 0%CPEs: 9EXPL: 0

08 Oct 2024 — Windows Cryptographic Information Disclosure Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43546 • CWE-203: Observable Discrepancy •

CVSS: 5.5EPSS: 0%CPEs: 5EXPL: 0

08 Oct 2024 — Windows Resilient File System (ReFS) Information Disclosure Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43500 • CWE-126: Buffer Over-read •

CVSS: 5.5EPSS: 0%CPEs: 16EXPL: 0

08 Oct 2024 — Windows Kernel-Mode Driver Information Disclosure Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43554 • CWE-212: Improper Removal of Sensitive Information Before Storage or Transfer •

CVSS: 7.8EPSS: 0%CPEs: 25EXPL: 0

08 Oct 2024 — Windows Graphics Component Information Disclosure Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43534 • CWE-125: Out-of-bounds Read •

CVSS: 5.5EPSS: 0%CPEs: 5EXPL: 0

08 Oct 2024 — Windows Graphics Component Information Disclosure Vulnerability • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-43508 • CWE-125: Out-of-bounds Read •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

08 Oct 2024 — In JetBrains TeamCity before 2024.07.3 path traversal leading to information disclosure was possible via server backups • https://www.jetbrains.com/privacy-security/issues-fixed • CWE-23: Relative Path Traversal •

CVSS: 5.5EPSS: 0%CPEs: 2EXPL: 0

08 Oct 2024 — in OpenHarmony v4.1.0 and prior versions allow a local attacker cause information leak through out-of-bounds Read. • https://gitee.com/openharmony/security/blob/master/zh/security-disclosure/2024/2024-10.md • CWE-125: Out-of-bounds Read •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

08 Oct 2024 — Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information This vulnerability allows remote attackers to disclose sensitive information on affected installations of Ivanti Avalanche. ... An attacker can leverage this vulnerability to disclose information in the context of SYSTEM. • https://forums.ivanti.com/s/article/Ivanti-Avalanche-6-4-5-Security-Advisory • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •