Total
396138 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2024-38441 | 1 Netatalk | 1 Netatalk | 2026-06-17 | N/A | 9.8 CRITICAL |
| Netatalk before 3.2.1 has an off-by-one error and resultant heap-based buffer overflow because of setting ibuf[len] to '\0' in FPMapName in afp_mapname in etc/afpd/directory.c. 2.4.1 and 3.1.19 are also fixed versions. | |||||
| CVE-2024-38440 | 1 Netatalk | 1 Netatalk | 2026-06-17 | N/A | 7.5 HIGH |
| Netatalk before 3.2.1 has an off-by-one error, and resultant heap-based buffer overflow and segmentation violation, because of incorrectly using FPLoginExt in BN_bin2bn in etc/uams/uams_dhx_pam.c. The original issue 1097 report stated: 'The latest version of Netatalk (v3.2.0) contains a security vulnerability. This vulnerability arises due to a lack of validation for the length field after parsing user-provided data, leading to an out-of-bounds heap write of one byte (\0). Under specific configurations, this can result in reading metadata of the next heap block, potentially causing a Denial of Service (DoS) under certain heap layouts or with ASAN enabled. ... The vulnerability is located in the FPLoginExt operation of Netatalk, in the BN_bin2bn function found in /etc/uams/uams_dhx_pam.c ... if (!(bn = BN_bin2bn((unsigned char *)ibuf, KEYSIZE, NULL))) ... threads ... [#0] Id 1, Name: "afpd", stopped 0x7ffff4304e58 in ?? (), reason: SIGSEGV ... [#0] 0x7ffff4304e58 mov BYTE PTR [r14+0x8], 0x0 ... mov rdx, QWORD PTR [rsp+0x18] ... afp_login_ext(obj=<optimized out>, ibuf=0x62d000010424 "", ibuflen=0xffffffffffff0015, rbuf=<optimized out>, rbuflen=<optimized out>) ... afp_over_dsi(obj=0x5555556154c0 <obj>).' 2.4.1 and 3.1.19 are also fixed versions. | |||||
| CVE-2024-38439 | 1 Netatalk | 1 Netatalk | 2026-06-17 | N/A | 9.8 CRITICAL |
| Netatalk before 3.2.1 has an off-by-one error and resultant heap-based buffer overflow because of setting ibuf[PASSWDLEN] to '\0' in FPLoginExt in login in etc/uams/uams_pam.c. 2.4.1 and 3.1.19 are also fixed versions. | |||||
| CVE-2024-38438 | 1 Dlink | 2 Dsl-225, Dsl-225 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| D-Link - CWE-294: Authentication Bypass by Capture-replay | |||||
| CVE-2024-38437 | 1 Dlink | 2 Dsl-225, Dsl-225 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| D-Link - CWE-288:Authentication Bypass Using an Alternate Path or Channel | |||||
| CVE-2024-38436 | 1 Commugen | 1 Sox 365 | 2026-06-17 | N/A | 6.1 MEDIUM |
| Commugen SOX 365 – CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |||||
| CVE-2024-38435 | 1 Unitronics | 1 Visilogic | 2026-06-17 | N/A | 6.5 MEDIUM |
| Unitronics Vision PLC – CWE-703: Improper Check or Handling of Exceptional Conditions may allow denial of service | |||||
| CVE-2024-38434 | 2026-06-17 | N/A | 6.5 MEDIUM | ||
| Unitronics Vision PLC – CWE-676: Use of Potentially Dangerous Function may allow security feature bypass | |||||
| CVE-2024-38433 | 1 Nuvoton | 8 Npcm705r, Npcm705r Firmware, Npcm710r and 5 more | 2026-06-17 | N/A | 6.7 MEDIUM |
| Nuvoton - CWE-305: Authentication Bypass by Primary Weakness An attacker with write access to the SPI-Flash on an NPCM7xx BMC subsystem that uses the Nuvoton BootBlock reference code can modify the u-boot image header on flash parsed by the BootBlock which could lead to arbitrary code execution. | |||||
| CVE-2024-38432 | 1 Matrix-globalservices | 1 Tafnit | 2026-06-17 | N/A | 5.5 MEDIUM |
| Matrix Tafnit v8 - CWE-646: Reliance on File Name or Extension of Externally-Supplied File | |||||
| CVE-2024-38431 | 1 Matrix-globalservices | 1 Tafnit | 2026-06-17 | N/A | 5.3 MEDIUM |
| Matrix Tafnit v8 - CWE-204: Observable Response Discrepancy | |||||
| CVE-2024-38430 | 1 Matrix-globalservices | 1 Tafnit | 2026-06-17 | N/A | 5.4 MEDIUM |
| Matrix - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |||||
| CVE-2024-38429 | 1 Matrix-globalservices | 1 Tafnit | 2026-06-17 | N/A | 7.5 HIGH |
| Matrix Tafnit v8 - CWE-552: Files or Directories Accessible to External Parties | |||||
| CVE-2024-38428 | 1 Gnu | 1 Wget | 2026-06-17 | N/A | 9.1 CRITICAL |
| url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent. | |||||
| CVE-2024-38427 | 2026-06-17 | N/A | 8.8 HIGH | ||
| In International Color Consortium DemoIccMAX before 85ce74e, a logic flaw in CIccTagXmlProfileSequenceId::ParseXml in IccXML/IccLibXML/IccTagXml.cpp results in unconditionally returning false. | |||||
| CVE-2024-38426 | 1 Qualcomm | 328 205, 205 Firmware, 215 and 325 more | 2026-06-17 | N/A | 5.4 MEDIUM |
| While processing the authentication message in UE, improper authentication may lead to information disclosure. | |||||
| CVE-2024-38425 | 1 Qualcomm | 48 Fastconnect 6900, Fastconnect 6900 Firmware, Fastconnect 7800 and 45 more | 2026-06-17 | N/A | 6.1 MEDIUM |
| Information disclosure while sending implicit broadcast containing APP launch information. | |||||
| CVE-2024-38424 | 1 Qualcomm | 238 Ar8035, Ar8035 Firmware, Fastconnect 6200 and 235 more | 2026-06-17 | N/A | 7.8 HIGH |
| Memory corruption during GNSS HAL process initialization. | |||||
| CVE-2024-38423 | 1 Qualcomm | 412 205 Mobile Platform, 205 Mobile Platform Firmware, 215 Mobile Platform and 409 more | 2026-06-17 | N/A | 7.8 HIGH |
| Memory corruption while processing GPU page table switch. | |||||
| CVE-2024-38422 | 1 Qualcomm | 536 205 Mobile Platform, 205 Mobile Platform Firmware, 215 Mobile Platform and 533 more | 2026-06-17 | N/A | 7.8 HIGH |
| Memory corruption while processing voice packet with arbitrary data received from ADSP. | |||||
