Vulnerabilities (CVE)

Total 396349 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-38440 1 Netatalk 1 Netatalk 2026-06-17 N/A 7.5 HIGH
Netatalk before 3.2.1 has an off-by-one error, and resultant heap-based buffer overflow and segmentation violation, because of incorrectly using FPLoginExt in BN_bin2bn in etc/uams/uams_dhx_pam.c. The original issue 1097 report stated: 'The latest version of Netatalk (v3.2.0) contains a security vulnerability. This vulnerability arises due to a lack of validation for the length field after parsing user-provided data, leading to an out-of-bounds heap write of one byte (\0). Under specific configurations, this can result in reading metadata of the next heap block, potentially causing a Denial of Service (DoS) under certain heap layouts or with ASAN enabled. ... The vulnerability is located in the FPLoginExt operation of Netatalk, in the BN_bin2bn function found in /etc/uams/uams_dhx_pam.c ... if (!(bn = BN_bin2bn((unsigned char *)ibuf, KEYSIZE, NULL))) ... threads ... [#0] Id 1, Name: "afpd", stopped 0x7ffff4304e58 in ?? (), reason: SIGSEGV ... [#0] 0x7ffff4304e58 mov BYTE PTR [r14+0x8], 0x0 ... mov rdx, QWORD PTR [rsp+0x18] ... afp_login_ext(obj=<optimized out>, ibuf=0x62d000010424 "", ibuflen=0xffffffffffff0015, rbuf=<optimized out>, rbuflen=<optimized out>) ... afp_over_dsi(obj=0x5555556154c0 <obj>).' 2.4.1 and 3.1.19 are also fixed versions.
CVE-2024-38439 1 Netatalk 1 Netatalk 2026-06-17 N/A 9.8 CRITICAL
Netatalk before 3.2.1 has an off-by-one error and resultant heap-based buffer overflow because of setting ibuf[PASSWDLEN] to '\0' in FPLoginExt in login in etc/uams/uams_pam.c. 2.4.1 and 3.1.19 are also fixed versions.
CVE-2024-38438 1 Dlink 2 Dsl-225, Dsl-225 Firmware 2026-06-17 N/A 9.8 CRITICAL
D-Link - CWE-294: Authentication Bypass by Capture-replay
CVE-2024-38437 1 Dlink 2 Dsl-225, Dsl-225 Firmware 2026-06-17 N/A 9.8 CRITICAL
D-Link - CWE-288:Authentication Bypass Using an Alternate Path or Channel
CVE-2024-38436 1 Commugen 1 Sox 365 2026-06-17 N/A 6.1 MEDIUM
Commugen SOX 365 – CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-38435 1 Unitronics 1 Visilogic 2026-06-17 N/A 6.5 MEDIUM
Unitronics Vision PLC – CWE-703: Improper Check or Handling of Exceptional Conditions may allow denial of service
CVE-2024-38434 2026-06-17 N/A 6.5 MEDIUM
Unitronics Vision PLC – CWE-676: Use of Potentially Dangerous Function may allow security feature bypass
CVE-2024-38433 1 Nuvoton 8 Npcm705r, Npcm705r Firmware, Npcm710r and 5 more 2026-06-17 N/A 6.7 MEDIUM
Nuvoton - CWE-305: Authentication Bypass by Primary Weakness An attacker with write access to the SPI-Flash on an NPCM7xx BMC subsystem that uses the Nuvoton BootBlock reference code can modify the u-boot image header on flash parsed by the BootBlock which could lead to arbitrary code execution.
CVE-2024-38432 1 Matrix-globalservices 1 Tafnit 2026-06-17 N/A 5.5 MEDIUM
Matrix Tafnit v8 - CWE-646: Reliance on File Name or Extension of Externally-Supplied File
CVE-2024-38431 1 Matrix-globalservices 1 Tafnit 2026-06-17 N/A 5.3 MEDIUM
Matrix Tafnit v8 - CWE-204: Observable Response Discrepancy
CVE-2024-38430 1 Matrix-globalservices 1 Tafnit 2026-06-17 N/A 5.4 MEDIUM
Matrix - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-38429 1 Matrix-globalservices 1 Tafnit 2026-06-17 N/A 7.5 HIGH
Matrix Tafnit v8 -  CWE-552: Files or Directories Accessible to External Parties
CVE-2024-38428 1 Gnu 1 Wget 2026-06-17 N/A 9.1 CRITICAL
url.c in GNU Wget through 1.24.5 mishandles semicolons in the userinfo subcomponent of a URI, and thus there may be insecure behavior in which data that was supposed to be in the userinfo subcomponent is misinterpreted to be part of the host subcomponent.
CVE-2024-38427 2026-06-17 N/A 8.8 HIGH
In International Color Consortium DemoIccMAX before 85ce74e, a logic flaw in CIccTagXmlProfileSequenceId::ParseXml in IccXML/IccLibXML/IccTagXml.cpp results in unconditionally returning false.
CVE-2024-38426 1 Qualcomm 328 205, 205 Firmware, 215 and 325 more 2026-06-17 N/A 5.4 MEDIUM
While processing the authentication message in UE, improper authentication may lead to information disclosure.
CVE-2024-38425 1 Qualcomm 48 Fastconnect 6900, Fastconnect 6900 Firmware, Fastconnect 7800 and 45 more 2026-06-17 N/A 6.1 MEDIUM
Information disclosure while sending implicit broadcast containing APP launch information.
CVE-2024-38424 1 Qualcomm 238 Ar8035, Ar8035 Firmware, Fastconnect 6200 and 235 more 2026-06-17 N/A 7.8 HIGH
Memory corruption during GNSS HAL process initialization.
CVE-2024-38423 1 Qualcomm 412 205 Mobile Platform, 205 Mobile Platform Firmware, 215 Mobile Platform and 409 more 2026-06-17 N/A 7.8 HIGH
Memory corruption while processing GPU page table switch.
CVE-2024-38422 1 Qualcomm 536 205 Mobile Platform, 205 Mobile Platform Firmware, 215 Mobile Platform and 533 more 2026-06-17 N/A 7.8 HIGH
Memory corruption while processing voice packet with arbitrary data received from ADSP.
CVE-2024-38421 1 Qualcomm 154 Fastconnect 6200, Fastconnect 6200 Firmware, Fastconnect 7800 and 151 more 2026-06-17 N/A 7.8 HIGH
Memory corruption while processing GPU commands.