Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-10-29 CVE-2024-10228 Incorrect Permission Assignment for Critical Resource vulnerability in Hashicorp Vagrant VMWare Utility
The Vagrant VMWare Utility Windows installer targeted a custom location with a non-protected path that could be modified by an unprivileged user, introducing potential for unauthorized file system writes.
local
low complexity
hashicorp CWE-732
3.3
2024-10-29 CVE-2024-10487 Out-of-bounds Write vulnerability in Google Chrome
Out of bounds write in Dawn in Google Chrome prior to 130.0.6723.92 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page.
network
low complexity
google CWE-787
8.8
2024-10-29 CVE-2024-10488 Use After Free vulnerability in Google Chrome
Use after free in WebRTC in Google Chrome prior to 130.0.6723.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
network
low complexity
google CWE-416
8.8
2024-10-29 CVE-2024-50428 Missing Authorization vulnerability in Mondula Multi Step Form
Missing Authorization vulnerability in Mondula GmbH Multi Step Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Multi Step Form: from n/a through 1.7.21.
network
low complexity
mondula CWE-862
critical
9.8
2024-10-29 CVE-2024-7991 Out-of-bounds Write vulnerability in Autodesk products
A maliciously crafted DWG file, when parsed through Autodesk AutoCAD and certain AutoCAD-based products, may force an Out-of-Bounds Write vulnerability.
local
low complexity
autodesk CWE-787
7.8
2024-10-29 CVE-2024-7992 Out-of-bounds Write vulnerability in Autodesk products
A maliciously crafted DWG file, when parsed through Autodesk AutoCAD and certain AutoCAD-based products, can force a Stack-based Buffer Overflow.
local
low complexity
autodesk CWE-787
7.8
2024-10-29 CVE-2024-8588 Out-of-bounds Read vulnerability in Autodesk products
A maliciously crafted SLDPRT file when parsed in odxsw_dll.dll through Autodesk AutoCAD can force a Out-of-Bounds Read vulnerability.
local
low complexity
autodesk CWE-125
7.8
2024-10-29 CVE-2024-8589 Out-of-bounds Read vulnerability in Autodesk products
A maliciously crafted SLDPRT file when parsed in odxsw_dll.dll through Autodesk AutoCAD can force a Out-of-Bounds Read vulnerability.
local
low complexity
autodesk CWE-125
7.8
2024-10-29 CVE-2024-8590 Use After Free vulnerability in Autodesk products
A maliciously crafted 3DM file when parsed in atf_api.dll through Autodesk AutoCAD can force a Use-After-Free vulnerability.
local
low complexity
autodesk CWE-416
7.8
2024-10-29 CVE-2024-8591 Out-of-bounds Write vulnerability in Autodesk products
A maliciously crafted 3DM file when parsed in AcTranslators.exe through Autodesk AutoCAD can force a Heap-Based Buffer Overflow vulnerability.
local
low complexity
autodesk CWE-787
7.8