Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-10-03 CVE-2024-41591 Cross-site Scripting vulnerability in Draytek products
DrayTek Vigor3910 devices through 4.3.2.6 allow unauthenticated DOM-based reflected XSS.
network
low complexity
draytek CWE-79
6.1
2024-10-03 CVE-2024-41593 Out-of-bounds Write vulnerability in Draytek products
DrayTek Vigor310 devices through 4.3.2.6 allow a remote attacker to execute arbitrary code via the function ft_payload_dns(), because a byte sign-extension operation occurs for the length argument of a _memcpy call, leading to a heap-based Buffer Overflow.
network
low complexity
draytek CWE-787
critical
9.8
2024-10-03 CVE-2024-41594 Inadequate Encryption Strength vulnerability in Draytek products
An issue in DrayTek Vigor310 devices through 4.3.2.6 allows an attacker to obtain sensitive information because the httpd server of the Vigor management UI uses a static string for seeding the PRNG of OpenSSL.
network
low complexity
draytek CWE-326
7.5
2024-10-03 CVE-2023-37822 Insufficient Entropy vulnerability in Eufy Homebase 2 Firmware
The Eufy Homebase 2 before firmware version 3.3.4.1h creates a dedicated wireless network for its ecosystem, which serves as a proxy to the end user's primary network.
low complexity
eufy CWE-331
8.2
2024-10-03 CVE-2024-7824 Type Confusion vulnerability in Webroot Secureanywhere web Shield
Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Webroot SecureAnywhere - Web Shield on Windows, ARM, 64 bit, 32 bit (wrUrl.Dll modules) allows Functionality Misuse.This issue affects SecureAnywhere - Web Shield: before 2.1.2.3.
network
low complexity
webroot CWE-843
critical
9.8
2024-10-03 CVE-2024-7825 Type Confusion vulnerability in Webroot Secureanywhere web Shield
Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Webroot SecureAnywhere - Web Shield on Windows, ARM, 64 bit, 32 bit (wrUrl.Dll modules) allows Functionality Misuse.This issue affects SecureAnywhere - Web Shield: before 2.1.2.3.
network
low complexity
webroot CWE-843
critical
9.8
2024-10-03 CVE-2024-7826 Improper Check for Unusual or Exceptional Conditions vulnerability in Webroot Secureanywhere web Shield
Improper Check for Unusual or Exceptional Conditions vulnerability in Webroot SecureAnywhere - Web Shield on Windows, ARM, 64 bit, 32 bit (wrURL.Dll modules) allows Functionality Misuse.This issue affects SecureAnywhere - Web Shield: before 2.1.2.3.
network
low complexity
webroot CWE-754
critical
9.8
2024-10-03 CVE-2024-8508 Improper Validation of Specified Quantity in Input vulnerability in multiple products
NLnet Labs Unbound up to and including version 1.21.0 contains a vulnerability when handling replies with very large RRsets that it needs to perform name compression for.
network
low complexity
nlnetlabs debian CWE-1284
5.3
2024-10-03 CVE-2024-36474 Integer Overflow or Wraparound vulnerability in Gnome Libgsf 1.14.52
An integer overflow vulnerability exists in the Compound Document Binary File format parser of the GNOME Project G Structured File Library (libgsf) version v1.14.52.
local
low complexity
gnome CWE-190
7.8
2024-10-03 CVE-2024-42415 Unspecified vulnerability in Gnome Libgsf 1.14.52
An integer overflow vulnerability exists in the Compound Document Binary File format parser of v1.14.52 of the GNOME Project G Structured File Library (libgsf).
local
low complexity
gnome
7.8