Lucene search

K

Pandora Media, Inc. Security Vulnerabilities

packetstorm

7.4AI Score

2024-06-03 12:00 AM
67
cvelist

7.8CVSS

8.4AI Score

0.068EPSS

2021-10-13 12:27 AM
1
vulnrichment

7.8CVSS

6.8AI Score

0.068EPSS

2021-10-13 12:27 AM
1
osv
osv

Moderate: gstreamer1-plugins-good security update

GStreamer is a streaming media framework based on graphs of filters which operate on media data. The gstreamer1-plugins-good packages contain a collection of well-supported plug-ins of good quality and under the LGPL license. Security Fix(es): gstreamer-plugins-good: integer overflow leading to...

7.6CVSS

6.7AI Score

0.0005EPSS

2024-06-14 01:59 PM
osv
osv

CVE-2023-36088

Server Side Request Forgery (SSRF) vulnerability in NebulaGraph Studio version 3.7.0, allows remote attackers to gain sensitive...

7.5CVSS

7.4AI Score

0.001EPSS

2023-09-01 04:15 PM
12
vulnrichment
vulnrichment

CVE-2024-30278 Adobe Media Encoder 2024 TGA File parsing memory corruption

Media Encoder versions 23.6.5, 24.3 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in...

5.5CVSS

6AI Score

0.001EPSS

2024-06-13 09:34 AM
2
zdt

7.4AI Score

2024-06-04 12:00 AM
67
cvelist
cvelist

CVE-2024-30278 Adobe Media Encoder 2024 TGA File parsing memory corruption

Media Encoder versions 23.6.5, 24.3 and earlier Answer: are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in...

5.5CVSS

0.001EPSS

2024-06-13 09:34 AM
4
exploitdb

7.4AI Score

2024-06-03 12:00 AM
33
cvelist

8.6AI Score

0.002EPSS

2020-08-17 07:13 PM
cvelist

7CVSS

8.1AI Score

0.001EPSS

2020-08-17 07:13 PM
cvelist
cvelist

CVE-2024-38547 media: atomisp: ssh_css: Fix a null-pointer dereference in load_video_binaries

In the Linux kernel, the following vulnerability has been resolved: media: atomisp: ssh_css: Fix a null-pointer dereference in load_video_binaries The allocation failure of mycs->yuv_scaler_binary in load_video_binaries() is followed with a dereference of mycs->yuv_scaler_binary after the...

0.0004EPSS

2024-06-19 01:35 PM
cvelist

8.6AI Score

0.012EPSS

2020-08-17 07:13 PM
cvelist

7.8CVSS

8.6AI Score

0.001EPSS

2020-08-17 07:13 PM
cvelist

7.8CVSS

8.6AI Score

0.001EPSS

2020-08-17 07:13 PM
cvelist

7.8CVSS

8.7AI Score

0.001EPSS

2020-08-17 07:13 PM
debiancve
debiancve

CVE-2024-39465

In the Linux kernel, the following vulnerability has been resolved: media: mgb4: Fix double debugfs remove Fixes an error where debugfs_remove_recursive() is called first on a parent directory and then again on a child which causes a kernel panic. [hverkuil: added Fixes/Cc...

6.6AI Score

0.0004EPSS

2024-06-25 03:15 PM
2
vulnrichment
vulnrichment

CVE-2024-35919 media: mediatek: vcodec: adding lock to protect encoder context list

In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: adding lock to protect encoder context list Add a lock for the ctx_list, to avoid accessing a NULL pointer within the 'vpu_enc_ipi_handler' function when the ctx_list has been deleted due to an unexpected.....

7.2AI Score

0.0004EPSS

2024-05-19 10:10 AM
cvelist
cvelist

CVE-2024-36976 Revert "media: v4l2-ctrls: show all owned controls in log_status"

In the Linux kernel, the following vulnerability has been resolved: Revert "media: v4l2-ctrls: show all owned controls in log_status" This reverts commit 9801b5b28c6929139d6fceeee8d739cc67bb2739. This patch introduced a potential deadlock scenario: [Wed May 8 10:02:06 2024] Possible unsafe...

0.0004EPSS

2024-06-18 07:23 PM
3
cvelist

5.5CVSS

7.3AI Score

0.001EPSS

2020-08-17 07:13 PM
1
cvelist
cvelist

CVE-2024-35919 media: mediatek: vcodec: adding lock to protect encoder context list

In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: adding lock to protect encoder context list Add a lock for the ctx_list, to avoid accessing a NULL pointer within the 'vpu_enc_ipi_handler' function when the ctx_list has been deleted due to an unexpected.....

6.4AI Score

0.0004EPSS

2024-05-19 10:10 AM
3
nessus
nessus

Adobe Media Encoder < 23.6.5 / 24.0.0 < 24.3.0 Arbitrary code execution (APSB24-23) (macOS)

The version of Adobe Media Encoder installed on the remote macOS host is prior to 23.6.5, 24.3.0. It is, therefore, affected by a vulnerability as referenced in the APSB24-23 advisory. Media Encoder versions 24.2.1, 23.6.4 and earlier are affected by a Stack-based Buffer Overflow ...

7.8CVSS

7.8AI Score

0.001EPSS

2024-04-09 12:00 AM
5
vulnrichment
vulnrichment

CVE-2023-52844 media: vidtv: psi: Add check for kstrdup

In the Linux kernel, the following vulnerability has been resolved: media: vidtv: psi: Add check for kstrdup Add check for the return value of kstrdup() and return the error if it fails in order to avoid NULL pointer...

6.9AI Score

0.0004EPSS

2024-05-21 03:31 PM
1
packetstorm

7.4AI Score

2024-06-03 12:00 AM
55
githubexploit
githubexploit

Exploit for Out-of-bounds Write in Microsoft

CVE-2022-37969 Windows Local Privilege Escalation PoC...

7.8CVSS

8.7AI Score

0.002EPSS

2023-03-09 09:17 PM
463
vulnrichment
vulnrichment

CVE-2023-52589 media: rkisp1: Fix IRQ disable race issue

In the Linux kernel, the following vulnerability has been resolved: media: rkisp1: Fix IRQ disable race issue In rkisp1_isp_stop() and rkisp1_csi_disable() the driver masks the interrupts and then apparently assumes that the interrupt handler won't be running, and proceeds in the stop procedure....

6.8AI Score

0.0004EPSS

2024-03-06 06:45 AM
1
vulnrichment
vulnrichment

CVE-2023-52459 media: v4l: async: Fix duplicated list deletion

In the Linux kernel, the following vulnerability has been resolved: media: v4l: async: Fix duplicated list deletion The list deletion call dropped here is already called from the helper function in the line before. Having a second list_del() call results in either a warning (with...

6.7AI Score

0.0004EPSS

2024-02-23 02:46 PM
2
cvelist
cvelist

CVE-2023-52459 media: v4l: async: Fix duplicated list deletion

In the Linux kernel, the following vulnerability has been resolved: media: v4l: async: Fix duplicated list deletion The list deletion call dropped here is already called from the helper function in the line before. Having a second list_del() call results in either a warning (with...

5.5AI Score

0.0004EPSS

2024-02-23 02:46 PM
2
cvelist
cvelist

CVE-2024-5021 WordPress Picture / Portfolio / Media Gallery <= 3.0.1 - Unauthenticated Server-Side Request Forgery

The WordPress Picture / Portfolio / Media Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.0.1 via the 'file_get_contents' function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations...

9.3CVSS

0.001EPSS

2024-06-19 03:12 AM
3
cvelist
cvelist

CVE-2024-35920 media: mediatek: vcodec: adding lock to protect decoder context list

In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: adding lock to protect decoder context list Add a lock for the ctx_list, to avoid accessing a NULL pointer within the 'vpu_dec_ipi_handler' function when the ctx_list has been deleted due to an unexpected.....

6.4AI Score

0.0004EPSS

2024-05-19 10:10 AM
1
cvelist
cvelist

CVE-2023-52565 media: uvcvideo: Fix OOB read

In the Linux kernel, the following vulnerability has been resolved: media: uvcvideo: Fix OOB read If the index provided by the user is bigger than the mask size, we might do an out of bound...

7.7AI Score

0.0004EPSS

2024-03-02 09:59 PM
vulnrichment
vulnrichment

CVE-2024-35920 media: mediatek: vcodec: adding lock to protect decoder context list

In the Linux kernel, the following vulnerability has been resolved: media: mediatek: vcodec: adding lock to protect decoder context list Add a lock for the ctx_list, to avoid accessing a NULL pointer within the 'vpu_dec_ipi_handler' function when the ctx_list has been deleted due to an unexpected.....

6.8AI Score

0.0004EPSS

2024-05-19 10:10 AM
1
vulnrichment
vulnrichment

CVE-2024-5021 WordPress Picture / Portfolio / Media Gallery <= 3.0.1 - Unauthenticated Server-Side Request Forgery

The WordPress Picture / Portfolio / Media Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 3.0.1 via the 'file_get_contents' function. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations...

9.3CVSS

7AI Score

0.001EPSS

2024-06-19 03:12 AM
2
nuclei
nuclei

School Dormitory Management System 1.0 - Authenticated Cross-Site Scripting

School Dormitory Management System 1.0 contains an authenticated cross-site scripting vulnerability in admin/inc/navigation.php:126. An attacker can inject arbitrary script in the browser of an unsuspecting user in the context of the affected site. This can allow the attacker to steal cookie-based....

6.1CVSS

6.1AI Score

0.001EPSS

2022-10-05 08:01 PM
6
cvelist
cvelist

CVE-2023-52844 media: vidtv: psi: Add check for kstrdup

In the Linux kernel, the following vulnerability has been resolved: media: vidtv: psi: Add check for kstrdup Add check for the return value of kstrdup() and return the error if it fails in order to avoid NULL pointer...

6.5AI Score

0.0004EPSS

2024-05-21 03:31 PM
cvelist
cvelist

CVE-2023-52589 media: rkisp1: Fix IRQ disable race issue

In the Linux kernel, the following vulnerability has been resolved: media: rkisp1: Fix IRQ disable race issue In rkisp1_isp_stop() and rkisp1_csi_disable() the driver masks the interrupts and then apparently assumes that the interrupt handler won't be running, and proceeds in the stop procedure....

7.6AI Score

0.0004EPSS

2024-03-06 06:45 AM
cvelist
cvelist

CVE-2024-2328

The Real Media Library: Media Library Folder & File Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the image title and alt text in all versions up to, and including, 4.22.11 due to insufficient input sanitization and output escaping. This makes it possible for...

6.4CVSS

5.8AI Score

0.001EPSS

2024-05-02 04:52 PM
osv
osv

CVE-2023-36460

Mastodon is a free, open-source social network server based on ActivityPub. Starting in version 3.5.0 and prior to versions 3.5.9, 4.0.5, and 4.1.3, attackers using carefully crafted media files can cause Mastodon's media processing code to create arbitrary files at any location. This allows...

9.9CVSS

7.8AI Score

0.004EPSS

2023-07-06 07:15 PM
3
githubexploit
githubexploit

Exploit for CVE-2022-30136

CVE-2022-30136 Windows Network File System Remote exploit PoC...

9.8CVSS

6.9AI Score

0.849EPSS

2023-03-15 10:59 AM
19
mscve
mscve

Chromium: CVE-2024-5496 Use after free in Media Session

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more...

6.1AI Score

0.0004EPSS

2024-06-03 06:30 PM
5
wpvulndb
wpvulndb

WP Media folder < 5.7.3 - Missing Authorization to Authenticated(Subscriber+) Title Modification

Description The wp-media-folder plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on an unknown function in all versions up to, and including, 5.7.2. This makes it possible for authenticated attackers, with subscriber access and above, to...

6.5AI Score

0.0004EPSS

2024-05-07 12:00 AM
8
cvelist
cvelist

CVE-2024-5605 Media Library Assistant <= 3.16 - Authenticated (Contributor+) SQL Injection via order Parameter

The Media Library Assistant plugin for WordPress is vulnerable to time-based SQL Injection via the ‘order’ parameter within the mla_tag_cloud Shortcode in all versions up to, and including, 3.16 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the...

8.8CVSS

0.001EPSS

2024-06-20 03:37 AM
6
cvelist
cvelist

CVE-2024-35717 WordPress Media Slider plugin <= 1.3.9 - Broken Access Control vulnerability

Missing Authorization vulnerability in A WP Life Media Slider – Photo Sleder, Video Slider, Link Slider, Carousal Slideshow.This issue affects Media Slider – Photo Sleder, Video Slider, Link Slider, Carousal Slideshow: from n/a through...

4.3CVSS

0.0004EPSS

2024-06-10 08:00 AM
4
osv
osv

Moderate: gstreamer1-plugins-bad-free security update

GStreamer is a streaming media framework based on graphs of filters which operate on media data. The gstreamer1-plugins-bad-free package contains a collection of plug-ins for GStreamer. Security Fix(es): gstreamer-plugins-bad: Integer overflow leading to heap overwrite in MXF file handling with...

8.8CVSS

6.9AI Score

0.0005EPSS

2024-06-14 01:59 PM
vulnrichment
vulnrichment

CVE-2024-20772 Adobe Media Encoder 2024 AI file parsing Stack based buffer overflow

Media Encoder versions 24.2.1, 23.6.4 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious...

7.8CVSS

7.2AI Score

0.001EPSS

2024-04-10 01:02 PM
1
cvelist
cvelist

CVE-2024-38611 media: i2c: et8ek8: Don't strip remove function when driver is builtin

In the Linux kernel, the following vulnerability has been resolved: media: i2c: et8ek8: Don't strip remove function when driver is builtin Using __exit for the remove function results in the remove callback being discarded with CONFIG_VIDEO_ET8EK8=y. When such a device gets unbound (e.g. using...

0.0004EPSS

2024-06-19 01:56 PM
1
cvelist
cvelist

CVE-2024-20772 Adobe Media Encoder 2024 AI file parsing Stack based buffer overflow

Media Encoder versions 24.2.1, 23.6.4 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious...

7.8CVSS

8AI Score

0.001EPSS

2024-04-10 01:02 PM
githubexploit
githubexploit

Exploit for Improper Privilege Management in Minio

MinIO FIPS Builds MinIO creates FIPS builds using a patched...

9AI Score

2023-03-27 08:53 AM
573
veeam
veeam

Bare Metal Recovery Fails With "The requested security package does not exist."

This issue is caused by the WinRE.wim packaged in some early distributions of Server 2022. New Recovery Media must be created using Server 2019 or a newer version of Server...

7.1AI Score

2023-10-31 12:00 AM
20
nessus
nessus

Intel Media SDK Multiple Vulnerabilities (INTEL-SA-00935)

The version of Intel Media SDK installed on the remote host is affected by multiple vulnerabilities: Improper input validation in Intel Media SDK software all versions may allow an authenticated user to potentially enable denial of service via local access. (CVE-2023-48368) Improper buffer...

5.9CVSS

4.9AI Score

0.0004EPSS

2024-05-24 12:00 AM
7
Total number of security vulnerabilities327618