This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autodesk Navisworks Freedom. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-12198.
Monthly Archives: December 2024
ZDI-24-1710: Autodesk Navisworks Freedom DWFX File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Autodesk Navisworks Freedom. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-12200.
ZDI-24-1711: AnyDesk Link Following Information Disclosure Vulnerability
This vulnerability allows local attackers to disclose sensitive information on affected installations of AnyDesk. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.5. The following CVEs are assigned: CVE-2024-12754.
Stored XSS with Filter Bypass – blogenginev3.3.8
Posted by Andrey Stoykov on Dec 18
# Exploit Title: Stored XSS with Filter Bypass – blogenginev3.3.8
# Date: 12/2024
# Exploit Author: Andrey Stoykov
# Version: 3.3.8
# Tested on: Ubuntu 22.04
# Blog:
https://msecureltd.blogspot.com/2024/12/friday-fun-pentest-series-16-stored-xss.html
Stored XSS Filter Bypass #1:
Steps to Reproduce:
1. Login as admin and go to “Content” > “Posts”
2. On the right side of the page choose “Categories”
3. In…
[SYSS-2024-085]: Broadcom CA Client Automation – Improper Privilege Management (CWE-269)
Posted by Matthias Deeg via Fulldisclosure on Dec 18
Advisory ID: SYSS-2024-085
Product: CA Client Automation (CA DSM)
Manufacturer: Broadcom
Affected Version(s): 14.5.0.15
Tested Version(s): 14.5.0.15
Vulnerability Type: Improper Privilege Management (CWE-269)
Risk Level: High
Solution Status: Fixed
Manufacturer Notification: 2024-10-18
Solution Date: 2024-12-17
Public Disclosure:…
webkitgtk-2.46.5-1.fc40
FEDORA-2024-03a1955920
Packages in this update:
webkitgtk-2.46.5-1.fc40
Update description:
Update to 2.46.5:
Fix several crashes and rendering issues.
CVE-2024-54479, CVE-2024-54502, CVE-2024-54508, CVE-2024-54505
webkitgtk-2.46.5-1.fc41
FEDORA-2024-32bc143584
Packages in this update:
webkitgtk-2.46.5-1.fc41
Update description:
Update to 2.46.5:
Fix several crashes and rendering issues.
CVE-2024-54479, CVE-2024-54502, CVE-2024-54508, CVE-2024-54505
incus-6.8-1.fc41
FEDORA-2024-0912cd3ad9
Packages in this update:
incus-6.8-1.fc41
Update description:
Update to 6.8 to get various features and fixes
USN-7177-1: YARA vulnerability
It was discovered that YARA did not properly sanitize its
configuration settings. An attacker could potentially exploit this issue to
cause a denial of service.
USN-7169-2: Linux kernel (GCP) vulnerabilities
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
– Ext4 file system;
– Network traffic control;
– VMware vSockets driver;
(CVE-2024-49967, CVE-2024-53057, CVE-2024-50264)