Vulnerabilities (CVE)

Filtered by CWE-404
Total 444 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-47972 2024-11-06 N/A 4.0 MEDIUM
Improper resource management in firmware of some Solidigm DC Products may allow an attacker to potentially control the performance of the resource.
CVE-2024-39721 2024-11-01 N/A 7.5 HIGH
An issue was discovered in Ollama before 0.1.34. The CreateModelHandler function uses os.Open to read a file until completion. The req.Path parameter is user-controlled and can be set to /dev/random, which is blocking, causing the goroutine to run infinitely (even after the HTTP request is aborted by the client).
CVE-2024-45182 2 Microsoft, Wibu 2 Windows, Wibukey 2024-10-29 N/A 5.5 MEDIUM
An issue was discovered in WibuKey64.sys in WIBU-SYSTEMS WibuKey before v6.70 and fixed in v.6.70 An improper bounds check allows specially crafted packets to cause an arbitrary address read, resulting in Denial of Service.
CVE-2024-7887 2024-08-19 3.3 LOW 2.7 LOW
A vulnerability was found in LimeSurvey 6.3.0-231016 and classified as problematic. Affected by this issue is some unknown functionality of the file /index.php of the component File Upload. The manipulation of the argument size leads to denial of service. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.