CVE-2023-24021 : MODSECURITY UP TO 2.9.6 WEB APPLICATION FIREWALL ACCESS CONTROL

Description

In ModSecurity before 2.9.7, FILES_TMP_CONTENT sometimes lacked the complete content. This can lead to a Web Application Firewall bypass.

References

https://github.com/SpiderLabs/ModSecurity/pull/2857

https://github.com/SpiderLabs/ModSecurity/pull/2857/commits/4324f0ac59f8225aa44bc5034df60dbeccd1d334

https://github.com/SpiderLabs/ModSecurity/releases/tag/v2.9.7

For More Information

MITRE

Common Vulnerabilityies and Exposures

Contact us to get started

CVE-2023-52479 : LINUX KERNEL UP TO 5.15.134/6.1.56/6.5.6 KSMBD SMB20_OPLOCK_BREAK_ACK USE AFTER FREE

CVE-2023-52479 : LINUX KERNEL UP TO 5.15.134/6.1.56/6.5.6 KSMBD SMB20_OPLOCK_BREAK_ACK USE AFTER FREE

Description In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix uaf in smb20_oplock_break_ack drop reference after use

CVE-2024-22459 : DELL ECS UP TO 3.6.2.5/3.7.0.6/3.8.0.4 ACCESS CONTROL

CVE-2024-22459 : DELL ECS UP TO 3.6.2.5/3.7.0.6/3.8.0.4 ACCESS CONTROL

Description Dell ECS, versions 3.6 through 3.6.2.5, and 3.7 through 3.7.0.6, and 3.8 through 3.8.0.4 versions, contain an improper access

CVE-2024-25751 : TENDA AC9 15.03.06.42_MULTI FROMSETSYSTIME STACK-BASED OVERFLOW

CVE-2024-25751 : TENDA AC9 15.03.06.42_MULTI FROMSETSYSTIME STACK-BASED OVERFLOW

Description A Stack Based Buffer Overflow vulnerability in Tenda AC9 v.3.0 with firmware version v.15.03.06.42_multi allows a remote attacker to