NVD disclosure day

Published threat advisories for October 7, 2024

CVE advisoryCRITICAL

CVE-2024-45874

VegaBird Vooki DLL Hijacking Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A DLL hijacking vulnerability in VegaBird Vooki allows attackers to execute arbitrary code or maintain persistence by placing a crafted DLL file in the application's directory. This could result in unauthorized code execution if the vulnerability is reachable. The relevance of this issue depends on whether this softwar

CVE advisoryCRITICAL

CVE-2024-45873

VegaBird Yaazhini DLL Hijacking Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A DLL hijacking vulnerability in VegaBird Yaazhini allows attackers to execute arbitrary code by placing a crafted DLL file in the same directory as the application's executable. This requires local file system access to exploit, making it a client-side attack vector.

CVE advisoryCRITICAL

CVE-2024-46446

Mecha CMS Directory Traversal File Deletion and Takeover Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A directory traversal vulnerability in Mecha CMS allows attackers to bypass identity checks via crafted cookies and URIs, potentially leading to arbitrary file deletion or website takeover. This issue is critical due to its network accessibility, lack of authentication requirements, and potential for significant impact