NVD disclosure day

Published threat advisories for December 27, 2024

CVE advisoryCRITICAL

CVE-2024-56732

HarfBuzz Heap Overflow Vulnerability in Text Shaping Engine

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical heap-based buffer overflow vulnerability exists in the HarfBuzz text shaping engine. This issue, present in versions 8.5.0 through 10.0.1, could be triggered by processing specially crafted font data. While specific impacts are not detailed, such vulnerabilities can lead to application instability or unautho

CVE advisoryKnown Exploit

CVE-2024-12987

DrayTek Routers Command Injection Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A command injection vulnerability exists in the web management interface of certain DrayTek routers, allowing remote attackers to execute OS commands. This poses a risk of unauthorized system control and data compromise. Prompt patching is recommended.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2024-53197

Linux Kernel: USB Audio Driver Out-of-Bounds Access Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

The Linux kernel's USB audio driver has an out-of-bounds access vulnerability. An attacker with physical access could connect a malicious USB device to manipulate system memory. This impacts organizations using specific Linux kernel versions, posing a risk of data corruption or unauthorized code execution.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2024-3393

Palo Alto Networks PAN-OS Denial of Service Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

A Denial of Service vulnerability in Palo Alto Networks' PAN-OS software affects its DNS Security feature. An unauthenticated attacker can exploit this by sending a malicious packet, causing the firewall to reboot. Repeated exploitation can lead to the firewall entering maintenance mode, disrupting network availability

• CISA KEV