CVE-2024-30090
Microsoft Streaming Service Elevation of Privilege Vulnerability
CVSS
7.0
Alto
EPSS
2.0%
p78
KEV
—
Exploit Today
23
0-100
Publicado: 11 jun 2024 · Última mod.: 20 jul 2026 · CWE-822 · CWE-119
2.0%EPSS · 30 días2.0%
2026-06-302026-07-20
Microsoft Streaming Service Elevation of Privilege Vulnerability
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-162488.8 ALT—
——0A vulnerability was found in Tenda AC10 16.03.10.09_multi_TDE01. This issue affects the function fromAdvSetLanip of the file /goform/AdvSetLanip of the component httpd/netctrl. The manipulation of the argument GetValue/SetValue results in stack-based buffer overflow. The attack may be performed from remote. The exploit has been made public and could be used.22hCVE-2026-162256.3 MED13.7%
——4A security flaw has been discovered in davenardella snap7 up to 1.4.3. The impacted element is the function TSnap7Peer::NegotiatePDULength of the file src/core/s7_peer.cpp. The manipulation of the argument PDULength results in out-of-bounds write. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.22hCVE-2026-160978.8 ALT37.3%
——11A vulnerability was found in Shibby Tomato 1.28. This vulnerability affects the function sub_42537C of the component Scheduler Name Handler. The manipulation of the argument a1 results in stack-based buffer overflow. It is possible to launch the attack remotely. This project is superseded by FreshTomato.19hCVE-2026-160968.8 ALT35.6%
——11A vulnerability has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. This affects the function sub_40BB50 of the file /proc/webmon_recent_domains. The manipulation leads to stack-based buffer overflow. It is possible to initiate the attack remotely. This project is superseded by FreshTomato.1dCVE-2026-160958.8 ALT34.1%
——10A flaw has been found in Shibby Tomato 1.28 RT-N5x MIPSR2 Build 124. Affected by this issue is the function setup_conntrack of the file /sbin/rc. Executing a manipulation of the argument ct_tcp_timeout can lead to out-of-bounds write. The attack may be performed from remote. This project is superseded by FreshTomato.22hCVE-2025-516787.5 ALT6.2%
——2An issue was discovered in RISC-V PicoRV32 commit 87c89a. A mismatch in the PCPI INSN and memory address can lead to unexpected behavior.18h