CVE-2024-0145
published 2025-02-12CVE-2024-0145: NVIDIA nvJPEG2000 library contains a vulnerability where an attacker can cause a heap-based buffer overflow issue by means of a specially crafted JPEG2000…
PriorityP433medium6.8CVSS 3.1
AVNACHPRNUIRSUCNIHAH
EPSS
0.91%
55.6th percentile
NVIDIA nvJPEG2000 library contains a vulnerability where an attacker can cause a heap-based buffer overflow issue by means of a specially crafted JPEG2000 file. A successful exploit of this vulnerability might lead to code execution and data tampering.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nvidia | nvjpeg2000 | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Talos
ClearML and Nvidia vulns
blogs_talos·2025-02-14·CVSS 6.8
[MEDIUM] ClearML and Nvidia vulns
## ClearML and Nvidia vulns
Cisco Talos’ Vulnerability Discovery & Research team recently disclosed two vulnerabilities in ClearML and four vulnerabilities in Nvidia.
The vulnerabilities mentioned in this blog post have been patched by their respective vendors, all in adherence to Cisco’s third-party vulnerability disclosure policy .
For Snort coverage that can detect the exploitation of these vulnerabilities, download the latest rule sets from Snort.org , and our latest Vulnerability Advisories are always posted on Talos Intelligence’s website .
## ClearML XSS and information disclosure vulnerabilities
Discovered by Edwin Molenaar of Cisco Meraki.
ClearML contains two vulnerabilities. ClearML is an open-source AI platform that supports the entire AI development lifecycle from resear
Talos
ClearML and Nvidia vulns
blogs_talos·2025-02-14·CVSS 6.8
[MEDIUM] ClearML and Nvidia vulns
Cisco Talos’ Vulnerability Discovery & Research team recently disclosed two vulnerabilities in ClearML and four vulnerabilities in Nvidia.
The vulnerabilities mentioned in this blog post have been patched by their respective vendors, all in adherence to Cisco’s third-party vulnerability disclosure policy.
For Snort coverage that can detect the exploitation of these vulnerabilities, download the latest rule sets from Snort.org, and our latest Vulnerability Advisories are always posted on Talos Intelligence’s website.
## ClearML XSS and information disclosure vulnerabilities
Discovered by Edwin Molenaar of Cisco Meraki.
ClearML contains two vulnerabilities. ClearML is an open-source AI platform that supports the entire AI development lifecycle from research to production. It is designed
Bugzilla
CVE-2024-54502 webkit: Processing maliciously crafted web content may lead to an unexpected process crash
bugzilla·2024-12-23·CVSS 6.5
CVE-2024-54502 [MEDIUM] CVE-2024-54502 webkit: Processing maliciously crafted web content may lead to an unexpected process crash
CVE-2024-54502 webkit: Processing maliciously crafted web content may lead to an unexpected process crash
The issue was addressed with improved checks. This issue is fixed in watchOS 11.2, visionOS 2.2, tvOS 18.2, macOS Sequoia 15.2, Safari 18.2, iOS 18.2 and iPadOS 18.2. Processing maliciously crafted web content may lead to an unexpected process crash.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9
Via RHSA-2025:0146 https://access.redhat.com/errata/RHSA-2025:0146
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2025:0145 https://access.redhat.com/errata/RHSA-2025:0145
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 9.4 Extended Update Support
2025-02-12
Published