LiveActive security incident?Get immediate response
CVE archive

2024 CVE Archive

Browse CVE records published in 2024 CVE Archive, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 38424 matching CVEs · Page 6 of 769.

High · CVSS 7.3

CVE-2024-27619: Dlink Dir-3040us A1 1.20b03a hotfix is vulnerable to Buffer Overflow.

Dlink Dir-3040us A1 1.20b03a hotfix is vulnerable to Buffer Overflow. Any user having read/write access to ftp server can write directly to ram causing buffer overflow if file or files uploaded are greater than available ram. Ftp server allows change of directory to root which is one level up than root of usb flash directory. During upload ram is getting filled and causing system resource exhaustion (no free memory) which causes system to crash and reboot.

Published Mar 29, 2024 · Updated Jul 9, 2026

Critical · CVSS 9.8

CVE-2024-23086: Apfloat v1.10.1 was discovered to contain a stack overflow via the component org.apfloat.internal.DoubleMod...

Apfloat v1.10.1 was discovered to contain a stack overflow via the component org.apfloat.internal.DoubleModMath::modPow(double. NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The submission may have been based on a tool that is not sufficiently robust for vulnerability identification.

Published Apr 8, 2024 · Updated Jul 9, 2026

High · CVSS 7.5

CVE-2024-23085: Apfloat v1.10.1 was discovered to contain a NullPointerException via the component org.apfloat.internal.Dou...

Apfloat v1.10.1 was discovered to contain a NullPointerException via the component org.apfloat.internal.DoubleScramble::scramble(double[], int, int[]). NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The submission may have been based on a tool that is not sufficiently robust for vulnerability identification.

Published Apr 8, 2024 · Updated Jul 9, 2026

High · CVSS 7.5

CVE-2024-23084: Apfloat v1.10.1 was discovered to contain an ArrayIndexOutOfBoundsException via the component org.apfloat.i...

Apfloat v1.10.1 was discovered to contain an ArrayIndexOutOfBoundsException via the component org.apfloat.internal.DoubleCRTMath::add(double[], double[]). NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The submission may have been based on a tool that is not sufficiently robust for vulnerability identification.

Published Apr 8, 2024 · Updated Jul 9, 2026

Medium · CVSS 5.3

CVE-2024-23083: Time4J Base v5.9.3 was discovered to contain a NullPointerException via the component net.time4j.format.int...

Time4J Base v5.9.3 was discovered to contain a NullPointerException via the component net.time4j.format.internal.FormatUtils::useDefaultWeekmodel(Locale). NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The submission may have been based on a tool that is not sufficiently robust for vulnerability identification.

Published Apr 10, 2024 · Updated Jul 9, 2026

Unknown · CVSS Not scored

CVE-2024-23082: ThreeTen Backport v1.6.8 was discovered to contain an integer overflow via the component org.threeten.bp.fo...

ThreeTen Backport v1.6.8 was discovered to contain an integer overflow via the component org.threeten.bp.format.DateTimeFormatter::parse(CharSequence, ParsePosition). NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The submission may have been based on a tool that is not sufficiently robust for vulnerability identification.

Published Apr 8, 2024 · Updated Jul 9, 2026

Unknown · CVSS Not scored

CVE-2024-23081: ThreeTen Backport v1.6.8 was discovered to contain a NullPointerException via the component org.threeten.bp...

ThreeTen Backport v1.6.8 was discovered to contain a NullPointerException via the component org.threeten.bp.LocalDate::compareTo(ChronoLocalDate). NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The submission may have been based on a tool that is not sufficiently robust for vulnerability identification.

Published Apr 8, 2024 · Updated Jul 9, 2026

Critical · CVSS 9.1

CVE-2024-23080: Joda Time v2.12.5 was discovered to contain a NullPointerException via the component org.joda.time.format.P...

Joda Time v2.12.5 was discovered to contain a NullPointerException via the component org.joda.time.format.PeriodFormat::wordBased(Locale). NOTE: this is disputed by multiple third parties who believe there was not reasonable evidence to determine the existence of a vulnerability. The submission may have been based on a tool that is not sufficiently robust for vulnerability identification.

Published Apr 10, 2024 · Updated Jul 9, 2026