7.8
CVE-2024-57850 - jffs2: Prevent rtime decompress memory corruption
In the Linux kernel, the following vulnerability has been resolved: jffs2: Prevent rtime decompress memory corruption The rtime decompression routine does not fully check bounds during the entirety of the decompression pass and can corrupt memory outside the decompression buffer if the compressedβ¦
7.8
CVE-2024-57849 - s390/cpum_sf: Handle CPU hotplug remove during sampling
In the Linux kernel, the following vulnerability has been resolved: s390/cpum_sf: Handle CPU hotplug remove during sampling CPU hotplug remove handling triggers the following function call sequence: CPUHP_AP_PERF_S390_SF_ONLINE --> s390_pmu_sf_offline_cpu() ... CPUHP_AP_PERF_ONLINE β¦
7.8
CVE-2024-50051 - spi: mpc52xx: Add cancel_work_sync before module remove
In the Linux kernel, the following vulnerability has been resolved: spi: mpc52xx: Add cancel_work_sync before module remove If we remove the module which will call mpc52xx_spi_remove it will free 'ms' through spi_unregister_controller. while the work ms->work will be used. The sequence of operatiβ¦
8.8
CVE-2024-9188 - Specially constructed queries cause cross platform scripting leaking administrator tokens
Specially constructed queries cause cross platform scripting leaking administrator tokens
7.6
CVE-2024-47520 - A user with advanced report application access rights can perform actions for which they are not auβ¦
A user with advanced report application access rights can perform actions for which they are not authorized
8.3
CVE-2024-47519 - Backup uploads to ETM subject to man-in-the-middle interception
Backup uploads to ETM subject to man-in-the-middle interception
6.4
CVE-2024-47518 - Specially constructed queries targeting ETM could discover active remote access sessions
Specially constructed queries targeting ETM could discover active remote access sessions
6.8
CVE-2024-47517 - Expired and unusable administrator authentication tokens can be revealed by units that have timed oβ¦
Expired and unusable administrator authentication tokens can be revealed by units that have timed out from ETM access
8.3
CVE-2024-9134 - Multiple SQL Injection vulnerabilities exist in the reporting application. A user with advanced reβ¦
Multiple SQL Injection vulnerabilities exist in the reporting application. A user with advanced report application access rights can exploit the SQL injection, allowing them to execute commands on the underlying operating system with elevated privileges.
6.6
CVE-2024-9133 - A user with administrator privileges is able to retrieve authentication tokens
A user with administrator privileges is able to retrieve authentication tokens