5.5

CVSS3.1

CVE-2024-50245 - fs/ntfs3: Fix possible deadlock in mi_read

In the Linux kernel, the following vulnerability has been resolved: fs/ntfs3: Fix possible deadlock in mi_read Mutex lock with another subclass used in ni_lock_dir().

πŸ“… Published: Nov. 9, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 11:17 p.m.

7.8

CVSS3.1

CVE-2024-50235 - wifi: cfg80211: clear wdev->cqm_config pointer on free

In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: clear wdev->cqm_config pointer on free When we free wdev->cqm_config when unregistering, we also need to clear out the pointer since the same wdev/netdev may get re-registered in another network namespace, then de…

πŸ“… Published: Nov. 9, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 11:17 p.m.

5.5

CVSS3.1

CVE-2024-50238 - phy: qcom: qmp-usbc: fix NULL-deref on runtime suspend

In the Linux kernel, the following vulnerability has been resolved: phy: qcom: qmp-usbc: fix NULL-deref on runtime suspend Commit 413db06c05e7 ("phy: qcom-qmp-usb: clean up probe initialisation") removed most users of the platform device driver data from the qcom-qmp-usb driver, but mistakenly al…

πŸ“… Published: Nov. 9, 2024, midnight πŸ”„ Last Modified: Oct. 1, 2025, 9:16 p.m.

5.5

CVSS3.1

CVE-2024-50249 - ACPI: CPPC: Make rmw_lock a raw_spin_lock

In the Linux kernel, the following vulnerability has been resolved: ACPI: CPPC: Make rmw_lock a raw_spin_lock The following BUG was triggered: ============================= [ BUG: Invalid wait context ] 6.12.0-rc2-XXX #406 Not tainted ----------------------------- kworker/1:1/62 is trying to loc…

πŸ“… Published: Nov. 9, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 11:17 p.m.

5.5

CVSS3.1

CVE-2024-50218 - ocfs2: pass u64 to ocfs2_truncate_inline maybe overflow

In the Linux kernel, the following vulnerability has been resolved: ocfs2: pass u64 to ocfs2_truncate_inline maybe overflow Syzbot reported a kernel BUG in ocfs2_truncate_inline. There are two reasons for this: first, the parameter value passed is greater than ocfs2_max_inline_data_with_xattr, s…

πŸ“… Published: Nov. 9, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 11:17 p.m.

5.5

CVSS3.1

CVE-2024-50239 - phy: qcom: qmp-usb-legacy: fix NULL-deref on runtime suspend

In the Linux kernel, the following vulnerability has been resolved: phy: qcom: qmp-usb-legacy: fix NULL-deref on runtime suspend Commit 413db06c05e7 ("phy: qcom-qmp-usb: clean up probe initialisation") removed most users of the platform device driver data from the qcom-qmp-usb driver, but mistake…

πŸ“… Published: Nov. 9, 2024, midnight πŸ”„ Last Modified: Oct. 1, 2025, 9:16 p.m.

8.6

CVSS3.1

CVE-2024-52007 - XXE vulnerability in XSLT parsing in `org.hl7.fhir.core`

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. XSLT parsing performed by various components are vulnerable to XML external entity injections. A processed XML file with a malicious DTD tag ( <!DOCTYPE foo [<!ENTITY example SYSTEM "/etc/passwd…

πŸ“… Published: Nov. 8, 2024, 10:28 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.5

CVSS4.0

CVE-2024-52009 - Git credentials are exposed in atlantis logs

Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. Atlantis logs contains GitHub credentials (tokens `ghs_...`) when they are rotated. This enables an attacker able to read these logs to impersonate Atlantis application and to perform actions o…

πŸ“… Published: Nov. 8, 2024, 10:24 p.m. πŸ”„ Last Modified: Sept. 29, 2025, 3:06 p.m.

6.1

CVSS3.1

CVE-2024-52000 - Reflected Cross-site Scripting exploit in Combodo iTop

Combodo iTop is a simple, web based IT Service Management tool. Affected versions are subject to a reflected Cross-site Scripting (XSS) exploit by way of editing a request's payload which can lead to malicious javascript execution. This issue has been addressed in version 3.2.0 via systematic escap…

πŸ“… Published: Nov. 8, 2024, 10:20 p.m. πŸ”„ Last Modified: Jan. 7, 2025, 4:52 p.m.

4.3

CVSS3.1

CVE-2024-52001 - Portal user is able to access forbidden services information in Combodo iTop

Combodo iTop is a simple, web based IT Service Management tool. In affected versions portal users are able to access forbidden services information. This issue has been addressed in version 3.2.0. All users are advised to upgrade. There are no known workarounds for this vulnerability.

πŸ“… Published: Nov. 8, 2024, 10:18 p.m. πŸ”„ Last Modified: Jan. 7, 2025, 4:48 p.m.
Total resulsts: 349182
Page 7977 of 34,919
Β« previous page Β» next page
Filters