6.1

CVSS3.1

CVE-2024-43024 -

Multiple stored cross-site scripting (XSS) vulnerabilities in RWS MultiTrans v7.0.23324.2 and earlier allow attackers to execute arbitrary web scripts or HTML via a crafted payload.

πŸ“… Published: Sept. 18, 2024, midnight πŸ”„ Last Modified: March 25, 2025, 5:16 p.m.

5.5

CVSS3.1

CVE-2024-46791 - can: mcp251x: fix deadlock if an interrupt occurs during mcp251x_open

In the Linux kernel, the following vulnerability has been resolved: can: mcp251x: fix deadlock if an interrupt occurs during mcp251x_open The mcp251x_hw_wake() function is called with the mpc_lock mutex held and disables the interrupt handler so that no interrupts can be processed while waking th…

πŸ“… Published: Sept. 18, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 11:16 p.m.

5.5

CVSS3.1

CVE-2024-46790 - codetag: debug: mark codetags for poisoned page as empty

In the Linux kernel, the following vulnerability has been resolved: codetag: debug: mark codetags for poisoned page as empty When PG_hwpoison pages are freed they are treated differently in free_pages_prepare() and instead of being released they are isolated. Page allocation tag counters are dec…

πŸ“… Published: Sept. 18, 2024, midnight πŸ”„ Last Modified: May 4, 2025, 9:34 a.m.

5.5

CVSS3.1

CVE-2024-46784 - net: mana: Fix error handling in mana_create_txq/rxq's NAPI cleanup

In the Linux kernel, the following vulnerability has been resolved: net: mana: Fix error handling in mana_create_txq/rxq's NAPI cleanup Currently napi_disable() gets called during rxq and txq cleanup, even before napi is enabled and hrtimer is initialized. It causes kernel panic. ? page_fault_oo…

πŸ“… Published: Sept. 18, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 11:16 p.m.

5.5

CVSS3.1

CVE-2024-46780 - nilfs2: protect references to superblock parameters exposed in sysfs

In the Linux kernel, the following vulnerability has been resolved: nilfs2: protect references to superblock parameters exposed in sysfs The superblock buffers of nilfs2 can not only be overwritten at runtime for modifications/repairs, but they are also regularly swapped, replaced during resizing…

πŸ“… Published: Sept. 18, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 11:16 p.m.

5.5

CVSS3.1

CVE-2024-46771 - can: bcm: Remove proc entry when dev is unregistered.

In the Linux kernel, the following vulnerability has been resolved: can: bcm: Remove proc entry when dev is unregistered. syzkaller reported a warning in bcm_connect() below. [0] The repro calls connect() to vxcan1, removes vxcan1, and calls connect() with ifindex == 0. Calling connect() for a …

πŸ“… Published: Sept. 18, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 11:15 p.m.

7.1

CVSS3.1

CVE-2024-46764 - bpf: add check for invalid name in btf_name_valid_section()

In the Linux kernel, the following vulnerability has been resolved: bpf: add check for invalid name in btf_name_valid_section() If the length of the name string is 1 and the value of name[0] is NULL byte, an OOB vulnerability occurs in btf_name_valid_section() and the return value is true, so the…

πŸ“… Published: Sept. 18, 2024, midnight πŸ”„ Last Modified: Sept. 26, 2025, 6:20 p.m.

5.5

CVSS3.1

CVE-2024-46763 - fou: Fix null-ptr-deref in GRO.

In the Linux kernel, the following vulnerability has been resolved: fou: Fix null-ptr-deref in GRO. We observed a null-ptr-deref in fou_gro_receive() while shutting down a host. [0] The NULL pointer is sk->sk_user_data, and the offset 8 is of protocol in struct fou. When fou_release() is calle…

πŸ“… Published: Sept. 18, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 11:15 p.m.

5.5

CVSS3.1

CVE-2024-46760 - wifi: rtw88: usb: schedule rx work after everything is set up

In the Linux kernel, the following vulnerability has been resolved: wifi: rtw88: usb: schedule rx work after everything is set up Right now it's possible to hit NULL pointer dereference in rtw_rx_fill_rx_status on hw object and/or its fields because initialization routine can start getting USB re…

πŸ“… Published: Sept. 18, 2024, midnight πŸ”„ Last Modified: May 4, 2025, 9:33 a.m.

7.5

CVSS3.1

CVE-2024-46591 -

Draytek Vigor 3910 v4.3.2.6 was discovered to contain a buffer overflow in the sDnsPro parameter at v2x00.cgi. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted input.

πŸ“… Published: Sept. 18, 2024, midnight πŸ”„ Last Modified: March 19, 2025, 4:15 p.m.
Total resulsts: 349182
Page 8524 of 34,919
Β« previous page Β» next page
Filters