8.8

CVSS3.1

CVE-2024-5290 - wpa_supplicant: wpa_supplicant loading arbitrary shared objects allowing privilege escalation

An issue was discovered in Ubuntu wpa_supplicant that resulted in loading of arbitrary shared objects, which allows a local unprivileged attacker to escalate privileges to the user that wpa_supplicant runs as (usually root). Membership in the netdev group or access to the dbus interface of wpa_…

πŸ“… Published: Aug. 7, 2024, midnight πŸ”„ Last Modified: Sept. 18, 2024, 3:39 p.m.

8.8

CVSS3.1

CVE-2024-43199 -

Nagios NDOUtils before 2.1.4 allows privilege escalation from nagios to root because certain executable files are owned by the nagios user.

πŸ“… Published: Aug. 7, 2024, midnight πŸ”„ Last Modified: Nov. 21, 2024, 9:35 a.m.

5.5

CVSS3.1

CVE-2024-42239 - bpf: Fail bpf_timer_cancel when callback is being cancelled

In the Linux kernel, the following vulnerability has been resolved: bpf: Fail bpf_timer_cancel when callback is being cancelled Given a schedule: timer1 cb timer2 cb bpf_timer_cancel(timer2); bpf_timer_cancel(timer1); Both bpf_timer_cancel calls would wait for the other callback to finish ex…

πŸ“… Published: Aug. 7, 2024, midnight πŸ”„ Last Modified: May 4, 2025, 9:24 a.m.

5.5

CVSS3.1

CVE-2024-42246 - net, sunrpc: Remap EPERM in case of connection failure in xs_tcp_setup_socket

In the Linux kernel, the following vulnerability has been resolved: net, sunrpc: Remap EPERM in case of connection failure in xs_tcp_setup_socket When using a BPF program on kernel_connect(), the call can return -EPERM. This causes xs_tcp_setup_socket() to loop forever, filling up the syslog and …

πŸ“… Published: Aug. 7, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 10:17 p.m.

5.5

CVSS3.1

CVE-2024-42245 - Revert "sched/fair: Make sure to try to detach at least one movable task"

In the Linux kernel, the following vulnerability has been resolved: Revert "sched/fair: Make sure to try to detach at least one movable task" This reverts commit b0defa7ae03ecf91b8bfd10ede430cff12fcbd06. b0defa7ae03ec changed the load balancing logic to ignore env.max_loop if all tasks examined …

πŸ“… Published: Aug. 7, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 10:17 p.m.

5.5

CVSS3.1

CVE-2024-42243 - mm/filemap: make MAX_PAGECACHE_ORDER acceptable to xarray

In the Linux kernel, the following vulnerability has been resolved: mm/filemap: make MAX_PAGECACHE_ORDER acceptable to xarray Patch series "mm/filemap: Limit page cache size to that supported by xarray", v2. Currently, xarray can't support arbitrary page cache size. More details can be found fr…

πŸ“… Published: Aug. 7, 2024, midnight πŸ”„ Last Modified: May 4, 2025, 9:24 a.m.

5.5

CVSS3.1

CVE-2024-42238 - firmware: cs_dsp: Return error if block header overflows file

In the Linux kernel, the following vulnerability has been resolved: firmware: cs_dsp: Return error if block header overflows file Return an error from cs_dsp_power_up() if a block header is longer than the amount of data left in the file. The previous code in cs_dsp_load() and cs_dsp_load_coeff(…

πŸ“… Published: Aug. 7, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 10:17 p.m.

5.3

CVSS3.1

CVE-2024-41432 -

An IP Spoofing vulnerability has been discovered in Likeshop up to 2.5.7.20210811. This issue allows an attacker to replace their real IP address with any arbitrary IP address, specifically by adding a forged 'X-Forwarded' or 'Client-IP' header to requests. Exploiting IP spoofing, attackers can byp…

πŸ“… Published: Aug. 7, 2024, midnight πŸ”„ Last Modified: Aug. 8, 2024, 3:02 p.m.

8.8

CVSS3.1

CVE-2024-7557 - Odh-dashboard: odh-model-controller: cross-model authentication bypass in openshift ai

A vulnerability was found in OpenShift AI that allows for authentication bypass and privilege escalation across models within the same namespace. When deploying AI models, the UI provides the option to protect models with authentication. However, credentials from one model can be used to access oth…

πŸ“… Published: Aug. 7, 2024, midnight πŸ”„ Last Modified: March 19, 2026, 5:16 p.m.

3.3

CVSS3.1

CVE-2024-42249 - spi: don't unoptimize message in spi_async()

In the Linux kernel, the following vulnerability has been resolved: spi: don't unoptimize message in spi_async() Calling spi_maybe_unoptimize_message() in spi_async() is wrong because the message is likely to be in the queue and not transferred yet. This can corrupt the message while it is being …

πŸ“… Published: Aug. 7, 2024, midnight πŸ”„ Last Modified: May 4, 2025, 9:25 a.m.
Total resulsts: 346087
Page 8622 of 34,609
Β« previous page Β» next page
Filters