6.7

CVSS3.1

CVE-2024-42642 -

Micron Crucial MX500 Series Solid State Drives M3CR046 is vulnerable to Buffer Overflow, which can be triggered by sending specially crafted ATA packets from the host to the drive controller. NOTE: The supplier states that this vulnerability was fully remediated in December 2024 and that updated fi…

πŸ“… Published: Sept. 4, 2024, midnight πŸ”„ Last Modified: Feb. 5, 2026, 3:16 p.m.

5.5

CVSS3.1

CVE-2024-45000 - fs/netfs/fscache_cookie: add missing "n_accesses" check

In the Linux kernel, the following vulnerability has been resolved: fs/netfs/fscache_cookie: add missing "n_accesses" check This fixes a NULL pointer dereference bug due to a data race which looks like this: BUG: kernel NULL pointer dereference, address: 0000000000000008 #PF: supervisor read…

πŸ“… Published: Sept. 4, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 11:15 p.m.

5.5

CVSS3.1

CVE-2024-44975 - cgroup/cpuset: fix panic caused by partcmd_update

In the Linux kernel, the following vulnerability has been resolved: cgroup/cpuset: fix panic caused by partcmd_update We find a bug as below: BUG: unable to handle page fault for address: 00000003 PGD 0 P4D 0 Oops: 0000 [#1] PREEMPT SMP NOPTI CPU: 3 PID: 358 Comm: bash Tainted: G W I …

πŸ“… Published: Sept. 4, 2024, midnight πŸ”„ Last Modified: May 4, 2025, 9:30 a.m.

5.5

CVSS3.1

CVE-2024-44965 - x86/mm: Fix pti_clone_pgtable() alignment assumption

In the Linux kernel, the following vulnerability has been resolved: x86/mm: Fix pti_clone_pgtable() alignment assumption Guenter reported dodgy crashes on an i386-nosmp build using GCC-11 that had the form of endless traps until entry stack exhaust and then #DF from the stack guard. It turned ou…

πŸ“… Published: Sept. 4, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 11:15 p.m.

2.9

CVSS3.1

CVE-2024-8443 - Libopensc: heap buffer overflow in openpgp driver when generating key

A heap-based buffer overflow vulnerability was found in the libopensc OpenPGP driver. A crafted USB device or smart card with malicious responses to the APDUs during the card enrollment process using the `pkcs15-init` tool may lead to out-of-bound rights, possibly resulting in arbitrary code execut…

πŸ“… Published: Sept. 4, 2024, midnight πŸ”„ Last Modified: Nov. 7, 2025, 12:36 a.m.

5.5

CVSS3.1

CVE-2024-44957 - xen: privcmd: Switch from mutex to spinlock for irqfds

In the Linux kernel, the following vulnerability has been resolved: xen: privcmd: Switch from mutex to spinlock for irqfds irqfd_wakeup() gets EPOLLHUP, when it is called by eventfd_release() by way of wake_up_poll(&ctx->wqh, EPOLLHUP), which gets called under spin_lock_irqsave(). We can't use a …

πŸ“… Published: Sept. 4, 2024, midnight πŸ”„ Last Modified: Jan. 5, 2026, 10:52 a.m.

7.5

CVSS3.1

CVE-2024-45506 - haproxy: potential infinite loop condition in the h2_send() may trigger a DoS

HAProxy 2.9.x before 2.9.10, 3.0.x before 3.0.4, and 3.1.x through 3.1-dev6 allows a remote denial of service for HTTP/2 zero-copy forwarding (h2_send loop) under a certain set of conditions, as exploited in the wild in 2024.

πŸ“… Published: Sept. 4, 2024, midnight πŸ”„ Last Modified: March 14, 2025, 8:15 p.m.

5.5

CVSS3.1

CVE-2024-45001 - net: mana: Fix RX buf alloc_size alignment and atomic op panic

In the Linux kernel, the following vulnerability has been resolved: net: mana: Fix RX buf alloc_size alignment and atomic op panic The MANA driver's RX buffer alloc_size is passed into napi_build_skb() to create SKB. skb_shinfo(skb) is located at the end of skb, and its alignment is affected by t…

πŸ“… Published: Sept. 4, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 8:16 p.m.

5.5

CVSS3.1

CVE-2024-45004 - KEYS: trusted: dcp: fix leak of blob encryption key

In the Linux kernel, the following vulnerability has been resolved: KEYS: trusted: dcp: fix leak of blob encryption key Trusted keys unseal the key blob on load, but keep the sealed payload in the blob field so that every subsequent read (export) will simply convert this field to hex and send it …

πŸ“… Published: Sept. 4, 2024, midnight πŸ”„ Last Modified: May 4, 2025, 9:30 a.m.

7.8

CVSS3.1

CVE-2024-44986 - ipv6: fix possible UAF in ip6_finish_output2()

In the Linux kernel, the following vulnerability has been resolved: ipv6: fix possible UAF in ip6_finish_output2() If skb_expand_head() returns NULL, skb has been freed and associated dst/idev could also have been freed. We need to hold rcu_read_lock() to make sure the dst and associated idev ar…

πŸ“… Published: Sept. 4, 2024, midnight πŸ”„ Last Modified: April 9, 2026, 5:42 p.m.
Total resulsts: 349182
Page 8672 of 34,919
Β« previous page Β» next page
Filters