5.5

CVSS3.1

CVE-2024-42255 - tpm: Use auth only after NULL check in tpm_buf_check_hmac_response()

In the Linux kernel, the following vulnerability has been resolved: tpm: Use auth only after NULL check in tpm_buf_check_hmac_response() Dereference auth after NULL check in tpm_buf_check_hmac_response(). Otherwise, unless tpm2_sessions_init() was called, a call can cause NULL dereference, when T…

πŸ“… Published: Aug. 8, 2024, midnight πŸ”„ Last Modified: May 4, 2025, 9:25 a.m.

5.5

CVSS3.1

CVE-2024-42252 - closures: Change BUG_ON() to WARN_ON()

In the Linux kernel, the following vulnerability has been resolved: closures: Change BUG_ON() to WARN_ON() If a BUG_ON() can be hit in the wild, it shouldn't be a BUG_ON() For reference, this has popped up once in the CI, and we'll need more info to debug it: 03240 ------------[ cut here ]-----…

πŸ“… Published: Aug. 8, 2024, midnight πŸ”„ Last Modified: Jan. 5, 2026, 10:52 a.m.

6.6

CVSS3.1

CVE-2023-28865 -

Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR15, 4.0.0 SR05, 4.1.0 SR03, and 4.2.0 SR02 fails to validate the directory contents of certain directories (e.g., ensuring the expected hash sum) during the Pre-Boot Authorization (PBA) process. This can be exploited by a physical attacker…

πŸ“… Published: Aug. 8, 2024, midnight πŸ”„ Last Modified: Aug. 19, 2024, 7:04 p.m.

7.8

CVSS3.1

CVE-2024-42257 - ext4: use memtostr_pad() for s_volume_name

In the Linux kernel, the following vulnerability has been resolved: ext4: use memtostr_pad() for s_volume_name As with the other strings in struct ext4_super_block, s_volume_name is not NUL terminated. The other strings were marked in commit 072ebb3bffe6 ("ext4: add nonstring annotations to ext4.…

πŸ“… Published: Aug. 8, 2024, midnight πŸ”„ Last Modified: May 4, 2025, 9:25 a.m.

9.8

CVSS3.1

CVE-2024-40486 -

A SQL injection vulnerability in "/index.php" of Kashipara Live Membership System v1.0 allows remote attackers to execute arbitrary SQL commands and bypass Login via the email or password Login parameters.

πŸ“… Published: Aug. 8, 2024, midnight πŸ”„ Last Modified: April 28, 2025, 2:29 p.m.

5.3

CVSS3.1

CVE-2024-40475 -

SourceCodester Best House Rental Management System v1.0 is vulnerable to Incorrect Access Control via /rental/payment_report.php, /rental/balance_report.php, /rental/invoices.php, /rental/tenants.php, and /rental/users.php.

πŸ“… Published: Aug. 8, 2024, midnight πŸ”„ Last Modified: Aug. 15, 2024, 1:40 p.m.

4.7

CVSS3.1

CVE-2024-42253 - gpio: pca953x: fix pca953x_irq_bus_sync_unlock race

In the Linux kernel, the following vulnerability has been resolved: gpio: pca953x: fix pca953x_irq_bus_sync_unlock race Ensure that `i2c_lock' is held when setting interrupt latch and mask in pca953x_irq_bus_sync_unlock() in order to avoid races. The other (non-probe) call site pca953x_gpio_set_…

πŸ“… Published: Aug. 8, 2024, midnight πŸ”„ Last Modified: Jan. 5, 2026, 10:52 a.m.

4.3

CVSS3.1

CVE-2024-41238 -

A SQL injection vulnerability in /smsa/student_login.php in Kashipara Responsive School Management System v1.0 allows an attacker to execute arbitrary SQL commands via the "username" parameter.

πŸ“… Published: Aug. 8, 2024, midnight πŸ”„ Last Modified: Aug. 12, 2024, 3:06 p.m.

7.4

CVSS3.1

CVE-2024-42365 - Asterisk allows `Write=originate` as sufficient permissions for code execution / `System()` dialplan

Asterisk is an open source private branch exchange (PBX) and telephony toolkit. Prior to asterisk versions 18.24.2, 20.9.2, and 21.4.2 and certified-asterisk versions 18.9-cert11 and 20.7-cert2, an AMI user with `write=originate` may change all configuration files in the `/etc/asterisk/` directory.…

πŸ“… Published: Aug. 8, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 10:18 p.m.

6.1

CVSS3.1

CVE-2024-41481 -

Typora before 1.9.3 Markdown editor has a cross-site scripting (XSS) vulnerability via the Mermaid component.

πŸ“… Published: Aug. 8, 2024, midnight πŸ”„ Last Modified: March 20, 2025, 2:15 p.m.
Total resulsts: 349182
Page 8920 of 34,919
Β« previous page Β» next page
Filters