5.5
CVE-2024-39488 - arm64: asm-bug: Add .align 2 to the end of __BUG_ENTRY
In the Linux kernel, the following vulnerability has been resolved: arm64: asm-bug: Add .align 2 to the end of __BUG_ENTRY When CONFIG_DEBUG_BUGVERBOSE=n, we fail to add necessary padding bytes to bug_table entries, and as a result the last entry in a bug table will be ignored, potentially leadinβ¦
6.5
CVE-2024-40417 -
A vulnerability was found in Tenda AX1806 1.0.0.1. Affected by this issue is the function formSetRebootTimer of the file /goform/SetIpMacBind. The manipulation of the argument list leads to stack-based buffer overflow.
8.8
CVE-2024-40333 -
idccms v1.35 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/softBak_deal.php?mudi=del&dataID=2
5.5
CVE-2024-39491 - ALSA: hda: cs35l56: Fix lifetime of cs_dsp instance
In the Linux kernel, the following vulnerability has been resolved: ALSA: hda: cs35l56: Fix lifetime of cs_dsp instance The cs_dsp instance is initialized in the driver probe() so it should be freed in the driver remove(). Also fix a missing call to cs_dsp_remove() in the error path of cs35l56_hdβ¦
7.5
CVE-2024-38875 - python-django: Potential denial-of-service in django.utils.html.urlize()
An issue was discovered in Django 4.2 before 4.2.14 and 5.0 before 5.0.7. urlize and urlizetrunc were subject to a potential denial of service attack via certain inputs with a very large number of brackets.
5.5
CVE-2024-25023 - IBM QRadar Suite Software information disclosure
IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 and IBM QRadar Suite Software 1.10.12.0 through 1.10.22.0 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 281429.
8.8
CVE-2024-21417 - Windows Text Services Framework Elevation of Privilege Vulnerability
Windows Text Services Framework Elevation of Privilege Vulnerability
3.5
CVE-2024-21832 - PingFederate REST API Data Store Injection
A potential JSON injection attack vector exists in PingFederate REST API data stores using the POST method and a JSON request body.
5.3
CVE-2024-22377 - PingFederate Runtime Node Path Traversal
The deploy directory in PingFederate runtime nodes is reachable to unauthorized users.
1.8
CVE-2024-22477 - PingFederate OIDC Policy Management Editor Cross-Site Scripting
A cross-site scripting vulnerability exists in the admin console OIDC Policy Management Editor. The impact is contained to admin console users only.