10

CVSS3.1

CVE-2024-36679 -

In the module "Module Live Chat Pro (All in One Messaging)" (livechatpro) <=8.4.0, a guest can perform PHP Code injection. Due to a predictable token, the method `Lcp::saveTranslations()` suffer of a white writer that can inject PHP code into a PHP file.

📅 Published: June 19, 2024, midnight 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2024-38593 - net: micrel: Fix receiving the timestamp in the frame for lan8841

In the Linux kernel, the following vulnerability has been resolved: net: micrel: Fix receiving the timestamp in the frame for lan8841 The blamed commit started to use the ptp workqueue to get the second part of the timestamp. And when the port was set down, then this workqueue is stopped. But if …

📅 Published: June 19, 2024, midnight 🔄 Last Modified: Oct. 20, 2025, 10:08 p.m.

5.5

CVSS3.1

CVE-2024-38590 - RDMA/hns: Modify the print level of CQE error

In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Modify the print level of CQE error Too much print may lead to a panic in kernel. Change ibdev_err() to ibdev_err_ratelimited(), and change the printing level of cqe dump to debug level.

📅 Published: June 19, 2024, midnight 🔄 Last Modified: May 4, 2025, 9:14 a.m.

5.5

CVSS3.1

CVE-2021-47606 - net: netlink: af_netlink: Prevent empty skb by adding a check on len.

In the Linux kernel, the following vulnerability has been resolved: net: netlink: af_netlink: Prevent empty skb by adding a check on len. Adding a check on len parameter to avoid empty skb. This prevents a division error in netem_enqueue function which is caused when skb->len=0 and skb->data_len=…

📅 Published: June 19, 2024, midnight 🔄 Last Modified: Dec. 18, 2025, 11:38 a.m.

9.8

CVSS3.1

CVE-2024-33836 -

In the module "JA Marketplace" (jamarketplace) up to version 9.0.1 from JA Module for PrestaShop, a guest can upload files with extensions .php. In version 6.X, the method `JmarketplaceproductModuleFrontController::init()` and in version 8.X, the method `JmarketplaceSellerproductModuleFrontControll…

📅 Published: June 19, 2024, midnight 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2024-38574 - libbpf: Prevent null-pointer dereference when prog to load has no BTF

In the Linux kernel, the following vulnerability has been resolved: libbpf: Prevent null-pointer dereference when prog to load has no BTF In bpf_objec_load_prog(), there's no guarantee that obj->btf is non-NULL when passing it to btf__fd(), and this function does not perform any check before dere…

📅 Published: June 19, 2024, midnight 🔄 Last Modified: May 4, 2025, 9:14 a.m.

5.5

CVSS3.1

CVE-2024-38567 - wifi: carl9170: add a proper sanity check for endpoints

In the Linux kernel, the following vulnerability has been resolved: wifi: carl9170: add a proper sanity check for endpoints Syzkaller reports [1] hitting a warning which is caused by presence of a wrong endpoint type at the URB sumbitting stage. While there was a check for a specific 4th endpoint…

📅 Published: June 19, 2024, midnight 🔄 Last Modified: Nov. 4, 2025, 6:16 p.m.

7.5

CVSS3.1

CVE-2024-6162 - Undertow: url-encoded request path information can be broken on ajp-listener

A vulnerability was found in Undertow, where URL-encoded request paths can be mishandled during concurrent requests on the AJP listener. This issue arises because the same buffer is used to decode the paths for multiple requests simultaneously, leading to incorrect path information being processed.…

📅 Published: June 19, 2024, midnight 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2024-38562 - wifi: nl80211: Avoid address calculations via out of bounds array indexing

In the Linux kernel, the following vulnerability has been resolved: wifi: nl80211: Avoid address calculations via out of bounds array indexing Before request->channels[] can be used, request->n_channels must be set. Additionally, address calculations for memory after the "channels" array need to …

📅 Published: June 19, 2024, midnight 🔄 Last Modified: May 4, 2025, 9:14 a.m.

4.7

CVSS3.1

CVE-2021-47577 - io-wq: check for wq exit after adding new worker task_work

In the Linux kernel, the following vulnerability has been resolved: io-wq: check for wq exit after adding new worker task_work We check IO_WQ_BIT_EXIT before attempting to create a new worker, and wq exit cancels pending work if we have any. But it's possible to have a race between the two, where…

📅 Published: June 19, 2024, midnight 🔄 Last Modified: Dec. 18, 2025, 11:37 a.m.
Total resulsts: 346643
Page 9149 of 34,665
« previous page » next page
Filters