5.5

CVSS3.1

CVE-2024-36478 - null_blk: fix null-ptr-dereference while configuring 'power' and 'submit_queues'

In the Linux kernel, the following vulnerability has been resolved: null_blk: fix null-ptr-dereference while configuring 'power' and 'submit_queues' Writing 'power' and 'submit_queues' concurrently will trigger kernel panic: Test script: modprobe null_blk nr_devices=0 mkdir -p /sys/kernel/confi…

πŸ“… Published: June 21, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 10:16 p.m.

5.5

CVSS3.1

CVE-2024-31076 - genirq/cpuhotplug, x86/vector: Prevent vector leak during CPU offline

In the Linux kernel, the following vulnerability has been resolved: genirq/cpuhotplug, x86/vector: Prevent vector leak during CPU offline The absence of IRQD_MOVE_PCNTXT prevents immediate effectiveness of interrupt affinity reconfiguration via procfs. Instead, the change is deferred until the ne…

πŸ“… Published: June 21, 2024, midnight πŸ”„ Last Modified: Nov. 4, 2025, 6:16 p.m.

5.5

CVSS3.1

CVE-2024-38633 - serial: max3100: Update uart_driver_registered on driver removal

In the Linux kernel, the following vulnerability has been resolved: serial: max3100: Update uart_driver_registered on driver removal The removal of the last MAX3100 device triggers the removal of the driver. However, code doesn't update the respective global variable and after insmod β€” rmmod β€” in…

πŸ“… Published: June 21, 2024, midnight πŸ”„ Last Modified: Nov. 4, 2025, 6:16 p.m.

0.0

CVE-2024-37694 -

This submission has been rejected by the CNA of record. Authentication is user configurable as described in our documentation. Β  Β  https://enterprise.arcgis.com/en/server/latest/administer/windows/configuring-arcgis-server-security.htm

πŸ“… Published: June 21, 2024, midnight πŸ”„ Last Modified: June 27, 2024, 8:15 p.m.

7.8

CVSS3.1

CVE-2024-39277 - dma-mapping: benchmark: handle NUMA_NO_NODE correctly

In the Linux kernel, the following vulnerability has been resolved: dma-mapping: benchmark: handle NUMA_NO_NODE correctly cpumask_of_node() can be called for NUMA_NO_NODE inside do_map_benchmark() resulting in the following sanitizer report: UBSAN: array-index-out-of-bounds in ./arch/x86/include…

πŸ“… Published: June 21, 2024, midnight πŸ”„ Last Modified: May 30, 2025, 7:30 p.m.

5.3

CVSS3.1

CVE-2024-38873 -

An issue was discovered in the friendlycaptcha_official (aka Integration of Friendly Captcha) extension before 0.1.4 for TYPO3. The extension fails to check the requirement of the captcha field in submitted form data, allowing a remote user to bypass the captcha check. This only affects the captcha…

πŸ“… Published: June 21, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.7

CVSS3.1

CVE-2024-38361 - Permissions processing error in spacedb

Spicedb is an Open Source, Google Zanzibar-inspired permissions database to enable fine-grained authorization for customer applications. Use of an exclusion under an arrow that has multiple resources may resolve to `NO_PERMISSION` when permission is expected. If the resource exists under *multiple*…

πŸ“… Published: June 20, 2024, 10:18 p.m. πŸ”„ Last Modified: Sept. 2, 2025, 8:37 p.m.

6.5

CVSS3.1

CVE-2024-38359 - Lightning Network Daemon Onion Bomb

The Lightning Network Daemon (lnd) - is a complete implementation of a Lightning Network node. A parsing vulnerability in lnd's onion processing logic and lead to a DoS vector due to excessive memory allocation. The issue was patched in lnd v0.17.0. Users should update to a version > v0.17.0 to be…

πŸ“… Published: June 20, 2024, 10:16 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2024-37899 - Disabling a user account changes its author, allowing RCE from user account in XWiki

XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. When an admin disables a user account, the user's profile is executed with the admin's rights. This allows a user to place malicious code in the user profile before getting an admin to disable t…

πŸ“… Published: June 20, 2024, 10:13 p.m. πŸ”„ Last Modified: Feb. 5, 2025, 4:01 p.m.

8.7

CVSS4.0

CVE-2024-32943 - Westermo L210-F2G Lynx Improper Control of Interaction Frequency

An attacker may be able to cause a denial-of-service condition by sending many SSH packets repeatedly.

πŸ“… Published: June 20, 2024, 10:12 p.m. πŸ”„ Last Modified: July 30, 2025, 6:05 p.m.
Total resulsts: 348413
Page 9295 of 34,842
Β« previous page Β» next page
Filters