5.4

CVSS3.1

CVE-2024-37672 -

Cross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute arbitrary code via the idactivity parameter.

πŸ“… Published: June 21, 2024, midnight πŸ”„ Last Modified: Nov. 21, 2024, 9:24 a.m.

5.4

CVSS3.1

CVE-2024-37671 -

Cross Site Scripting vulnerability in Tessi Docubase Document Management product 5.x allows a remote attacker to execute arbitrary code via the page parameter.

πŸ“… Published: June 21, 2024, midnight πŸ”„ Last Modified: March 14, 2025, 4:15 p.m.

7.5

CVSS3.1

CVE-2024-35537 -

TVS Motor Company Limited TVS Connect Android v4.6.0 and IOS v5.0.0 was discovered to insecurely handle the RSA key pair, allowing attackers to possibly access sensitive information via decryption.

πŸ“… Published: June 21, 2024, midnight πŸ”„ Last Modified: March 13, 2025, 3:15 p.m.

5.5

CVSS3.1

CVE-2024-36484 - net: relax socket state check at accept time.

In the Linux kernel, the following vulnerability has been resolved: net: relax socket state check at accept time. Christoph reported the following splat: WARNING: CPU: 1 PID: 772 at net/ipv4/af_inet.c:761 __inet_accept+0x1f4/0x4a0 Modules linked in: CPU: 1 PID: 772 Comm: syz-executor510 Not tain…

πŸ“… Published: June 21, 2024, midnight πŸ”„ Last Modified: Oct. 1, 2025, 1:59 p.m.

5.5

CVSS3.1

CVE-2024-33621 - ipvlan: Dont Use skb->sk in ipvlan_process_v{4,6}_outbound

In the Linux kernel, the following vulnerability has been resolved: ipvlan: Dont Use skb->sk in ipvlan_process_v{4,6}_outbound Raw packet from PF_PACKET socket ontop of an IPv6-backed ipvlan device will hit WARN_ON_ONCE() in sk_mc_loop() through sch_direct_xmit() path. WARNING: CPU: 2 PID: 0 at …

πŸ“… Published: June 21, 2024, midnight πŸ”„ Last Modified: Nov. 4, 2025, 6:16 p.m.

4.4

CVSS3.1

CVE-2024-33619 - efi: libstub: only free priv.runtime_map when allocated

In the Linux kernel, the following vulnerability has been resolved: efi: libstub: only free priv.runtime_map when allocated priv.runtime_map is only allocated when efi_novamap is not set. Otherwise, it is an uninitialized value. In the error path, it is freed unconditionally. Avoid passing an u…

πŸ“… Published: June 21, 2024, midnight πŸ”„ Last Modified: July 13, 2025, 11:14 a.m.

5.5

CVSS3.1

CVE-2024-38780 - dma-buf/sw-sync: don't enable IRQ from sync_print_obj()

In the Linux kernel, the following vulnerability has been resolved: dma-buf/sw-sync: don't enable IRQ from sync_print_obj() Since commit a6aa8fca4d79 ("dma-buf/sw-sync: Reduce irqsave/irqrestore from known context") by error replaced spin_unlock_irqrestore() with spin_unlock_irq() for both sync_d…

πŸ“… Published: June 21, 2024, midnight πŸ”„ Last Modified: Nov. 4, 2025, 6:16 p.m.

5.5

CVSS3.1

CVE-2024-38628 - usb: gadget: u_audio: Fix race condition use of controls after free during gadget unbind.

In the Linux kernel, the following vulnerability has been resolved: usb: gadget: u_audio: Fix race condition use of controls after free during gadget unbind. Hang on to the control IDs instead of pointers since those are correctly handled with locks.

πŸ“… Published: June 21, 2024, midnight πŸ”„ Last Modified: May 4, 2025, 9:15 a.m.

9.8

CVSS3.1

CVE-2024-34989 -

In the module RSI PDF/HTML catalog evolution (prestapdf) <= 7.0.0 from RSI for PrestaShop, a guest can perform SQL injection via `PrestaPDFProductListModuleFrontController::queryDb().'

πŸ“… Published: June 21, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.1

CVSS3.1

CVE-2024-38635 - soundwire: cadence: fix invalid PDI offset

In the Linux kernel, the following vulnerability has been resolved: soundwire: cadence: fix invalid PDI offset For some reason, we add an offset to the PDI, presumably to skip the PDI0 and PDI1 which are reserved for BPT. This code is however completely wrong and leads to an out-of-bounds access…

πŸ“… Published: June 21, 2024, midnight πŸ”„ Last Modified: Sept. 17, 2025, 5 p.m.
Total resulsts: 349182
Page 9369 of 34,919
Β« previous page Β» next page
Filters