4

CVSS3.1

CVE-2024-20065 -

In telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08698617; Issue ID: MSV-1394.

πŸ“… Published: June 3, 2024, 2:04 a.m. πŸ”„ Last Modified: April 25, 2025, 6:39 p.m.

5.3

CVSS4.0

CVE-2024-5590 - Netentsec NS-ASG Application Security Gateway JSON Content uploadiscuser.php sql injection

A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been declared as critical. This vulnerability affects unknown code of the file /protocol/iscuser/uploadiscuser.php of the component JSON Content Handler. The manipulation of the argument messagecontent leads to s…

πŸ“… Published: June 3, 2024, 12:31 a.m. πŸ”„ Last Modified: Feb. 7, 2025, 3:10 p.m.

5.3

CVSS4.0

CVE-2024-5589 - Netentsec NS-ASG Application Security Gateway sql injection

A vulnerability was found in Netentsec NS-ASG Application Security Gateway 6.3. It has been classified as critical. This affects an unknown part of the file /admin/config_MT.php?action=delete. The manipulation of the argument Mid leads to sql injection. It is possible to initiate the attack remotel…

πŸ“… Published: June 3, 2024, midnight πŸ”„ Last Modified: Feb. 7, 2025, 3:10 p.m.

7.8

CVSS3.1

CVE-2024-36963 - tracefs: Reset permissions on remount if permissions are options

In the Linux kernel, the following vulnerability has been resolved: tracefs: Reset permissions on remount if permissions are options There's an inconsistency with the way permissions are handled in tracefs. Because the permissions are generated when accessed, they default to the root inode's perm…

πŸ“… Published: June 3, 2024, midnight πŸ”„ Last Modified: Sept. 17, 2025, 9:01 p.m.

6.2

CVSS3.1

CVE-2024-36962 - net: ks8851: Queue RX packets in IRQ handler instead of disabling BHs

In the Linux kernel, the following vulnerability has been resolved: net: ks8851: Queue RX packets in IRQ handler instead of disabling BHs Currently the driver uses local_bh_disable()/local_bh_enable() in its IRQ handler to avoid triggering net_rx_action() softirq on exit from netif_rx(). The net_…

πŸ“… Published: June 3, 2024, midnight πŸ”„ Last Modified: Oct. 1, 2025, 2:36 p.m.

5.5

CVSS3.1

CVE-2024-36961 - thermal/debugfs: Fix two locking issues with thermal zone debug

In the Linux kernel, the following vulnerability has been resolved: thermal/debugfs: Fix two locking issues with thermal zone debug With the current thermal zone locking arrangement in the debugfs code, user space can open the "mitigations" file for a thermal zone before the zone's debugfs pointe…

πŸ“… Published: June 3, 2024, midnight πŸ”„ Last Modified: Sept. 17, 2025, 10:22 p.m.

7.1

CVSS3.1

CVE-2024-36960 - drm/vmwgfx: Fix invalid reads in fence signaled events

In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Fix invalid reads in fence signaled events Correctly set the length of the drm_event to the size of the structure that's actually used. The length of the drm_event was set to the parent structure instead of to the dr…

πŸ“… Published: June 3, 2024, midnight πŸ”„ Last Modified: May 4, 2025, 9:12 a.m.

4.9

CVSS3.1

CVE-2025-0620 - Samba: smbd doesn't pick up group membership changes when re-authenticating an expired smb session

A flaw was found in Samba. The smbd service daemon does not pick up group membership changes when re-authenticating an expired SMB session. This issue can expose file shares until clients disconnect and then connect again.

πŸ“… Published: June 3, 2024, midnight πŸ”„ Last Modified: March 18, 2026, 8:43 p.m.

5.5

CVSS3.1

CVE-2024-36964 - fs/9p: only translate RWX permissions for plain 9P2000

In the Linux kernel, the following vulnerability has been resolved: fs/9p: only translate RWX permissions for plain 9P2000 Garbage in plain 9P2000's perm bits is allowed through, which causes it to be able to set (among others) the suid bit. This was presumably not the intent since the unix exten…

πŸ“… Published: June 3, 2024, midnight πŸ”„ Last Modified: Jan. 5, 2026, 10:36 a.m.

7.5

CVSS3.1

CVE-2024-4540 - Keycloak: exposure of sensitive information in pushed authorization requests (par) kc_restart cookie

A flaw was found in Keycloak in OAuth 2.0 Pushed Authorization Requests (PAR). Client-provided parameters were found to be included in plain text in the KC_RESTART cookie returned by the authorization server's HTTP response to a `request_uri` authorization request, possibly leading to an informatio…

πŸ“… Published: June 3, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 9610 of 34,919
Β« previous page Β» next page
Filters