7.8
CVE-2024-36012 - Bluetooth: msft: fix slab-use-after-free in msft_do_close()
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: msft: fix slab-use-after-free in msft_do_close() Tying the msft->data lifetime to hdev by freeing it in hci_release_dev() to fix the following case: [use] msft_do_close() msft = hdev->msft_data; if (!msft) โฆ
5.5
CVE-2024-36011 - Bluetooth: HCI: Fix potential null-ptr-deref
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HCI: Fix potential null-ptr-deref Fix potential null-ptr-deref in hci_le_big_sync_established_evt().
7.8
CVE-2024-29853 -
An authentication bypass vulnerability in Veeam Agent for Microsoft Windows allows for local privilege escalation.
7.2
CVE-2024-29851 -
Veeam Backup Enterprise Manager allows high-privileged users to steal NTLM hash of Enterprise manager service account.
2.7
CVE-2024-29852 -
Veeam Backup Enterprise Manager allows high-privileged users to read backup session logs.
8.8
CVE-2024-29850 -
Veeam Backup Enterprise Manager allows account takeover via NTLM relay.
9.8
CVE-2024-29849 -
Veeam Backup Enterprise Manager allows unauthenticated users to log in as any user to enterprise manager web interface.
6.7
CVE-2023-46806 -
An SQL Injection vulnerability in a web component of EPMM versions before 12.1.0.0 allows an authenticated user with appropriate privilege to access or modify data in the underlying database.
6.7
CVE-2023-46807 -
An SQL Injection vulnerability in web component of EPMM before 12.1.0.0 allows an authenticated user with appropriate privilege to access or modify data in the underlying database.
6.7
CVE-2024-22026 -
A local privilege escalation vulnerability in EPMM before 12.1.0.0 allows an authenticated local user to bypass shell restriction and execute arbitrary commands on the appliance.