6.5

CVSS3.1

CVE-2024-57540 -

Linksys E8450 v1.2.00.360516 was discovered to contain a buffer overflow vulnerability. The parsed field (action) is copied to the stack without length verification.

πŸ“… Published: Jan. 21, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 2:11 p.m.

5.5

CVSS3.1

CVE-2024-57939 - riscv: Fix sleeping in invalid context in die()

In the Linux kernel, the following vulnerability has been resolved: riscv: Fix sleeping in invalid context in die() die() can be called in exception handler, and therefore cannot sleep. However, die() takes spinlock_t which can sleep with PREEMPT_RT enabled. That causes the following warning: BU…

πŸ“… Published: Jan. 21, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 9:18 p.m.

7.5

CVSS3.1

CVE-2024-24424 -

A reachable assertion in the decode_access_point_name_ie function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows attackers to cause a Denial of Service (DoS) via a crafted NAS packet.

πŸ“… Published: Jan. 21, 2025, midnight πŸ”„ Last Modified: July 12, 2025, 11:06 p.m.

5.5

CVSS3.1

CVE-2024-55504 -

An issue in RAR Extractor - Unarchiver Free and Pro v.6.4.0 allows local attackers to inject arbitrary code potentially leading to remote control and unauthorized access to sensitive user data via the exploit_combined.dylib component on MacOS.

πŸ“… Published: Jan. 21, 2025, midnight πŸ”„ Last Modified: Feb. 4, 2025, 4:15 p.m.

5.3

CVSS3.1

CVE-2025-23085 - nodejs: GOAWAY HTTP/2 frames cause memory leak outside heap

A memory leak could occur when a remote peer abruptly closes the socket without sending a GOAWAY notification. Additionally, if an invalid header was detected by nghttp2, causing the connection to be terminated by the peer, the same leak was triggered. This flaw could lead to increased memory consu…

πŸ“… Published: Jan. 21, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 9:19 p.m.

8.8

CVSS3.1

CVE-2024-57542 -

Linksys E8450 v1.2.00.360516 was discovered to contain a command injection vulnerability via the field id_email_check_btn.

πŸ“… Published: Jan. 21, 2025, midnight πŸ”„ Last Modified: April 22, 2025, 2:11 p.m.

6.5

CVSS3.1

CVE-2023-37036 -

A Null pointer dereference vulnerability in the Mobile Management Entity (MME) in Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows network-adjacent attackers to crash the MME via an S1AP `Uplink NAS Transport` packet missing an expected `ENB_UE_S1AP_ID` field.

πŸ“… Published: Jan. 21, 2025, midnight πŸ”„ Last Modified: March 18, 2025, 9:15 p.m.

6.1

CVSS3.1

CVE-2023-45908 -

Homarr before v0.14.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the Notebook widget.

πŸ“… Published: Jan. 21, 2025, midnight πŸ”„ Last Modified: Jan. 21, 2025, 8:15 p.m.

7.5

CVSS3.1

CVE-2024-24444 -

Improper file descriptor handling for closed connections in OpenAirInterface CN5G AMF (oai-cn5g-amf) up to v2.0.0 allows attackers to cause a Denial of Service (DoS) by repeatedly establishing SCTP connections with the N2 interface.

πŸ“… Published: Jan. 21, 2025, midnight πŸ”„ Last Modified: Feb. 10, 2025, 10:15 p.m.

5.5

CVSS3.1

CVE-2024-57930 - tracing: Have process_string() also allow arrays

In the Linux kernel, the following vulnerability has been resolved: tracing: Have process_string() also allow arrays In order to catch a common bug where a TRACE_EVENT() TP_fast_assign() assigns an address of an allocated string to the ring buffer and then references it in TP_printk(), which can …

πŸ“… Published: Jan. 21, 2025, midnight πŸ”„ Last Modified: Nov. 3, 2025, 9:18 p.m.
Total resulsts: 342654
Page 6386 of 34,266
Β« previous page Β» next page
Filters