7.5

CVSS3.1

CVE-2024-44856 -

Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component nav2_smac_planner().

πŸ“… Published: Dec. 6, 2024, midnight πŸ”„ Last Modified: Dec. 13, 2024, 8:30 p.m.

7.8

CVSS3.1

CVE-2024-53141 - netfilter: ipset: add missing range check in bitmap_ip_uadt

In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: add missing range check in bitmap_ip_uadt When tb[IPSET_ATTR_IP_TO] is not present but tb[IPSET_ATTR_CIDR] exists, the values of ip and ip_to are slightly swapped. Therefore, the range check for ip should be don…

πŸ“… Published: Dec. 6, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 9:17 p.m.

9.1

CVSS3.1

CVE-2024-38923 -

Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request to change the value of dynamic-parameter`/amcl odom_frame_id` .

πŸ“… Published: Dec. 6, 2024, midnight πŸ”„ Last Modified: Dec. 17, 2024, 8:28 p.m.

9.8

CVSS3.1

CVE-2024-54745 -

WAVLINK WN701AE M01AE_V240305 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root.

πŸ“… Published: Dec. 6, 2024, midnight πŸ”„ Last Modified: Oct. 3, 2025, 12:52 a.m.

9.8

CVSS3.1

CVE-2024-41644 -

Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble allows an attacker to execute arbitrary code via the dyn_param_handler_ component.

πŸ“… Published: Dec. 6, 2024, midnight πŸ”„ Last Modified: Dec. 13, 2024, 8:28 p.m.

7.5

CVSS3.1

CVE-2024-44853 -

Open Robotics Robotic Operating System 2 ROS2 navigation2 v.humble was discovered to contain a NULL pointer dereference via the component computeControl().

πŸ“… Published: Dec. 6, 2024, midnight πŸ”„ Last Modified: Dec. 13, 2024, 8:33 p.m.

9.1

CVSS3.1

CVE-2024-38926 -

Open Robotics Robotic Operating System 2 (ROS2) and Nav2 humble versions were discovered to contain a use-after-free via the nav2_amcl process. This vulnerability is triggered via remotely sending a request for change the value of dynamic-parameter `/amcl z_short`.

πŸ“… Published: Dec. 6, 2024, midnight πŸ”„ Last Modified: Dec. 17, 2024, 8:28 p.m.

0.0

CVE-2024-55356 -

DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

πŸ“… Published: Dec. 6, 2024, midnight πŸ”„ Last Modified: Jan. 8, 2025, 1:15 a.m.

9.8

CVSS3.1

CVE-2024-54750 -

Ubiquiti U6-LR 6.6.65 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root. NOTE: In Ubiquiti's view there is no vulnerability as the Hardcoded Password should be after setup not before.

πŸ“… Published: Dec. 6, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-54749 -

Ubiquiti U7-Pro 7.0.35 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root. NOTE: this is disputed by the Supplier because the observation only established that a password is present in a firmware image; however, the device cannot be…

πŸ“… Published: Dec. 6, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 345149
Page 7204 of 34,515
Β« previous page Β» next page
Filters