4.7

CVSS3.1

CVE-2024-50192 - irqchip/gic-v4: Don't allow a VMOVP on a dying VPE

In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v4: Don't allow a VMOVP on a dying VPE Kunkun Jiang reported that there is a small window of opportunity for userspace to force a change of affinity for a VPE while the VPE has already been unmapped, but the correspon…

πŸ“… Published: Nov. 8, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 11:17 p.m.

9.8

CVSS3.1

CVE-2024-48073 -

sunniwell HT3300 before 1.0.0.B022.2 is vulnerable to Insecure Permissions. The /usr/local/bin/update program, which is responsible for updating the software in the HT3300 device, is given the execution mode of sudo NOPASSWD. This program is vulnerable to a command injection vulnerability, which co…

πŸ“… Published: Nov. 8, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.8

CVSS3.1

CVE-2024-50186 - net: explicitly clear the sk pointer, when pf->create fails

In the Linux kernel, the following vulnerability has been resolved: net: explicitly clear the sk pointer, when pf->create fails We have recently noticed the exact same KASAN splat as in commit 6cd4a78d962b ("net: do not leave a dangling sk pointer, when socket creation fails"). The problem is tha…

πŸ“… Published: Nov. 8, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 11:16 p.m.

5.5

CVSS3.1

CVE-2024-50187 - drm/vc4: Stop the active perfmon before being destroyed

In the Linux kernel, the following vulnerability has been resolved: drm/vc4: Stop the active perfmon before being destroyed Upon closing the file descriptor, the active performance monitor is not stopped. Although all perfmons are destroyed in `vc4_perfmon_close_file()`, the active performance mo…

πŸ“… Published: Nov. 8, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 11:16 p.m.

6.5

CVSS3.1

CVE-2024-51030 -

A SQL injection vulnerability in manage_client.php and view_cab.php of Sourcecodester Cab Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter, leading to unauthorized access and potential compromise of sensitive data within the database.

πŸ“… Published: Nov. 8, 2024, midnight πŸ”„ Last Modified: Nov. 21, 2024, 5:15 p.m.

5.5

CVSS3.1

CVE-2024-50185 - mptcp: handle consistently DSS corruption

In the Linux kernel, the following vulnerability has been resolved: mptcp: handle consistently DSS corruption Bugged peer implementation can send corrupted DSS options, consistently hitting a few warning in the data path. Use DEBUG_NET assertions, to avoid the splat on some builds and handle cons…

πŸ“… Published: Nov. 8, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 11:16 p.m.

5.5

CVSS3.1

CVE-2024-50184 - virtio_pmem: Check device status before requesting flush

In the Linux kernel, the following vulnerability has been resolved: virtio_pmem: Check device status before requesting flush If a pmem device is in a bad status, the driver side could wait for host ack forever in virtio_pmem_flush(), causing the system to hang. So add a status check in the begin…

πŸ“… Published: Nov. 8, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 11:16 p.m.

4.7

CVSS3.1

CVE-2024-50174 - drm/panthor: Fix race when converting group handle to group object

In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Fix race when converting group handle to group object XArray provides it's own internal lock which protects the internal array when entries are being simultaneously added and removed. However there is still a race be…

πŸ“… Published: Nov. 8, 2024, midnight πŸ”„ Last Modified: Oct. 1, 2025, 9:15 p.m.

5.5

CVSS3.1

CVE-2024-50173 - drm/panthor: Fix access to uninitialized variable in tick_ctx_cleanup()

In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Fix access to uninitialized variable in tick_ctx_cleanup() The group variable can't be used to retrieve ptdev in our second loop, because it points to the previously iterated list_head, not a valid group. Get the ptd…

πŸ“… Published: Nov. 8, 2024, midnight πŸ”„ Last Modified: Oct. 1, 2025, 9:15 p.m.

5.5

CVSS3.1

CVE-2024-50182 - secretmem: disable memfd_secret() if arch cannot set direct map

In the Linux kernel, the following vulnerability has been resolved: secretmem: disable memfd_secret() if arch cannot set direct map Return -ENOSYS from memfd_secret() syscall if !can_set_direct_map(). This is the case for example on some arm64 configurations, where marking 4k PTEs in the direct …

πŸ“… Published: Nov. 8, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 11:16 p.m.
Total resulsts: 345055
Page 7572 of 34,506
Β« previous page Β» next page
Filters