7.8

CVSS3.1

CVE-2024-50085 - mptcp: pm: fix UaF read in mptcp_pm_nl_rm_addr_or_subflow

In the Linux kernel, the following vulnerability has been resolved: mptcp: pm: fix UaF read in mptcp_pm_nl_rm_addr_or_subflow Syzkaller reported this splat: ================================================================== BUG: KASAN: slab-use-after-free in mptcp_pm_nl_rm_addr_or_subflow+0x…

πŸ“… Published: Oct. 29, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 11:16 p.m.

10

CVSS3.1

CVE-2024-51567 -

upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus by bypassing secMiddleware (which is only for a POST request) and using shell metacharacters in t…

πŸ“… Published: Oct. 29, 2024, midnight πŸ”„ Last Modified: Nov. 7, 2025, 7:02 p.m.

5.5

CVSS3.1

CVE-2024-50079 - io_uring/sqpoll: ensure task state is TASK_RUNNING when running task_work

In the Linux kernel, the following vulnerability has been resolved: io_uring/sqpoll: ensure task state is TASK_RUNNING when running task_work When the sqpoll is exiting and cancels pending work items, it may need to run task_work. If this happens from within io_uring_cancel_generic(), then it may…

πŸ“… Published: Oct. 29, 2024, midnight πŸ”„ Last Modified: Oct. 1, 2025, 9:15 p.m.

7.8

CVSS3.1

CVE-2024-50084 - net: microchip: vcap api: Fix memory leaks in vcap_api_encode_rule_test()

In the Linux kernel, the following vulnerability has been resolved: net: microchip: vcap api: Fix memory leaks in vcap_api_encode_rule_test() Commit a3c1e45156ad ("net: microchip: vcap: Fix use-after-free error in kunit test") fixed the use-after-free error, but introduced below memory leaks by r…

πŸ“… Published: Oct. 29, 2024, midnight πŸ”„ Last Modified: May 4, 2025, 12:59 p.m.

7.8

CVSS3.1

CVE-2024-50073 - tty: n_gsm: Fix use-after-free in gsm_cleanup_mux

In the Linux kernel, the following vulnerability has been resolved: tty: n_gsm: Fix use-after-free in gsm_cleanup_mux BUG: KASAN: slab-use-after-free in gsm_cleanup_mux+0x77b/0x7b0 drivers/tty/n_gsm.c:3160 [n_gsm] Read of size 8 at addr ffff88815fe99c00 by task poc/3379 CPU: 0 UID: 0 PID: 3379 Co…

πŸ“… Published: Oct. 29, 2024, midnight πŸ”„ Last Modified: Jan. 5, 2026, 10:55 a.m.

5.5

CVSS3.1

CVE-2024-50080 - ublk: don't allow user copy for unprivileged device

In the Linux kernel, the following vulnerability has been resolved: ublk: don't allow user copy for unprivileged device UBLK_F_USER_COPY requires userspace to call write() on ublk char device for filling request buffer, and unprivileged device can't be trusted. So don't allow user copy for unpri…

πŸ“… Published: Oct. 29, 2024, midnight πŸ”„ Last Modified: Oct. 1, 2025, 9:15 p.m.

7.8

CVSS3.1

CVE-2024-50074 - parport: Proper fix for array out-of-bounds access

In the Linux kernel, the following vulnerability has been resolved: parport: Proper fix for array out-of-bounds access The recent fix for array out-of-bounds accesses replaced sprintf() calls blindly with snprintf(). However, since snprintf() returns the would-be-printed size, not the actually o…

πŸ“… Published: Oct. 29, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 11:16 p.m.

5.5

CVSS3.1

CVE-2024-50087 - btrfs: fix uninitialized pointer free on read_alloc_one_name() error

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix uninitialized pointer free on read_alloc_one_name() error The function read_alloc_one_name() does not initialize the name field of the passed fscrypt_str struct if kmalloc fails to allocate the corresponding buffer. T…

πŸ“… Published: Oct. 29, 2024, midnight πŸ”„ Last Modified: Nov. 3, 2025, 11:16 p.m.

9.8

CVSS3.1

CVE-2024-48138 -

A remote code execution (RCE) vulnerability in the component /PluXml/core/admin/parametres_edittpl.php of PluXml v5.8.16 and lower allows attackers to execute arbitrary code via injecting a crafted payload into a template.

πŸ“… Published: Oct. 29, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.5

CVSS3.1

CVE-2024-50075 - xhci: tegra: fix checked USB2 port number

In the Linux kernel, the following vulnerability has been resolved: xhci: tegra: fix checked USB2 port number If USB virtualizatoin is enabled, USB2 ports are shared between all Virtual Functions. The USB2 port number owned by an USB2 root hub in a Virtual Function may be less than total USB2 phy…

πŸ“… Published: Oct. 29, 2024, midnight πŸ”„ Last Modified: Oct. 1, 2025, 9:15 p.m.
Total resulsts: 345151
Page 7706 of 34,516
Β« previous page Β» next page
Filters