|
31
|
7.5
-
|
HIGH
Network
|
A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from the server contains another symbolic link within it…
|
CWE-22
Path Traversal
|
CVE-2024-12088
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2026-04-15 07:16
2025-01-15
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
32
|
7.5
-
|
HIGH
Network
|
A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can be enabled by the server even …
|
CWE-22
Path Traversal
|
CVE-2024-12087
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2026-04-15 07:16
2025-01-15
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
33
|
6.8
-
|
MEDIUM
Network
|
A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when files are being copied from a client to a server. D…
|
CWE-390
Detection of Error Condition Without Action
|
CVE-2024-12086
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2026-04-15 07:16
2025-01-15
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
34
|
7.5
-
|
HIGH
Network
|
A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checks…
|
CWE-908
Use of Uninitialized Resource
|
CVE-2024-12085
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2026-04-15 07:16
2025-01-15
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
35
|
5.3
-
|
MEDIUM
Network
|
In mutt and neomutt, PGP encryption does not use the --hidden-recipient mode which may leak the Bcc email header field by inferring from the recipients info.
|
NVD-CWE-noinfo
|
CVE-2024-49395
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-14 22:33
2024-11-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
36
|
5.3
-
|
MEDIUM
Network
|
In mutt and neomutt the In-Reply-To email header field is not protected by cryptographic signing which allows an attacker to reuse an unencrypted but signed email message to impersonate the original …
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2024-49394
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-14 22:38
2024-11-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
37
|
5.9
-
|
MEDIUM
Network
|
In neomutt and mutt, the To and Cc email headers are not validated by cryptographic signing which allows an attacker that intercepts a message to change their value and include himself as a one of th…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2024-49393
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-14 23:31
2024-11-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
38
|
7.8
-
|
HIGH
Local
|
In the Linux kernel, the following vulnerability has been resolved:
parport: Proper fix for array out-of-bounds access
The recent fix for array out-of-bounds accesses replaced sprintf()
calls blind…
|
CWE-125
Out-of-bounds Read
|
CVE-2024-50074
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-9 01:15
2024-10-29
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
39
|
8.2
-
|
HIGH
Network
|
A flaw was found in Go. When FIPS mode is enabled on a system, container runtimes may incorrectly handle certain file paths due to improper validation in the containers/common Go library. This flaw a…
|
CWE-59
Link Following
|
CVE-2024-9341
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-23 04:34
2024-10-2
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
40
|
5.5
-
|
MEDIUM
Local
|
A flaw was found in QEMU. An assertion failure was present in the usb_ep_get() function in hw/net/core.c when trying to get the USB endpoint from a USB device. This flaw may allow a malicious unprivi…
|
-
|
CVE-2024-8354
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2024-11-21 18:53
2024-09-19
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|