|
51
|
6.5
-
|
MEDIUM
Network
|
A flaw was found in the 389 Directory Server. This flaw allows an unauthenticated user to cause a systematic server crash while sending a specific extended search request, leading to a denial of serv…
|
NVD-CWE-noinfo
|
CVE-2024-6237
|
cpe:2.3:o:redhat:enterprise_linux:9.0:*
|
|
|
|
|
2024-11-21 18:49
2024-07-10
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
52
|
6.8
-
|
MEDIUM
Network
|
A flaw was found in the virtio-net device in QEMU. When enabling the RSS feature on the virtio-net network card, the indirections_table data within RSS becomes controllable. Setting excessively large…
|
-
|
CVE-2024-6505
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2024-11-21 18:49
2024-07-5
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
53
|
8.1
-
|
HIGH
Network
|
A security regression (CVE-2006-5051) was discovered in OpenSSH's server (sshd). There is a race condition which can lead sshd to handle some signals in an unsafe manner. An unauthenticated, remote a…
|
CWE-362
Race Condition
|
CVE-2024-6387
|
cpe:2.3:o:redhat:enterprise_linux:9.0:*
|
|
|
|
|
2024-11-21 18:49
2024-07-1
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
54
|
7.5
-
|
HIGH
Network
|
A flaw was found in the Poppler's Pdfinfo utility. This issue occurs when using -dests parameter with pdfinfo utility. By using certain malformed input files, an attacker could cause the utility to c…
|
NVD-CWE-noinfo
|
CVE-2024-6239
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2024-11-21 18:49
2024-06-21
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
55
|
8.1
-
|
HIGH
Network
|
A vulnerability was found in FreeIPA in a way when a Kerberos TGS-REQ is encrypted using the client’s session key. This key is different for each new session, which protects it from brute force attac…
|
-
|
CVE-2024-3183
|
cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux:7.0:*
|
|
|
|
|
2024-11-21 18:29
2024-06-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
56
|
6.7
-
|
MEDIUM
Local
|
A vulnerability was found in GNU Nano that allows a possible privilege escalation through an insecure temporary file. If Nano is killed while editing, a file it saves to an emergency file with the pe…
|
-
|
CVE-2024-5742
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2024-11-21 18:48
2024-06-12
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
57
|
5.9
-
|
MEDIUM
Network
|
A flaw was found in Booth, a cluster ticket manager. If a specially-crafted hash is passed to gcry_md_get_algo_dlen(), it may allow an invalid HMAC to be accepted by the Booth server.
|
-
|
CVE-2024-3049
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2024-11-21 18:28
2024-06-6
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
58
|
5.5
-
|
MEDIUM
Local
|
A flaw was found in QEMU. An assertion failure was present in the update_sctp_checksum() function in hw/net/net_tx_pkt.c when trying to calculate the checksum of a short-sized fragmented packet. This…
|
-
|
CVE-2024-3567
|
cpe:2.3:o:redhat:enterprise_linux:9.0:*
|
|
|
|
|
2024-11-21 18:29
2024-04-11
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
59
|
6.5
-
|
MEDIUM
Network
|
The implementation of PEAP in wpa_supplicant through 2.10 allows authentication bypass. For a successful attack, wpa_supplicant must be configured to not verify the network's TLS certificate during P…
|
CWE-287
Improper Authentication
|
CVE-2023-52160
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:*
|
|
|
|
|
2024-11-21 17:39
2024-02-23
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
60
|
7.5
-
|
HIGH
Network
|
Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, ak…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2023-50387
|
cpe:2.3:o:redhat:enterprise_linux:9.0:* cpe:2.3:o:redhat:enterprise_linux:8.0:* cpe:2.3:o:redhat:enterprise_linux…
|
|
|
|
|
2024-11-21 17:36
2024-02-15
|
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|