1341
|
- |
|
-
|
-
|
An incorrect access control issue in Life: Personal Diary, Journal android app 17.5.0 allows a physically proximate attacker to escalate privileges via the fingerprint authentication function.
|
-
|
CVE-2024-40239
|
2024-11-14 00:35 |
2024-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1342
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
be2net: fix potential memory leak in be_xmit()
The be_xmit() returns NETDEV_TX_OK without freeing skb
in case of be_xmit_enqueue(…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2024-50167
|
2024-11-14 00:29 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1343
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath9k_htc: Use __skb_set_length() for resetting urb before resubmit
Syzbot points out that skb_trim() has a sanity check on…
|
CWE-824
Access of Uninitialized Pointer
|
CVE-2024-49938
|
2024-11-14 00:25 |
2024-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1344
|
6.1 |
MEDIUM
Network
|
veritas
|
data_insight
|
An XSS vulnerability was discovered in Veritas Data Insight before 7.1. It allows a remote attacker to inject an arbitrary web script into an HTTP request that could reflect back to an authenticated …
|
CWE-79
Cross-site Scripting
|
CVE-2024-47854
|
2024-11-14 00:25 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1345
|
6.5 |
MEDIUM
Adjacent
|
zephyrproject
|
zephyr
|
No proper validation of the length of user input in olcp_ind_handler in zephyr/subsys/bluetooth/services/ots/ots_client.c.
|
CWE-787
Out-of-bounds Write
|
CVE-2024-6444
|
2024-11-14 00:24 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1346
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
scsi: target: core: Fix null-ptr-deref in target_alloc_device()
There is a null-ptr-deref issue reported by KASAN:
BUG: KASAN: n…
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-50153
|
2024-11-14 00:23 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1347
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
ACPI: PAD: fix crash in exit_round_robin()
The kernel occasionally crashes in cpumask_clear_cpu(), which is called
within exit_ro…
|
NVD-CWE-noinfo
|
CVE-2024-49935
|
2024-11-14 00:21 |
2024-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1348
|
4.6 |
MEDIUM
Physics
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
fs/inode: Prevent dump_mapping() accessing invalid dentry.d_name.name
It's observed that a crash occurs during hot-remove a memor…
|
NVD-CWE-noinfo
|
CVE-2024-49934
|
2024-11-14 00:18 |
2024-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1349
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix possible double free in smb2_set_ea()
Clang static checker(scan-build) warning?
fs/smb/client/smb2ops.c:1304:2: …
|
CWE-415
Double Free
|
CVE-2024-50152
|
2024-11-14 00:15 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1350
|
5.3 |
MEDIUM
Network
iowacomputergurus
|
aspnetcore.utilities.cloudstorage
|
ICG.AspNetCore.Utilities.CloudStorage is a collection of cloud storage utilities to assist with the management of files for cloud upload. Users of this library that set a duration for a SAS Uri with …
|
NVD-CWE-noinfo
|
CVE-2024-50353
|
2024-11-14 00:15 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|