51
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm/sti: avoid potential dereference of error pointers
The return value of drm_atomic_get_crtc_state() needs to be
checked. To av…
New
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2024-56776
|
2025-01-10 06:41 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
52
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Fix handling of plane refcount
[Why]
The mechanism to backup and restore plane states doesn't maintain
refcount,…
New
|
CWE-415 CWE-401
Double Free Missing Release of Memory after Effective Lifetime
|
CVE-2024-56775
|
2025-01-10 06:37 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
53
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
soc: imx8m: Probe the SoC driver as platform driver
With driver_async_probe=* on kernel command line, the following trace is
prod…
New
|
NVD-CWE-noinfo
|
CVE-2024-56787
|
2025-01-10 06:28 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
54
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
MIPS: Loongson64: DTS: Really fix PCIe port nodes for ls7a
Fix the dtc warnings:
arch/mips/boot/dts/loongson/ls7a-pch.dtsi:6…
New
|
NVD-CWE-noinfo
|
CVE-2024-56785
|
2025-01-10 06:27 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
55
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Adding array index check to prevent memory corruption
[Why & How]
Array indices out of bound caused memory corru…
New
|
CWE-787
Out-of-bounds Write
|
CVE-2024-56784
|
2025-01-10 06:25 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
56
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nft_socket: remove WARN_ON_ONCE on maximum cgroup level
cgroup maximum depth is INT_MAX by default, there is a cgroup …
New
|
CWE-617
Reachable Assertion
|
CVE-2024-56783
|
2025-01-10 06:24 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
57
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
powerpc/prom_init: Fixup missing powermac #size-cells
On some powermacs `escc` nodes are missing `#size-cells` properties,
which …
New
|
NVD-CWE-noinfo
|
CVE-2024-56781
|
2025-01-10 06:21 |
2025-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
58
|
- |
|
-
|
-
|
Vaultwarden v1.32.5 was discovered to contain an authenticated reflected cross-site scripting (XSS) vulnerability via the component /api/core/mod.rs.
New
|
-
|
CVE-2024-55226
|
2025-01-10 06:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
59
|
- |
|
-
|
-
|
An issue in the component src/api/identity.rs of Vaultwarden prior to v1.32.5 allows attackers to impersonate users, including Administrators, via a crafted authorization request.
New
|
-
|
CVE-2024-55225
|
2025-01-10 06:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
60
|
- |
|
-
|
-
|
An HTML injection vulnerability in Vaultwarden prior to v1.32.5 allows attackers to execute arbitrary code via injecting a crafted payload into the username field of an e-mail message.
New
|
-
|
CVE-2024-55224
|
2025-01-10 06:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|