931
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
fork: only invoke khugepaged, ksm hooks if no error
There is no reason to invoke these hooks early against an mm that is in an
in…
|
NVD-CWE-noinfo
|
CVE-2024-50263
|
2024-11-15 01:23 |
2024-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
932
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
riscv/purgatory: align riscv_kernel_entry
When alignment handling is delegated to the kernel, everything must be
word-aligned in …
|
-
|
CVE-2024-43868
|
2024-11-15 01:15 |
2024-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
933
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
ice: Add a per-VF limit on number of FDIR filters
While the iavf driver adds a s/w limit (128) on the number of FDIR
filters that…
|
-
|
CVE-2024-42291
|
2024-11-15 01:15 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
934
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
net: sched: use RCU read-side critical section in taprio_dump()
Fix possible use-after-free in 'taprio_dump()' by adding RCU
read…
|
CWE-416
Use After Free
|
CVE-2024-50126
|
2024-11-15 01:15 |
2024-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
935
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
bnxt_re: avoid shift undefined behavior in bnxt_qplib_alloc_init_hwq
Undefined behavior is triggered when bnxt_qplib_alloc_init_h…
|
-
|
CVE-2024-38540
|
2024-11-15 01:15 |
2024-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
936
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
fs/ntfs3: Additional check in ntfs_file_release
|
NVD-CWE-noinfo
|
CVE-2024-50242
|
2024-11-15 01:12 |
2024-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
937
|
5.4 |
MEDIUM
Network
|
sap
|
netweaver_enterprise_portal
|
SAP NetWeaver Enterprise Portal (KMC) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting vulnerability in KMC servlet. An attacker could craft a script and trick t…
|
CWE-79
Cross-site Scripting
|
CVE-2024-47594
|
2024-11-15 01:12 |
2024-10-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
938
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
phy: qcom: qmp-usb: fix NULL-deref on runtime suspend
Commit 413db06c05e7 ("phy: qcom-qmp-usb: clean up probe initialisation")
re…
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-50240
|
2024-11-15 00:57 |
2024-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
939
|
5.4 |
MEDIUM
Network
|
ampache
|
ampache
|
Ampache is a web based audio/video streaming application and file manager. The current implementation of token parsing does not adequately validate CSRF tokens when users send messages to one another…
|
CWE-352
Origin Validation Error
|
CVE-2024-51489
|
2024-11-15 00:46 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
940
|
9.0 |
CRITICAL
Network
|
ampache
|
ampache
|
Ampache is a web based audio/video streaming application and file manager. This vulnerability exists in the interface section of the Ampache menu, where users can change "Custom URL - Logo". This sec…
|
CWE-79
Cross-site Scripting
|
CVE-2024-51490
|
2024-11-15 00:30 |
2024-11-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|