911
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
f2fs: fix to don't dirty inode for readonly filesystem
syzbot reports f2fs bug as below:
kernel BUG at fs/f2fs/inode.c:933!
RIP:…
|
NVD-CWE-noinfo
|
CVE-2024-42297
|
2024-09-30 22:41 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
912
|
6.1 |
MEDIUM
Network
|
oveleon
|
cookiebar
|
Oveleon Cookie Bar is a cookie bar is for the Contao Open Source CMS and allows a visitor to define cookie & privacy settings for the website. Prior to versions 1.16.3 and 2.1.3, the `block/locale` e…
|
CWE-79
Cross-site Scripting
|
CVE-2024-47069
|
2024-09-30 22:40 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
913
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
sched: act_ct: take care of padding in struct zones_ht_key
Blamed commit increased lookup key size from 2 bytes to 16 bytes,
beca…
|
CWE-908
Use of Uninitialized Resource
|
CVE-2024-42272
|
2024-09-30 22:40 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
914
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
Squashfs: sanity check symbolic link size
Syzkiller reports a "KMSAN: uninit-value in pick_link" bug.
This is caused by an unini…
|
CWE-59
Link Following
|
CVE-2024-46744
|
2024-09-30 22:36 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
915
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
PCI: Add missing bridge lock to pci_bus_lock()
One of the true positives that the cfg_access_lock lockdep effort
identified is th…
|
CWE-667
Improper Locking
|
CVE-2024-46750
|
2024-09-30 22:27 |
2024-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
916
|
- |
|
-
|
-
|
Cross Application Scripting vulnerability in Vercom S.A. Redlink SDK in specific situations allows local code injection and to manipulate the view of a vulnerable application.This issue affects Redli…
|
-
|
CVE-2024-6051
|
2024-09-30 22:15 |
2024-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
917
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WPDeveloperr Confetti Fall Animation allows Stored XSS.This issue affects Confetti Fall An…
|
CWE-79
Cross-site Scripting
|
CVE-2024-47641
|
2024-09-30 22:15 |
2024-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
918
|
- |
|
-
|
-
|
A Stored Cross-Site Scripting (XSS) vulnerability in Solvait 24.4.2 allows remote attackers to inject malicious scripts into the application. This issue arises due to insufficient input validation an…
|
-
|
CVE-2024-45920
|
2024-09-30 22:15 |
2024-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
919
|
6.1 |
MEDIUM
Network
|
ruoyi
|
ruoyi
|
A vulnerability was found in y_project RuoYi up to 4.7.9. It has been declared as problematic. Affected by this vulnerability is the function SysUserServiceImpl of the file ruoyi-system/src/main/java…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9048
|
2024-09-30 22:00 |
2024-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
920
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
s390/dasd: fix error checks in dasd_copy_pair_store()
dasd_add_busid() can return an error via ERR_PTR() if an allocation
fails. …
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-42320
|
2024-09-30 21:54 |
2024-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|