961
|
7.0 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
tcp/dccp: Don't use timer_pending() in reqsk_queue_unlink().
Martin KaFai Lau reported use-after-free [0] in reqsk_timer_handler(…
Update
|
CWE-416
Use After Free
|
CVE-2024-50154
|
2024-11-14 01:17 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
962
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
net/sun3_82586: fix potential memory leak in sun3_82586_send_packet()
The sun3_82586_send_packet() returns NETDEV_TX_OK without f…
Update
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2024-50168
|
2024-11-14 01:16 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
963
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
ALSA: hda/cs8409: Fix possible NULL dereference
If snd_hda_gen_add_kctl fails to allocate memory and returns NULL, then
NULL poin…
Update
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-50160
|
2024-11-14 01:13 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
964
|
6.5 |
MEDIUM
Adjacent
|
zephyrproject
|
zephyr
|
In ascs_cp_rsp_add in /subsys/bluetooth/audio/ascs.c, an unchecked tailroom could lead to a global buffer overflow.
Update
|
CWE-787
Out-of-bounds Write
|
CVE-2024-6442
|
2024-11-14 01:04 |
2024-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
965
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
RDMA/bnxt_re: Fix a possible memory leak
In bnxt_re_setup_chip_ctx() when bnxt_qplib_map_db_bar() fails
driver is not freeing the…
Update
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2024-50172
|
2024-11-14 00:55 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
966
|
- |
|
-
|
-
|
The fetch(3) library uses environment variables for passing certain information, including the revocation file pathname. The environment variable name used by fetch(1) to pass the filename to the li…
New
|
-
|
CVE-2024-45289
|
2024-11-14 00:35 |
2024-11-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
967
|
- |
|
-
|
-
|
File Upload vulnerability in Laravel CMS v.1.4.7 and before allows a remote attacker to execute arbitrary code via the shell.php a component.
Update
|
-
|
CVE-2024-51152
|
2024-11-14 00:35 |
2024-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
968
|
- |
|
-
|
-
|
An incorrect access control issue in Life: Personal Diary, Journal android app 17.5.0 allows a physically proximate attacker to escalate privileges via the fingerprint authentication function.
Update
|
-
|
CVE-2024-40239
|
2024-11-14 00:35 |
2024-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
969
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
be2net: fix potential memory leak in be_xmit()
The be_xmit() returns NETDEV_TX_OK without freeing skb
in case of be_xmit_enqueue(…
Update
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2024-50167
|
2024-11-14 00:29 |
2024-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
970
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
wifi: ath9k_htc: Use __skb_set_length() for resetting urb before resubmit
Syzbot points out that skb_trim() has a sanity check on…
Update
|
CWE-824
Access of Uninitialized Pointer
|
CVE-2024-49938
|
2024-11-14 00:25 |
2024-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|