401
|
8.8 |
HIGH
Network
|
liferay
|
digital_experience_platform liferay_portal
|
The workflow component in Liferay Portal 7.3.2 through 7.4.3.111, and Liferay DXP 2023.Q4.0 through 2023.Q4.5, 2023.Q3.1 through 2023.Q3.8, 7.4 GA through update 92 and 7.3 GA through update 36 does …
Update
|
CWE-863
Incorrect Authorization
|
CVE-2024-38002
|
2024-10-30 23:47 |
2024-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
402
|
7.0 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
ksmbd: fix user-after-free from session log off
There is racy issue between smb2 session log off and smb2 session setup.
It will …
New
|
CWE-416
Use After Free
|
CVE-2024-50086
|
2024-10-30 23:46 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
403
|
6.1 |
MEDIUM
Network
|
liferay
|
digital_experience_platform liferay_portal
|
The Script Console in Liferay Portal 7.0.0 through 7.4.3.101, and Liferay DXP 2023.Q3.1 through 2023.Q3.4, 7.4 GA through update 92, 7.3 GA through update 35, 7.2 GA through fix pack 20, 7.1 GA throu…
Update
|
CWE-352
Origin Validation Error
|
CVE-2024-8980
|
2024-10-30 23:46 |
2024-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
404
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
btrfs: fix uninitialized pointer free on read_alloc_one_name() error
The function read_alloc_one_name() does not initialize the n…
New
|
CWE-824
Access of Uninitialized Pointer
|
CVE-2024-50087
|
2024-10-30 23:40 |
2024-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
405
|
- |
|
-
|
-
|
In Eclipse Mosquito, versions from 2.0.0 through 2.0.18, if a Mosquitto broker is configured to create an outgoing bridge connection, and that bridge connection has an incoming topic configured that …
New
|
-
|
CVE-2024-3935
|
2024-10-30 23:35 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
406
|
- |
|
-
|
-
|
In Eclipse Mosquitto, from version 1.3.2 through 2.0.18, if a malicious broker sends a crafted SUBACK packet with no reason codes, a client using libmosquitto may make out of bounds memory access whe…
New
|
-
|
CVE-2024-10525
|
2024-10-30 23:35 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
407
|
- |
|
-
|
-
|
CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecutioner() sink. There is /filemanager/upload (aka File Manager upload) unauthenti…
New
|
-
|
CVE-2024-51568
|
2024-10-30 23:35 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
408
|
- |
|
-
|
-
|
upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstat…
New
|
-
|
CVE-2024-51567
|
2024-10-30 23:35 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
409
|
- |
|
-
|
-
|
Use after free in WebRTC in Google Chrome prior to 130.0.6723.92 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
New
|
-
|
CVE-2024-10488
|
2024-10-30 23:35 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
410
|
- |
|
-
|
-
|
Out of bounds write in Dawn in Google Chrome prior to 130.0.6723.92 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical)
New
|
-
|
CVE-2024-10487
|
2024-10-30 23:35 |
2024-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|