2151
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: L2CAP: Fix uaf in l2cap_connect
[Syzbot reported]
BUG: KASAN: slab-use-after-free in l2cap_connect.constprop.0+0x10d8/…
|
CWE-416
Use After Free
|
CVE-2024-49950
|
2024-11-2 00:05 |
2024-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2152
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
ext4: fix double brelse() the buffer of the extents path
In ext4_ext_try_to_merge_up(), set path[1].p_bh to NULL after it has bee…
|
CWE-415
Double Free
|
CVE-2024-49882
|
2024-11-2 00:05 |
2024-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2153
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm/amd/display: Check phantom_stream before it is used
dcn32_enable_phantom_stream can return null, so returned value
must be ch…
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-49897
|
2024-11-1 23:55 |
2024-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2154
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm/xe/guc_submit: add missing locking in wedged_fini
Any non-wedged queue can have a zero refcount here and can be running
concu…
|
CWE-667
Improper Locking
|
CVE-2024-49943
|
2024-11-1 23:54 |
2024-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2155
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
net/ncsi: Disable the ncsi work before freeing the associated structure
The work function can run after the ncsi device is freed,…
|
CWE-416
Use After Free
|
CVE-2024-49945
|
2024-11-1 23:52 |
2024-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2156
|
8.8 |
HIGH
Network
|
aa-team
|
wzone
|
Missing Authorization vulnerability in AA-Team WZone.This issue affects WZone: from n/a through 14.0.10.
|
CWE-862
Missing Authorization
|
CVE-2024-33547
|
2024-11-1 23:45 |
2024-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2157
|
6.3 |
MEDIUM
Network
|
softlabdb
|
integrate_google_drive
|
Missing Authorization vulnerability in SoftLab Integrate Google Drive.This issue affects Integrate Google Drive: from n/a through 1.3.3.
|
CWE-862
Missing Authorization
|
CVE-2023-52177
|
2024-11-1 23:44 |
2024-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2158
|
8.8 |
HIGH
Network
|
8theme
|
xstore_core
|
Missing Authorization vulnerability in 8theme XStore Core.This issue affects XStore Core: from n/a through 5.3.8.
|
CWE-862
Missing Authorization
|
CVE-2024-33555
|
2024-11-1 23:44 |
2024-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2159
|
5.9 |
MEDIUM
Network
|
securesystems
|
connaisseur
|
A vulnerability has been found in Secure Systems Engineering Connaisseur up to 3.3.0 and classified as problematic. This vulnerability affects unknown code of the file connaisseur/res/targets_schema.…
|
CWE-1333
Inefficient Regular Expression Complexity
|
CVE-2023-7279
|
2024-11-1 23:43 |
2024-09-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2160
|
7.5 |
HIGH
Network
wcharczuk
|
go-chart
|
go-chart v2.1.1 was discovered to contain an infinite loop via the drawCanvas() function.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2024-40060
|
2024-11-1 23:42 |
2024-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|