401
|
9.8 |
CRITICAL
Network
esafenet
|
cdg
|
A vulnerability classified as critical has been found in ESAFENET CDG 5. Affected is the function actionViewCDGRenewFile of the file /com/esafenet/servlet/client/CDGRenewApplicationService.java. The …
Update
|
CWE-89
SQL Injection
|
CVE-2024-10378
|
2024-10-31 08:58 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
402
|
6.5 |
MEDIUM
Local
|
-
|
-
|
A vulnerability was found in Golang FIPS OpenSSL. This flaw allows a malicious user to randomly cause an uninitialized buffer length variable with a zeroed buffer to be returned in FIPS mode. It may …
Update
|
CWE-457
Use of Uninitialized Variable
|
CVE-2024-9355
|
2024-10-31 08:15 |
2024-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
403
|
- |
|
-
|
-
|
A vulnerability was identified in Consul and Consul Enterprise such that the server response did not explicitly set a Content-Type HTTP header, allowing user-provided inputs to be misinterpreted and …
New
|
-
|
CVE-2024-10086
|
2024-10-31 07:15 |
2024-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
404
|
- |
|
-
|
-
|
A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using Headers in L7 traffic intentions could bypass HTTP header based access rules.
New
|
-
|
CVE-2024-10006
|
2024-10-31 07:15 |
2024-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
405
|
- |
|
-
|
-
|
A vulnerability was identified in Consul and Consul Enterprise (“Consul”) such that using URL paths in L7 traffic intentions could bypass HTTP request path-based access rules.
New
|
-
|
CVE-2024-10005
|
2024-10-31 07:15 |
2024-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
406
|
0.0 |
NONE
Physics
|
-
|
-
|
Rejected reason: Red Hat Product Security has come to the conclusion that this CVE is not needed.
Update
|
-
|
CVE-2024-8421
|
2024-10-31 07:15 |
2024-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
407
|
4.7 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
net: dsa: improve shutdown sequence
Alexander Sverdlin presents 2 problems during shutdown with the
lan9303 driver. One is specif…
Update
|
CWE-476 CWE-367
NULL Pointer Dereference Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2024-49998
|
2024-10-31 07:04 |
2024-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
408
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
net/mlx5: Fix error path in multi-packet WQE transmit
Remove the erroneous unmap in case no DMA mapping was established
The mult…
Update
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2024-50001
|
2024-10-31 06:59 |
2024-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
409
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
static_call: Handle module init failure correctly in static_call_del_module()
Module insertion invokes static_call_add_module() t…
Update
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2024-50002
|
2024-10-31 06:57 |
2024-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
410
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
btrfs: qgroup: fix sleep from invalid context bug in btrfs_qgroup_inherit()
Syzkaller reported BUG as follows:
BUG: sleeping f…
Update
|
NVD-CWE-noinfo
|
CVE-2022-49033
|
2024-10-31 06:50 |
2024-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|