1151
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm/connector: hdmi: Fix memory leak in drm_display_mode_from_cea_vic()
modprobe drm_connector_test and then rmmod drm_connector_…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2024-50214
|
2024-11-14 02:25 |
2024-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1152
|
4.3 |
MEDIUM
Network
|
northern.tech
|
mender
|
Northern.tech Mender before 3.6.5 and 3.7.x before 3.7.5 has Incorrect Access Control.
|
NVD-CWE-Other
|
CVE-2024-46948
|
2024-11-14 02:18 |
2024-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1153
|
6.5 |
MEDIUM
Network
|
openc3
|
cosmos
|
OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. OpenC3 COSMOS stores the password of a user unencrypted in the LocalStorage of …
|
-
|
CVE-2024-47529
|
2024-11-14 02:15 |
2024-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1154
|
5.9 |
MEDIUM
Network
|
redhat
|
kroxylicious
|
A flaw was found in Kroxylicious. When establishing the connection with the upstream Kafka server using a TLS secured connection, Kroxylicious fails to properly verify the server's hostname, resultin…
|
CWE-295
Improper Certificate Validation
|
CVE-2024-8285
|
2024-11-14 02:15 |
2024-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1155
|
7.5 |
HIGH
Network
bakerhughes
|
bentley_nevada_3500_system_firmware
|
Baker Hughes – Bently Nevada 3500 System TDI Firmware version 5.05
contains a vulnerability in their password retrieval functionality which could allow an attacker to access passwords stored on the…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2023-34437
|
2024-11-14 02:15 |
2023-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1156
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
wifi: rtw89: avoid to add interface to list twice when SER
If SER L2 occurs during the WoWLAN resume flow, the add interface flow…
|
NVD-CWE-noinfo
|
CVE-2024-49939
|
2024-11-14 02:04 |
2024-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1157
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
wifi: cfg80211: Set correct chandef when starting CAC
When starting CAC in a mode other than AP mode, it return a
"WARNING: CPU: …
|
NVD-CWE-noinfo
|
CVE-2024-49937
|
2024-11-14 02:02 |
2024-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1158
|
- |
|
-
|
-
|
In Progress Telerik Document Processing Libraries, versions prior to 2024 Q4 (2024.4.1106), importing a document with unsupported features can lead to excessive processing, leading to excessive use o…
|
CWE-834
Excessive Iteration
|
CVE-2024-8049
|
2024-11-14 02:01 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1159
|
- |
|
-
|
-
|
In Progress® Telerik® Report Server versions prior to 2024 Q4 (10.3.24.1112), the encryption of local asset data used an older algorithm which may allow a sophisticated actor to decrypt this informat…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2024-7295
|
2024-11-14 02:01 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1160
|
- |
|
-
|
-
|
FileManager provides a Backpack admin interface for files and folder. Prior to 3.0.9, deserialization of untrusted data from the mimes parameter could lead to remote code execution. This vulnerabilit…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-52306
|
2024-11-14 02:01 |
2024-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|