2291
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
ocfs2: fix slab-use-after-free due to dangling pointer dqi_priv
When mounting ocfs2 and then remounting it as read-only, a
slab-u…
|
CWE-416
Use After Free
|
CVE-2024-57892
|
2025-01-22 02:41 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2292
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
RDMA/uverbs: Prevent integer overflow issue
In the expression "cmd.wqe_size * cmd.wr_count", both variables are u32
values that c…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2024-57890
|
2025-01-22 02:41 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2293
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
drm: adv7511: Fix use-after-free in adv7533_attach_dsi()
The host_node pointer was assigned and freed in adv7533_parse_dt(), and
…
|
CWE-416
Use After Free
|
CVE-2024-57887
|
2025-01-22 02:40 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2294
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
mptcp: fix TCP options overflow.
Syzbot reported the following splat:
Oops: general protection fault, probably for non-canonical…
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-57882
|
2025-01-22 02:39 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2295
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
net: fix memory leak in tcp_conn_request()
If inet_csk_reqsk_queue_hash_add() return false, tcp_conn_request() will
return withou…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2024-57841
|
2025-01-22 02:38 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2296
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
netrom: check buffer length before accessing it
Syzkaller reports an uninit value read from ax25cmp when sending raw message
thro…
|
CWE-908
Use of Uninitialized Resource
|
CVE-2024-57802
|
2025-01-22 02:16 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2297
|
- |
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
-
|
CVE-2025-0623
|
2025-01-22 02:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2298
|
- |
|
-
|
-
|
Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') vulnerability in Payara Platform Payara Server (Grizzly, REST Management Interface modules), Payara Platf…
|
-
|
CVE-2024-45687
|
2025-01-22 02:15 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2299
|
- |
|
-
|
-
|
In onCreate of EmergencyCallbackModeExitDialog.java, there is a possible way to crash the emergency callback mode due to a missing null check. This could lead to local denial of service with no addit…
|
-
|
CVE-2018-9447
|
2025-01-22 02:15 |
2025-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
2300
|
- |
|
-
|
-
|
In multiple functions of Parcel.cpp, there is a possible way to bypass address space layout randomization. This could lead to local escalation of privilege with no additional execution privileges nee…
|
-
|
CVE-2018-9434
|
2025-01-22 02:15 |
2025-01-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|