101
|
- |
|
-
|
-
|
BigFix Patch Download Plug-ins are affected by an insecure package which is susceptible to XML injection attacks. This allows an attacker to exploit this vulnerability by injecting malicious XML con…
New
|
-
|
CVE-2024-42185
|
2025-01-23 12:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
102
|
- |
|
-
|
-
|
BigFix Patch Download Plug-ins are affected by insecure support for file URI scheme. It could allow a malicious operator to attempt to download files using the file:// URI scheme.
New
|
-
|
CVE-2024-42184
|
2025-01-23 12:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
103
|
6.4 |
MEDIUM
Network
|
-
|
-
|
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus alt…
New
|
CWE-79
Cross-site Scripting
|
CVE-2023-50309
|
2025-01-23 12:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
104
|
4.6 |
MEDIUM
Network
|
-
|
-
|
IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.5 and 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering t…
New
|
CWE-79
Cross-site Scripting
|
CVE-2023-32340
|
2025-01-23 12:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
105
|
- |
|
-
|
-
|
BigFix Patch Download Plug-ins are affected by an arbitrary file download vulnerability. It could allow a malicious operator to download files from arbitrary URLs without any proper validation or al…
New
|
-
|
CVE-2024-42183
|
2025-01-23 11:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
106
|
- |
|
-
|
-
|
BigFix Patch Download Plug-ins are affected by Server-Side Request Forgery (SSRF) vulnerability. It may allow the application to download files from an internally hosted server on localhost.
New
|
-
|
CVE-2024-42182
|
2025-01-23 10:15 |
2025-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
107
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
iio: adc: ti-ads1298: Add NULL check in ads1298_init
devm_kasprintf() can return a NULL pointer on failure. A check on the
return…
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-57944
|
2025-01-23 08:02 |
2025-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
108
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
btrfs: avoid NULL pointer dereference if no valid extent tree
[BUG]
Syzbot reported a crash with the following call trace:
BTR…
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2025-21658
|
2025-01-23 08:02 |
2025-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
109
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
exfat: fix the infinite loop in exfat_readdir()
If the file system is corrupted so that a cluster is linked to
itself in the clus…
New
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2024-57940
|
2025-01-23 08:02 |
2025-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
110
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
net/sctp: Prevent autoclose integer overflow in sctp_association_init()
While by default max_autoclose equals to INT_MAX / HZ, on…
New
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2024-57938
|
2025-01-23 08:01 |
2025-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|