|
311931
|
- |
|
-
|
-
|
Deserialization of untrusted data can occur in versions 2.4.0 or newer of the Cleanlab project, enabling a maliciously crafted datalab.pkl file to run arbitrary code on an end user’s system when the …
|
-
|
CVE-2024-45857
|
2024-09-12 22:15 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311932
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
iommu/vt-d: Fix double list_add when enabling VMD in scalable mode
When enabling VMD and IOMMU scalable mode, the following kerne…
|
NVD-CWE-noinfo
|
CVE-2022-48916
|
2024-09-12 22:11 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311933
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
ASoC: ops: Shift tested values in snd_soc_put_volsw() by +min
While the $val/$val2 values passed in from userspace are always >= …
|
NVD-CWE-noinfo
|
CVE-2022-48917
|
2024-09-12 22:07 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311934
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
btrfs: get rid of warning on transaction commit when using flushoncommit
When using the flushoncommit mount option, during almost…
|
CWE-667
Improper Locking
|
CVE-2022-48920
|
2024-09-12 22:04 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311935
|
4.7 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
sched/fair: Fix fault in reweight_entity
Syzbot found a GPF in reweight_entity. This has been bisected to
commit 4ef0c5c6b5ba ("k…
|
CWE-362
Race Condition
|
CVE-2022-48921
|
2024-09-12 21:58 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311936
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
riscv: fix oops caused by irqsoff latency tracer
The trace_hardirqs_{on,off}() require the caller to setup frame pointer
properly…
|
CWE-476
NULL Pointer Dereference
|
CVE-2022-48922
|
2024-09-12 21:52 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311937
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
btrfs: prevent copying too big compressed lzo segment
Compressed length can be corrupted to be a lot larger than memory
we have a…
|
CWE-787
Out-of-bounds Write
|
CVE-2022-48923
|
2024-09-12 21:50 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311938
|
7.2 |
HIGH
Network
|
lifterlms
|
lifterlms
|
The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to blind SQL Injection via the 'order' parameter in all versions up to, and including, 7.7.5 due to …
|
CWE-89
SQL Injection
|
CVE-2024-7349
|
2024-09-12 21:43 |
2024-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311939
|
9.8 |
CRITICAL
Network
|
plechevandrey
|
wp-recall
|
The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to privilege escalation/account takeover in all versions up to, and including, 16.26.8. This is due to to plu…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-8292
|
2024-09-12 21:37 |
2024-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311940
|
- |
|
-
|
-
|
A vulnerability was found in Shandong Star Measurement and Control Equipment Heating Network Wireless Monitoring System 5.6.2 and classified as critical. Affected by this issue is the function GetDat…
|
CWE-89
SQL Injection
|
CVE-2024-8705
|
2024-09-12 21:35 |
2024-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|