Количество 26 125
Количество 26 125
CVE-2024-56569
ftrace: Fix regression with module command in stack_trace_filter
CVE-2024-56568
iommu/arm-smmu: Defer probe of clients after smmu device bound
CVE-2024-56567
ad7780: fix division by zero in ad7780_write_raw()
CVE-2024-56566
mm/slub: Avoid list corruption when removing a slab from the full list
CVE-2024-56565
f2fs: fix to drop all discards after creating snapshot on lvm device
CVE-2024-56557
iio: adc: ad7923: Fix buffer overflow for tx_buf and ring_xfer
CVE-2024-56551
drm/amdgpu: fix usage slab after free
CVE-2024-56549
cachefiles: Fix NULL pointer dereference in object->file
CVE-2024-56548
hfsplus: don't query the device logical block size multiple times
CVE-2024-56544
udmabuf: change folios array from kmalloc to kvmalloc
CVE-2024-56538
drm: zynqmp_kms: Unplug DRM device before removal
CVE-2024-56433
shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid.
CVE-2024-5642
Buffer overread when using an empty list with SSLContext.set_npn_protocols()
CVE-2024-56406
Perl is vulnerable to a heap buffer overflow when transliterating non-ASCII bytes
CVE-2024-56369
drm/modes: Avoid divide by zero harder in drm_mode_vrefresh()
CVE-2024-56326
Jinja has a sandbox breakout through indirect reference to format method
CVE-2024-56201
Jinja has a sandbox breakout through malicious filenames
CVE-2024-56171
libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used.
CVE-2024-55916
Drivers: hv: util: Avoid accessing a ringbuffer not initialized yet
CVE-2024-5585
Command injection via array-ish $command parameter of proc_open() (bypass CVE-2024-1874 fix)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2024-56569 ftrace: Fix regression with module command in stack_trace_filter | CVSS3: 5.5 | 0% Низкий | больше 1 года назад | |
CVE-2024-56568 iommu/arm-smmu: Defer probe of clients after smmu device bound | CVSS3: 4.7 | 0% Низкий | больше 1 года назад | |
CVE-2024-56567 ad7780: fix division by zero in ad7780_write_raw() | CVSS3: 5.5 | 0% Низкий | больше 1 года назад | |
CVE-2024-56566 mm/slub: Avoid list corruption when removing a slab from the full list | 0% Низкий | 11 месяцев назад | ||
CVE-2024-56565 f2fs: fix to drop all discards after creating snapshot on lvm device | 0% Низкий | 10 месяцев назад | ||
CVE-2024-56557 iio: adc: ad7923: Fix buffer overflow for tx_buf and ring_xfer | 0% Низкий | 12 месяцев назад | ||
CVE-2024-56551 drm/amdgpu: fix usage slab after free | CVSS3: 7.8 | 0% Низкий | больше 1 года назад | |
CVE-2024-56549 cachefiles: Fix NULL pointer dereference in object->file | 0% Низкий | 12 месяцев назад | ||
CVE-2024-56548 hfsplus: don't query the device logical block size multiple times | CVSS3: 7.8 | 0% Низкий | больше 1 года назад | |
CVE-2024-56544 udmabuf: change folios array from kmalloc to kvmalloc | 0% Низкий | 9 месяцев назад | ||
CVE-2024-56538 drm: zynqmp_kms: Unplug DRM device before removal | CVSS3: 7.8 | 0% Низкий | 6 месяцев назад | |
CVE-2024-56433 shadow-utils (aka shadow) 4.4 through 4.17.0 establishes a default /etc/subuid behavior (e.g., uid 100000 through 165535 for the first user account) that can realistically conflict with the uids of users defined on locally administered networks, potentially leading to account takeover, e.g., by leveraging newuidmap for access to an NFS home directory (or same-host resources in the case of remote logins by these local network users). NOTE: it may also be argued that system administrators should not have assigned uids, within local networks, that are within the range that can occur in /etc/subuid. | CVSS3: 3.6 | 0% Низкий | 12 месяцев назад | |
CVE-2024-5642 Buffer overread when using an empty list with SSLContext.set_npn_protocols() | 1% Низкий | 12 месяцев назад | ||
CVE-2024-56406 Perl is vulnerable to a heap buffer overflow when transliterating non-ASCII bytes | CVSS3: 8.6 | 1% Низкий | больше 1 года назад | |
CVE-2024-56369 drm/modes: Avoid divide by zero harder in drm_mode_vrefresh() | CVSS3: 5.5 | 0% Низкий | больше 1 года назад | |
CVE-2024-56326 Jinja has a sandbox breakout through indirect reference to format method | CVSS3: 7.8 | 1% Низкий | больше 1 года назад | |
CVE-2024-56201 Jinja has a sandbox breakout through malicious filenames | CVSS3: 8.8 | 0% Низкий | больше 1 года назад | |
CVE-2024-56171 libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-after-free in xmlSchemaIDCFillNodeTables and xmlSchemaBubbleIDCNodeTables in xmlschemas.c. To exploit this, a crafted XML document must be validated against an XML schema with certain identity constraints, or a crafted XML schema must be used. | CVSS3: 7.8 | 1% Низкий | больше 1 года назад | |
CVE-2024-55916 Drivers: hv: util: Avoid accessing a ringbuffer not initialized yet | CVSS3: 5.5 | 0% Низкий | 7 дней назад | |
CVE-2024-5585 Command injection via array-ish $command parameter of proc_open() (bypass CVE-2024-1874 fix) | CVSS3: 8.8 | 29% Средний | около 2 лет назад |
Уязвимостей на страницу