Количество 26 125
Количество 26 125
CVE-2024-53920
In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrary code. (This unsafe expansion also occurs if a user chooses to enable on-the-fly diagnosis that byte compiles untrusted Emacs Lisp source code.)
CVE-2024-53899
virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287.
CVE-2024-53859
go-gh `auth.TokenForHost` violates GitHub host security boundary within a codespace
CVE-2024-53858
Recursive repository cloning can leak authentication tokens to non-GitHub submodule hosts in the gh cli
CVE-2024-53846
ssl fails to validate incorrect extened key usage
CVE-2024-53687
riscv: Fix IPIs usage in kfence_protect_page()
CVE-2024-53589
GNU objdump 2.43 is vulnerable to Buffer Overflow in the BFD (Binary File Descriptor) library's handling of tekhex format files.
CVE-2024-53580
iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function.
CVE-2024-53427
decNumberCopy in decNumber.c in jq through 1.7.1 does not properly consider that NaN is interpreted as numeric, which has a resultant stack-based buffer overflow and out-of-bounds write, as demonstrated by use of --slurp with subtraction, such as a filter of .-. when the input has a certain form of digit string with NaN (e.g., "1 NaN123" immediately followed by many more digits).
CVE-2024-53426
A heap-buffer-overflow vulnerability has been identified in ntopng 6.2 in the Flow::dissectMDNS function.
CVE-2024-53263
Git LFS permits exfiltration of credentials via crafted HTTP URLs
CVE-2024-53259
quic-go affected by an ICMP Packet Too Large Injection Attack on Linux
CVE-2024-53257
Vitess allows HTML injection in /debug/querylogz & /debug/env
CVE-2024-53239
ALSA: 6fire: Release resources at card release
CVE-2024-53237
Bluetooth: fix use-after-free in device_for_each_child()
CVE-2024-53234
erofs: handle NONHEAD !delta[1] lclusters gracefully
CVE-2024-53231
cpufreq: CPPC: Fix possible null-ptr-deref for cpufreq_cpu_get_raw()
CVE-2024-53230
cpufreq: CPPC: Fix possible null-ptr-deref for cppc_get_cpu_cost()
CVE-2024-53227
scsi: bfa: Fix use-after-free in bfad_im_module_exit()
CVE-2024-53226
RDMA/hns: Fix NULL pointer derefernce in hns_roce_map_mr_sg()
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2024-53920 In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invoke elisp-completion-at-point (for code completion) on untrusted Emacs Lisp source code can trigger unsafe Lisp macro expansion that allows attackers to execute arbitrary code. (This unsafe expansion also occurs if a user chooses to enable on-the-fly diagnosis that byte compiles untrusted Emacs Lisp source code.) | CVSS3: 7.8 | 1% Низкий | больше 1 года назад | |
CVE-2024-53899 virtualenv before 20.26.6 allows command injection through the activation scripts for a virtual environment. Magic template strings are not quoted correctly when replacing. NOTE: this is not the same as CVE-2024-9287. | CVSS3: 8.4 | 2% Низкий | больше 1 года назад | |
CVE-2024-53859 go-gh `auth.TokenForHost` violates GitHub host security boundary within a codespace | CVSS3: 6.5 | 1% Низкий | больше 1 года назад | |
CVE-2024-53858 Recursive repository cloning can leak authentication tokens to non-GitHub submodule hosts in the gh cli | CVSS3: 6.5 | 0% Низкий | больше 1 года назад | |
CVE-2024-53846 ssl fails to validate incorrect extened key usage | CVSS3: 5.5 | 0% Низкий | 6 месяцев назад | |
CVE-2024-53687 riscv: Fix IPIs usage in kfence_protect_page() | 0% Низкий | 10 месяцев назад | ||
CVE-2024-53589 GNU objdump 2.43 is vulnerable to Buffer Overflow in the BFD (Binary File Descriptor) library's handling of tekhex format files. | 0% Низкий | 12 месяцев назад | ||
CVE-2024-53580 iperf v3.17.1 was discovered to contain a segmentation violation via the iperf_exchange_parameters() function. | CVSS3: 7.5 | 1% Низкий | больше 1 года назад | |
CVE-2024-53427 decNumberCopy in decNumber.c in jq through 1.7.1 does not properly consider that NaN is interpreted as numeric, which has a resultant stack-based buffer overflow and out-of-bounds write, as demonstrated by use of --slurp with subtraction, such as a filter of .-. when the input has a certain form of digit string with NaN (e.g., "1 NaN123" immediately followed by many more digits). | CVSS3: 8.1 | 0% Низкий | больше 1 года назад | |
CVE-2024-53426 A heap-buffer-overflow vulnerability has been identified in ntopng 6.2 in the Flow::dissectMDNS function. | 0% Низкий | 6 месяцев назад | ||
CVE-2024-53263 Git LFS permits exfiltration of credentials via crafted HTTP URLs | 1% Низкий | больше 1 года назад | ||
CVE-2024-53259 quic-go affected by an ICMP Packet Too Large Injection Attack on Linux | CVSS3: 6.5 | 1% Низкий | больше 1 года назад | |
CVE-2024-53257 Vitess allows HTML injection in /debug/querylogz & /debug/env | CVSS3: 4.9 | 0% Низкий | больше 1 года назад | |
CVE-2024-53239 ALSA: 6fire: Release resources at card release | CVSS3: 7.8 | 0% Низкий | больше 1 года назад | |
CVE-2024-53237 Bluetooth: fix use-after-free in device_for_each_child() | CVSS3: 7.8 | 0% Низкий | больше 1 года назад | |
CVE-2024-53234 erofs: handle NONHEAD !delta[1] lclusters gracefully | 0% Низкий | 10 месяцев назад | ||
CVE-2024-53231 cpufreq: CPPC: Fix possible null-ptr-deref for cpufreq_cpu_get_raw() | 0% Низкий | больше 1 года назад | ||
CVE-2024-53230 cpufreq: CPPC: Fix possible null-ptr-deref for cppc_get_cpu_cost() | CVSS3: 5.5 | 0% Низкий | больше 1 года назад | |
CVE-2024-53227 scsi: bfa: Fix use-after-free in bfad_im_module_exit() | CVSS3: 7.8 | 0% Низкий | больше 1 года назад | |
CVE-2024-53226 RDMA/hns: Fix NULL pointer derefernce in hns_roce_map_mr_sg() | CVSS3: 5.5 | 1% Низкий | больше 1 года назад |
Уязвимостей на страницу