Количество 26 125
Количество 26 125
CVE-2024-52798
path-to-regexp Unpatched `path-to-regexp` ReDoS in 0.1.x
CVE-2024-5274
Chromium: CVE-2024-5274 Type Confusion in V8
CVE-2024-52616
Avahi: avahi wide-area dns predictable transaction ids
CVE-2024-52560
fs/ntfs3: Mark inode as bad as soon as error detected in mi_enum_attr()
CVE-2024-52559
drm/msm/gem: prevent integer overflow in msm_ioctl_gem_submit()
CVE-2024-52533
gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufficient for a trailing '\0' character.
CVE-2024-52532
GNOME libsoup before 3.6.1 has an infinite loop and memory consumption. during the reading of certain patterns of WebSocket data from clients.
CVE-2024-52531
GNOME libsoup before 3.6.1 allows a buffer overflow in applications that perform conversion to UTF-8 in soup_header_parse_param_list_strict.
CVE-2024-52530
GNOME libsoup before 3.6.0 allows HTTP request smuggling in some configurations
CVE-2024-52338
Apache Arrow R package: Arbitrary code execution when loading a malicious data file
CVE-2024-52337
Tuned: improper sanitization of `instance_name` parameter of the `instance_create()` method
CVE-2024-52336
Tuned: `script_pre` and `script_post` options allow to pass arbitrary scripts executed by root
CVE-2024-52308
Connecting to a malicious Codespaces via GH CLI could allow command execution on the user's computer
CVE-2024-52006
Newline confusion in credential helpers can lead to credential exfiltration in git
CVE-2024-52005
The sideband payload is passed unfiltered to the terminal in git
CVE-2024-5197
Integer overflow in libvpx
CVE-2024-5187
CVE-2024-51756
cap-std doesn't fully sandbox all the Windows device filenames
CVE-2024-51744
Bad documentation of error handling in ParseWithClaims can lead to potentially dangerous situations in golang-jwt
CVE-2024-51741
Redis allows denial-of-service due to malformed ACL selectors
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2024-52798 path-to-regexp Unpatched `path-to-regexp` ReDoS in 0.1.x | 1% Низкий | больше 1 года назад | ||
CVE-2024-5274 Chromium: CVE-2024-5274 Type Confusion in V8 | 7% Низкий | около 2 лет назад | ||
CVE-2024-52616 Avahi: avahi wide-area dns predictable transaction ids | CVSS3: 5.3 | 1% Низкий | больше 1 года назад | |
CVE-2024-52560 fs/ntfs3: Mark inode as bad as soon as error detected in mi_enum_attr() | 0% Низкий | 12 месяцев назад | ||
CVE-2024-52559 drm/msm/gem: prevent integer overflow in msm_ioctl_gem_submit() | CVSS3: 7.8 | 0% Низкий | 6 месяцев назад | |
CVE-2024-52533 gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufficient for a trailing '\0' character. | CVSS3: 9.8 | 1% Низкий | почти 2 года назад | |
CVE-2024-52532 GNOME libsoup before 3.6.1 has an infinite loop and memory consumption. during the reading of certain patterns of WebSocket data from clients. | CVSS3: 7.5 | 1% Низкий | больше 1 года назад | |
CVE-2024-52531 GNOME libsoup before 3.6.1 allows a buffer overflow in applications that perform conversion to UTF-8 in soup_header_parse_param_list_strict. | CVSS3: 8.4 | 1% Низкий | больше 1 года назад | |
CVE-2024-52530 GNOME libsoup before 3.6.0 allows HTTP request smuggling in some configurations | CVSS3: 7.5 | 1% Низкий | 7 дней назад | |
CVE-2024-52338 Apache Arrow R package: Arbitrary code execution when loading a malicious data file | CVSS3: 9.8 | 2% Низкий | больше 1 года назад | |
CVE-2024-52337 Tuned: improper sanitization of `instance_name` parameter of the `instance_create()` method | CVSS3: 5.5 | 0% Низкий | больше 1 года назад | |
CVE-2024-52336 Tuned: `script_pre` and `script_post` options allow to pass arbitrary scripts executed by root | CVSS3: 7.8 | 0% Низкий | 7 дней назад | |
CVE-2024-52308 Connecting to a malicious Codespaces via GH CLI could allow command execution on the user's computer | CVSS3: 8 | 1% Низкий | 6 месяцев назад | |
CVE-2024-52006 Newline confusion in credential helpers can lead to credential exfiltration in git | 1% Низкий | больше 1 года назад | ||
CVE-2024-52005 The sideband payload is passed unfiltered to the terminal in git | 1% Низкий | 9 дней назад | ||
CVE-2024-5197 Integer overflow in libvpx | 1% Низкий | 12 месяцев назад | ||
CVSS3: 8.8 | 1% Низкий | почти 2 года назад | ||
CVE-2024-51756 cap-std doesn't fully sandbox all the Windows device filenames | 1% Низкий | 12 месяцев назад | ||
CVE-2024-51744 Bad documentation of error handling in ParseWithClaims can lead to potentially dangerous situations in golang-jwt | CVSS3: 3.1 | 1% Низкий | больше 1 года назад | |
CVE-2024-51741 Redis allows denial-of-service due to malformed ACL selectors | CVSS3: 4.4 | 0% Низкий | 6 месяцев назад |
Уязвимостей на страницу