Количество 26 125
Количество 26 125
CVE-2024-5171
heap buffer overflow in libaom
CVE-2024-5160
Chromium: CVE-2024-5160 Heap buffer overflow in Dawn
CVE-2024-5159
Chromium: CVE-2024-5159 Heap buffer overflow in ANGLE
CVE-2024-5158
Chromium: CVE-2024-5158 Type Confusion in V8
CVE-2024-5157
Chromium: CVE-2024-5157 Use after free in Scheduling
CVE-2024-50615
TinyXML2 through 10.0.0 has a reachable assertion for UINT_MAX/digit, that may lead to application exit, in tinyxml2.cpp XMLUtil::GetCharacterRef.
CVE-2024-50614
TinyXML2 through 10.0.0 has a reachable assertion for UINT_MAX/16, that may lead to application exit, in tinyxml2.cpp XMLUtil::GetCharacterRef.
CVE-2024-50613
libsndfile through 1.2.2 has a reachable assertion, that may lead to application exit, in mpeg_l3_encode.c mpeg_l3_encoder_close.
CVE-2024-50612
libsndfile through 1.2.2 has an ogg_vorbis.c vorbis_analysis_wrote out-of-bounds read.
CVE-2024-50609
An issue was discovered in Fluent Bit 3.1.9. When the OpenTelemetry input plugin is running and listening on an IP address and port, one can send a packet with Content-Length: 0 and it crashes the server. Improper handling of the case when Content-Length is 0 allows a user (with access to the endpoint) to perform a remote Denial of service attack. The crash happens because of a NULL pointer dereference when 0 (from the Content-Length) is passed to the function cfl_sds_len, which in turn tries to cast a NULL pointer into struct cfl_sds. This is related to process_payload_traces_proto_ng() at opentelemetry_prot.c.
CVE-2024-50608
An issue was discovered in Fluent Bit 3.1.9. When the Prometheus Remote Write input plugin is running and listening on an IP address and port, one can send a packet with Content-Length: 0 and it crashes the server. Improper handling of the case when Content-Length is 0 allows a user (with access to the endpoint) to perform a remote Denial of service attack. The crash happens because of a NULL pointer dereference when 0 (from the Content-Length) is passed to the function cfl_sds_len, which in turn tries to cast a NULL pointer into struct cfl_sds. This is related to process_payload_metrics_ng() at prom_rw_prot.c.
CVE-2024-50602
An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser.
CVE-2024-50349
Git does not sanitize URLs when asking for credentials interactively
CVE-2024-50338
GitHub: CVE-2024-50338 Malformed URL allows information disclosure through git-credential-manager
CVE-2024-50304
ipv4: ip_tunnel: Fix suspicious RCU usage warning in ip_tunnel_find()
CVE-2024-50302
HID: core: zero-initialize the report buffer
CVE-2024-50301
security/keys: fix slab-out-of-bounds in key_task_permission
CVE-2024-50300
regulator: rtq2208: Fix uninitialized use of regulator_config
CVE-2024-50299
sctp: properly validate chunk size in sctp_sf_ootb()
CVE-2024-50298
net: enetc: allocate vf_state during PF probes
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2024-5171 heap buffer overflow in libaom | 1% Низкий | 12 месяцев назад | ||
CVE-2024-5160 Chromium: CVE-2024-5160 Heap buffer overflow in Dawn | 1% Низкий | около 2 лет назад | ||
CVE-2024-5159 Chromium: CVE-2024-5159 Heap buffer overflow in ANGLE | 1% Низкий | около 2 лет назад | ||
CVE-2024-5158 Chromium: CVE-2024-5158 Type Confusion in V8 | 1% Низкий | около 2 лет назад | ||
CVE-2024-5157 Chromium: CVE-2024-5157 Use after free in Scheduling | 1% Низкий | около 2 лет назад | ||
CVE-2024-50615 TinyXML2 through 10.0.0 has a reachable assertion for UINT_MAX/digit, that may lead to application exit, in tinyxml2.cpp XMLUtil::GetCharacterRef. | CVSS3: 6.5 | 0% Низкий | больше 1 года назад | |
CVE-2024-50614 TinyXML2 through 10.0.0 has a reachable assertion for UINT_MAX/16, that may lead to application exit, in tinyxml2.cpp XMLUtil::GetCharacterRef. | CVSS3: 6.5 | 0% Низкий | 9 месяцев назад | |
CVE-2024-50613 libsndfile through 1.2.2 has a reachable assertion, that may lead to application exit, in mpeg_l3_encode.c mpeg_l3_encoder_close. | 1% Низкий | 12 месяцев назад | ||
CVE-2024-50612 libsndfile through 1.2.2 has an ogg_vorbis.c vorbis_analysis_wrote out-of-bounds read. | CVSS3: 5.3 | 0% Низкий | больше 1 года назад | |
CVE-2024-50609 An issue was discovered in Fluent Bit 3.1.9. When the OpenTelemetry input plugin is running and listening on an IP address and port, one can send a packet with Content-Length: 0 and it crashes the server. Improper handling of the case when Content-Length is 0 allows a user (with access to the endpoint) to perform a remote Denial of service attack. The crash happens because of a NULL pointer dereference when 0 (from the Content-Length) is passed to the function cfl_sds_len, which in turn tries to cast a NULL pointer into struct cfl_sds. This is related to process_payload_traces_proto_ng() at opentelemetry_prot.c. | CVSS3: 7.5 | 1% Низкий | 6 месяцев назад | |
CVE-2024-50608 An issue was discovered in Fluent Bit 3.1.9. When the Prometheus Remote Write input plugin is running and listening on an IP address and port, one can send a packet with Content-Length: 0 and it crashes the server. Improper handling of the case when Content-Length is 0 allows a user (with access to the endpoint) to perform a remote Denial of service attack. The crash happens because of a NULL pointer dereference when 0 (from the Content-Length) is passed to the function cfl_sds_len, which in turn tries to cast a NULL pointer into struct cfl_sds. This is related to process_payload_metrics_ng() at prom_rw_prot.c. | CVSS3: 7.5 | 1% Низкий | больше 1 года назад | |
CVE-2024-50602 An issue was discovered in libexpat before 2.6.4. There is a crash within the XML_ResumeParser function because XML_StopParser can stop/suspend an unstarted parser. | CVSS3: 5.9 | 1% Низкий | почти 2 года назад | |
CVE-2024-50349 Git does not sanitize URLs when asking for credentials interactively | 1% Низкий | больше 1 года назад | ||
CVE-2024-50338 GitHub: CVE-2024-50338 Malformed URL allows information disclosure through git-credential-manager | CVSS3: 7.4 | 3% Низкий | больше 1 года назад | |
CVE-2024-50304 ipv4: ip_tunnel: Fix suspicious RCU usage warning in ip_tunnel_find() | CVSS3: 5.5 | 0% Низкий | 6 месяцев назад | |
CVE-2024-50302 HID: core: zero-initialize the report buffer | CVSS3: 5.5 | 1% Низкий | больше 1 года назад | |
CVE-2024-50301 security/keys: fix slab-out-of-bounds in key_task_permission | CVSS3: 7.1 | 0% Низкий | больше 1 года назад | |
CVE-2024-50300 regulator: rtq2208: Fix uninitialized use of regulator_config | 0% Низкий | больше 1 года назад | ||
CVE-2024-50299 sctp: properly validate chunk size in sctp_sf_ootb() | CVSS3: 5.5 | 1% Низкий | 7 дней назад | |
CVE-2024-50298 net: enetc: allocate vf_state during PF probes | CVSS3: 5.5 | 0% Низкий | 5 месяцев назад |
Уязвимостей на страницу