Количество 26 125
Количество 26 125
CVE-2024-45336
Sensitive headers incorrectly sent after cross-domain redirect in net/http
CVE-2024-45310
runc can be confused to create empty files/directories on the host
CVE-2024-45296
path-to-regexp outputs backtracking regular expressions
CVE-2024-45159
An issue was discovered in Mbed TLS 3.x before 3.6.1. With TLS 1.3, when a server enables optional authentication of the client, if the client-provided certificate does not have appropriate values in if keyUsage or extKeyUsage extensions, then the return value of mbedtls_ssl_get_verify_result() would incorrectly have the MBEDTLS_X509_BADCERT_KEY_USAGE and MBEDTLS_X509_BADCERT_KEY_USAGE bits clear. As a result, an attacker that had a certificate valid for uses other than TLS client authentication would nonetheless be able to use it for TLS client authentication. Only TLS 1.3 servers were affected, and only with optional authentication (with required authentication, the handshake would be aborted with a fatal alert).
CVE-2024-45157
CVE-2024-45030
igb: cope with large MAX_SKB_FRAGS
CVE-2024-45029
i2c: tegra: Do not mark ACPI devices as irq safe
CVE-2024-45028
mmc: mmc_test: Fix NULL dereference on allocation failure
CVE-2024-45026
s390/dasd: fix error recovery leading to data corruption on ESE devices
CVE-2024-45025
fix bitmap corruption on close_range() with CLOSE_RANGE_UNSHARE
CVE-2024-45022
mm/vmalloc: fix page mapping if vm_area_alloc_pages() with high order fallback to order 0
CVE-2024-45021
memcg_write_event_control(): fix a user-triggerable oops
CVE-2024-45020
bpf: Fix a kernel verifier crash in stacksafe()
CVE-2024-45019
net/mlx5e: Take state lock during tx timeout reporter
CVE-2024-45018
netfilter: flowtable: initialise extack before use
CVE-2024-45016
netem: fix return value if duplicate enqueue fails
CVE-2024-45015
drm/msm/dpu: move dpu_encoder's connector assignment to atomic_enable()
CVE-2024-45012
nouveau/firmware: use dma non-coherent allocator
CVE-2024-45011
char: xillybus: Check USB endpoints when probing device
CVE-2024-45010
mptcp: pm: only mark 'subflow' endp as available
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2024-45336 Sensitive headers incorrectly sent after cross-domain redirect in net/http | CVSS3: 6.1 | 1% Низкий | больше 1 года назад | |
CVE-2024-45310 runc can be confused to create empty files/directories on the host | CVSS3: 3.6 | 0% Низкий | больше 1 года назад | |
CVE-2024-45296 path-to-regexp outputs backtracking regular expressions | CVSS3: 7.5 | 1% Низкий | почти 2 года назад | |
CVE-2024-45159 An issue was discovered in Mbed TLS 3.x before 3.6.1. With TLS 1.3, when a server enables optional authentication of the client, if the client-provided certificate does not have appropriate values in if keyUsage or extKeyUsage extensions, then the return value of mbedtls_ssl_get_verify_result() would incorrectly have the MBEDTLS_X509_BADCERT_KEY_USAGE and MBEDTLS_X509_BADCERT_KEY_USAGE bits clear. As a result, an attacker that had a certificate valid for uses other than TLS client authentication would nonetheless be able to use it for TLS client authentication. Only TLS 1.3 servers were affected, and only with optional authentication (with required authentication, the handshake would be aborted with a fatal alert). | CVSS3: 9.8 | 0% Низкий | больше 1 года назад | |
CVSS3: 5.1 | 0% Низкий | больше 1 года назад | ||
CVE-2024-45030 igb: cope with large MAX_SKB_FRAGS | CVSS3: 5.5 | 0% Низкий | почти 2 года назад | |
CVE-2024-45029 i2c: tegra: Do not mark ACPI devices as irq safe | CVSS3: 5.5 | 0% Низкий | почти 2 года назад | |
CVE-2024-45028 mmc: mmc_test: Fix NULL dereference on allocation failure | CVSS3: 5.5 | 0% Низкий | почти 2 года назад | |
CVE-2024-45026 s390/dasd: fix error recovery leading to data corruption on ESE devices | CVSS3: 7.8 | 0% Низкий | почти 2 года назад | |
CVE-2024-45025 fix bitmap corruption on close_range() with CLOSE_RANGE_UNSHARE | CVSS3: 5.5 | 0% Низкий | почти 2 года назад | |
CVE-2024-45022 mm/vmalloc: fix page mapping if vm_area_alloc_pages() with high order fallback to order 0 | CVSS3: 5.5 | 0% Низкий | почти 2 года назад | |
CVE-2024-45021 memcg_write_event_control(): fix a user-triggerable oops | CVSS3: 5.5 | 0% Низкий | почти 2 года назад | |
CVE-2024-45020 bpf: Fix a kernel verifier crash in stacksafe() | CVSS3: 5.5 | 0% Низкий | почти 2 года назад | |
CVE-2024-45019 net/mlx5e: Take state lock during tx timeout reporter | CVSS3: 5.5 | 0% Низкий | почти 2 года назад | |
CVE-2024-45018 netfilter: flowtable: initialise extack before use | CVSS3: 5.5 | 0% Низкий | почти 2 года назад | |
CVE-2024-45016 netem: fix return value if duplicate enqueue fails | CVSS3: 5.5 | 0% Низкий | почти 2 года назад | |
CVE-2024-45015 drm/msm/dpu: move dpu_encoder's connector assignment to atomic_enable() | CVSS3: 5.5 | 0% Низкий | почти 2 года назад | |
CVE-2024-45012 nouveau/firmware: use dma non-coherent allocator | CVSS3: 5.5 | 0% Низкий | почти 2 года назад | |
CVE-2024-45011 char: xillybus: Check USB endpoints when probing device | CVSS3: 5.5 | 0% Низкий | почти 2 года назад | |
CVE-2024-45010 mptcp: pm: only mark 'subflow' endp as available | CVSS3: 5.5 | 0% Низкий | почти 2 года назад |
Уязвимостей на страницу