Количество 26 125
Количество 26 125
CVE-2024-36893
usb: typec: tcpm: Check for port partner validity before consuming it
CVE-2024-36891
maple_tree: fix mas_empty_area_rev() null pointer dereference
CVE-2024-36623
moby through v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger multiple concurrent write operations resulting in data corruption or application crashes.
CVE-2024-36621
moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go. The vulnerability could be used to trigger concurrent builds that call the EnsureLayer function resulting in resource leaks/exhaustion.
CVE-2024-36620
moby v25.0.0 - v26.0.2 is vulnerable to NULL Pointer Dereference via daemon/images/image_history.go.
CVE-2024-3660
Arbitrary code injection vulnerability in Keras framework < 2.13
CVE-2024-3652
CVE-2024-3651
CVE-2024-36481
tracing/probes: fix error check in parse_btf_field()
CVE-2024-36479
fpga: bridge: add owner module and take its refcount
CVE-2024-36478
CVE-2024-36477
tpm_tis_spi: Account for SPI header when allocating TPM SPI xfer buffer
CVE-2024-36476
RDMA/rtrs: Ensure 'ib_sge list' is accessible
CVE-2024-36387
Apache HTTP Server: DoS by Null pointer in websocket over HTTP/2
CVE-2024-36357
AMD: CVE-2024-36357 Transient Scheduler Attack in L1 Data Queue
CVE-2024-36350
AMD: CVE-2024-36350 Transient Scheduler Attack in Store Queue
CVE-2024-36288
SUNRPC: Fix loop termination condition in gss_free_in_token_pages()
CVE-2024-36244
net/sched: taprio: extend minimum interval restriction to entire cycle too
CVE-2024-36138
Bypass incomplete fix of CVE-2024-27980, that arises from improper handling of batch files with all possible extensions on Windows via child_process.spawn / child_process.spawnSync. A malicious command line argument can inject arbitrary commands and achieve code execution even if the shell option is not enabled.
CVE-2024-36137
A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-write flag is used. Node.js Permission Model do not operate on file descriptors, however, operations such as fs.fchown or fs.fchmod can use a "read-only" file descriptor to change the owner and permissions of a file.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2024-36893 usb: typec: tcpm: Check for port partner validity before consuming it | CVSS3: 5.5 | 0% Низкий | около 2 лет назад | |
CVE-2024-36891 maple_tree: fix mas_empty_area_rev() null pointer dereference | CVSS3: 5.5 | 0% Низкий | около 2 лет назад | |
CVE-2024-36623 moby through v25.0.3 has a Race Condition vulnerability in the streamformatter package which can be used to trigger multiple concurrent write operations resulting in data corruption or application crashes. | CVSS3: 8.1 | 1% Низкий | больше 1 года назад | |
CVE-2024-36621 moby v25.0.5 is affected by a Race Condition in builder/builder-next/adapters/snapshot/layer.go. The vulnerability could be used to trigger concurrent builds that call the EnsureLayer function resulting in resource leaks/exhaustion. | CVSS3: 6.5 | 1% Низкий | больше 1 года назад | |
CVE-2024-36620 moby v25.0.0 - v26.0.2 is vulnerable to NULL Pointer Dereference via daemon/images/image_history.go. | CVSS3: 6.5 | 1% Низкий | больше 1 года назад | |
CVE-2024-3660 Arbitrary code injection vulnerability in Keras framework < 2.13 | 2% Низкий | 12 месяцев назад | ||
CVSS3: 6.5 | 1% Низкий | больше 2 лет назад | ||
CVSS3: 7.5 | 1% Низкий | около 2 лет назад | ||
CVE-2024-36481 tracing/probes: fix error check in parse_btf_field() | CVSS3: 5.5 | 0% Низкий | около 2 лет назад | |
CVE-2024-36479 fpga: bridge: add owner module and take its refcount | 0% Низкий | 12 месяцев назад | ||
CVSS3: 5.5 | 0% Низкий | почти 2 года назад | ||
CVE-2024-36477 tpm_tis_spi: Account for SPI header when allocating TPM SPI xfer buffer | CVSS3: 7.8 | 0% Низкий | около 2 лет назад | |
CVE-2024-36476 RDMA/rtrs: Ensure 'ib_sge list' is accessible | CVSS3: 5.5 | 1% Низкий | больше 1 года назад | |
CVE-2024-36387 Apache HTTP Server: DoS by Null pointer in websocket over HTTP/2 | CVSS3: 5.4 | 2% Низкий | больше 1 года назад | |
CVE-2024-36357 AMD: CVE-2024-36357 Transient Scheduler Attack in L1 Data Queue | CVSS3: 5.6 | 0% Низкий | около 1 года назад | |
CVE-2024-36350 AMD: CVE-2024-36350 Transient Scheduler Attack in Store Queue | CVSS3: 5.6 | 0% Низкий | около 1 года назад | |
CVE-2024-36288 SUNRPC: Fix loop termination condition in gss_free_in_token_pages() | CVSS3: 5.5 | 1% Низкий | около 2 лет назад | |
CVE-2024-36244 net/sched: taprio: extend minimum interval restriction to entire cycle too | 0% Низкий | 11 месяцев назад | ||
CVE-2024-36138 Bypass incomplete fix of CVE-2024-27980, that arises from improper handling of batch files with all possible extensions on Windows via child_process.spawn / child_process.spawnSync. A malicious command line argument can inject arbitrary commands and achieve code execution even if the shell option is not enabled. | 1% Низкий | 13 дней назад | ||
CVE-2024-36137 A vulnerability has been identified in Node.js, affecting users of the experimental permission model when the --allow-fs-write flag is used. Node.js Permission Model do not operate on file descriptors, however, operations such as fs.fchown or fs.fchmod can use a "read-only" file descriptor to change the owner and permissions of a file. | CVSS3: 3.3 | 0% Низкий | 9 месяцев назад |
Уязвимостей на страницу