Количество 26 124
Количество 26 124
CVE-2024-25744
In the Linux kernel before 6.6.7, an untrusted VMM can trigger int80 syscall handling at any given point. This is related to arch/x86/coco/tdx/tdx.c and arch/x86/mm/mem_encrypt_amd.c.
CVE-2024-25741
printer_write in drivers/usb/gadget/function/f_printer.c in the Linux kernel through 6.7.4 does not properly call usb_ep_queue, which might allow attackers to cause a denial of service or have unspecified other impact.
CVE-2024-25740
A memory leak flaw was found in the UBI driver in drivers/mtd/ubi/attach.c in the Linux kernel through 6.7.4 for UBI_IOCATT, because kobj->name is not released.
CVE-2024-25739
create_empty_lvol in drivers/mtd/ubi/vtbl.c in the Linux kernel through 6.7.4 can attempt to allocate zero bytes and crash because of a missing check for ubi->leb_size.
CVE-2024-25710
Apache Commons Compress: Denial of service caused by an infinite loop for a corrupted DUMP file
CVE-2024-25629
CVE-2024-25621
containerd affected by a local privilege escalation via wide permissions on CRI directory
CVE-2024-25620
Dependency management path traversal in helm
CVE-2024-25580
CVE-2024-25431
An issue in bytecodealliance wasm-micro-runtime before v.b3f728c and fixed in commit 06df58f allows a remote attacker to escalate privileges via a crafted file to the check_was_abi_compatibility function.
CVE-2024-25260
elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c.
CVE-2024-25178
LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an out-of-bounds read in the stack-overflow handler in lj_state.c.
CVE-2024-25177
LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an unsinking of IR_FSTORE for NULL metatable, which leads to Denial of Service (DoS).
CVE-2024-25176
LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240626 have a stack-buffer-overflow in lj_strfmt_wfnum in lj_strfmt_num.c.
CVE-2024-2511
CVE-2024-25112
Denial of service due to unbounded recursion in QuickTimeVideo::multipleEntriesDecoder in Exiv2
CVE-2024-25110
CVE-2024-25062
CVE-2024-2496
Libvirt: null pointer dereference in udevconnectlistallinterfaces()
CVE-2024-2494
Libvirt: negative g_new0 length can lead to unbounded memory allocation
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2024-25744 In the Linux kernel before 6.6.7, an untrusted VMM can trigger int80 syscall handling at any given point. This is related to arch/x86/coco/tdx/tdx.c and arch/x86/mm/mem_encrypt_amd.c. | 0% Низкий | 5 месяцев назад | ||
CVE-2024-25741 printer_write in drivers/usb/gadget/function/f_printer.c in the Linux kernel through 6.7.4 does not properly call usb_ep_queue, which might allow attackers to cause a denial of service or have unspecified other impact. | 0% Низкий | 12 месяцев назад | ||
CVE-2024-25740 A memory leak flaw was found in the UBI driver in drivers/mtd/ubi/attach.c in the Linux kernel through 6.7.4 for UBI_IOCATT, because kobj->name is not released. | 0% Низкий | 9 месяцев назад | ||
CVE-2024-25739 create_empty_lvol in drivers/mtd/ubi/vtbl.c in the Linux kernel through 6.7.4 can attempt to allocate zero bytes and crash because of a missing check for ubi->leb_size. | CVSS3: 5.5 | 0% Низкий | около 2 лет назад | |
CVE-2024-25710 Apache Commons Compress: Denial of service caused by an infinite loop for a corrupted DUMP file | CVSS3: 8.1 | 0% Низкий | около 1 года назад | |
CVSS3: 4.4 | 0% Низкий | почти 2 года назад | ||
CVE-2024-25621 containerd affected by a local privilege escalation via wide permissions on CRI directory | CVSS3: 7.3 | 0% Низкий | 9 месяцев назад | |
CVE-2024-25620 Dependency management path traversal in helm | CVSS3: 6.4 | 1% Низкий | 6 месяцев назад | |
CVSS3: 6.2 | 0% Низкий | почти 2 года назад | ||
CVE-2024-25431 An issue in bytecodealliance wasm-micro-runtime before v.b3f728c and fixed in commit 06df58f allows a remote attacker to escalate privileges via a crafted file to the check_was_abi_compatibility function. | CVSS3: 7.8 | 1% Низкий | больше 1 года назад | |
CVE-2024-25260 elfutils v0.189 was discovered to contain a NULL pointer dereference via the handle_verdef() function at readelf.c. | CVSS3: 4 | 0% Низкий | 12 месяцев назад | |
CVE-2024-25178 LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an out-of-bounds read in the stack-overflow handler in lj_state.c. | CVSS3: 9.1 | 1% Низкий | около 1 года назад | |
CVE-2024-25177 LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240314 have an unsinking of IR_FSTORE for NULL metatable, which leads to Denial of Service (DoS). | CVSS3: 7.5 | 0% Низкий | 12 месяцев назад | |
CVE-2024-25176 LuaJIT through 2.1 and OpenRusty luajit2 before v2.1-20240626 have a stack-buffer-overflow in lj_strfmt_wfnum in lj_strfmt_num.c. | CVSS3: 9.8 | 0% Низкий | около 1 года назад | |
54% Средний | больше 2 лет назад | |||
CVE-2024-25112 Denial of service due to unbounded recursion in QuickTimeVideo::multipleEntriesDecoder in Exiv2 | CVSS3: 5.5 | 0% Низкий | больше 1 года назад | |
CVSS3: 8.1 | 7% Низкий | около 2 лет назад | ||
CVSS3: 7.5 | 1% Низкий | почти 2 года назад | ||
CVE-2024-2496 Libvirt: null pointer dereference in udevconnectlistallinterfaces() | CVSS3: 5.5 | 0% Низкий | 6 месяцев назад | |
CVE-2024-2494 Libvirt: negative g_new0 length can lead to unbounded memory allocation | CVSS3: 6.2 | 0% Низкий | больше 2 лет назад |
Уязвимостей на страницу