Количество 26 124
Количество 26 124
CVE-2024-2466
CVE-2024-24577
libgit2 is vulnerable to arbitrary code execution due to heap corruption in `git_index_add`
CVE-2024-24576
Rusts's `std::process::Command` did not properly escape arguments of batch files on Windows
CVE-2024-24575
libgit2 is vulnerable to a denial of service attack in `git_revparse_single`
CVE-2024-24557
Moby classic builder cache poisoning
CVE-2024-24479
A Buffer Overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the wsutil/to_str.c, and format_fractional_part_nsecs components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected.
CVE-2024-24478
An issue in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the packet-bgp.c, dissect_bgp_open(tvbuff_t*tvb, proto_tree*tree, packet_info*pinfo), optlen components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected.
CVE-2024-24476
A buffer overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the pan/addr_resolv.c, and ws_manuf_lookup_str(), size components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected.
CVE-2024-24474
CVE-2024-24259
freeglut through 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddMenuEntry function.
CVE-2024-24258
freeglut 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddSubMenu function.
CVE-2024-2410
CVE-2024-2408
PHP is vulnerable to the Marvin Attack
CVE-2024-2400
Chromium: CVE-2024-2400 Use after free in Performance Manager
CVE-2024-2398
CVE-2024-2397
infinite loop in the PPP printer of tcpdump
CVE-2024-23851
copy_params in drivers/md/dm-ioctl.c in the Linux kernel through 6.7.1 can attempt to allocate more than INT_MAX bytes and crash because of a missing param_kernel->data_size check. This is related to ctl_ioctl.
CVE-2024-23850
In btrfs_get_root_ref in fs/btrfs/disk-io.c in the Linux kernel through 6.7.1 there can be an assertion failure and crash because a subvolume can be read out too soon after its root item is inserted upon subvolume creation.
CVE-2024-23849
In rds_recv_track_latency in net/rds/af_rds.c in the Linux kernel through 6.7.1 there is an off-by-one error for an RDS_MSG_RX_DGRAM_TRACE_MAX comparison resulting in out-of-bounds access.
CVE-2024-23848
In the Linux kernel through 6.7.1, there is a use-after-free in cec_queue_msg_fh, related to drivers/media/cec/core/cec-adap.c and drivers/media/cec/core/cec-api.c.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVSS3: 6.5 | 1% Низкий | около 2 лет назад | ||
CVE-2024-24577 libgit2 is vulnerable to arbitrary code execution due to heap corruption in `git_index_add` | CVSS3: 9.8 | 2% Низкий | больше 2 лет назад | |
CVE-2024-24576 Rusts's `std::process::Command` did not properly escape arguments of batch files on Windows | 20% Средний | 12 месяцев назад | ||
CVE-2024-24575 libgit2 is vulnerable to a denial of service attack in `git_revparse_single` | CVSS3: 7.5 | 1% Низкий | 6 месяцев назад | |
CVE-2024-24557 Moby classic builder cache poisoning | CVSS3: 7.8 | 0% Низкий | 6 месяцев назад | |
CVE-2024-24479 A Buffer Overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the wsutil/to_str.c, and format_fractional_part_nsecs components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected. | CVSS3: 7.5 | 1% Низкий | около 1 года назад | |
CVE-2024-24478 An issue in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the packet-bgp.c, dissect_bgp_open(tvbuff_t*tvb, proto_tree*tree, packet_info*pinfo), optlen components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected. | CVSS3: 7.5 | 1% Низкий | около 1 года назад | |
CVE-2024-24476 A buffer overflow in Wireshark before 4.2.0 allows a remote attacker to cause a denial of service via the pan/addr_resolv.c, and ws_manuf_lookup_str(), size components. NOTE: this is disputed by the vendor because neither release 4.2.0 nor any other release was affected. | CVSS3: 7.5 | 1% Низкий | около 1 года назад | |
CVSS3: 8.8 | 1% Низкий | почти 2 года назад | ||
CVE-2024-24259 freeglut through 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddMenuEntry function. | CVSS3: 7.5 | 1% Низкий | около 2 лет назад | |
CVE-2024-24258 freeglut 3.4.0 was discovered to contain a memory leak via the menuEntry variable in the glutAddSubMenu function. | CVSS3: 7.5 | 1% Низкий | около 2 лет назад | |
CVSS3: 7.6 | 0% Низкий | почти 2 года назад | ||
CVE-2024-2408 PHP is vulnerable to the Marvin Attack | CVSS3: 5.9 | 1% Низкий | 6 месяцев назад | |
CVE-2024-2400 Chromium: CVE-2024-2400 Use after free in Performance Manager | 1% Низкий | больше 2 лет назад | ||
CVSS3: 8.6 | 36% Средний | почти 2 года назад | ||
CVE-2024-2397 infinite loop in the PPP printer of tcpdump | 0% Низкий | 12 дней назад | ||
CVE-2024-23851 copy_params in drivers/md/dm-ioctl.c in the Linux kernel through 6.7.1 can attempt to allocate more than INT_MAX bytes and crash because of a missing param_kernel->data_size check. This is related to ctl_ioctl. | CVSS3: 5.5 | 0% Низкий | около 2 лет назад | |
CVE-2024-23850 In btrfs_get_root_ref in fs/btrfs/disk-io.c in the Linux kernel through 6.7.1 there can be an assertion failure and crash because a subvolume can be read out too soon after its root item is inserted upon subvolume creation. | CVSS3: 5.5 | 0% Низкий | около 2 лет назад | |
CVE-2024-23849 In rds_recv_track_latency in net/rds/af_rds.c in the Linux kernel through 6.7.1 there is an off-by-one error for an RDS_MSG_RX_DGRAM_TRACE_MAX comparison resulting in out-of-bounds access. | CVSS3: 5.5 | 0% Низкий | около 2 лет назад | |
CVE-2024-23848 In the Linux kernel through 6.7.1, there is a use-after-free in cec_queue_msg_fh, related to drivers/media/cec/core/cec-adap.c and drivers/media/cec/core/cec-api.c. | 0% Низкий | 12 месяцев назад |
Уязвимостей на страницу