Количество 26 124
Количество 26 124
CVE-2024-23829
aiohttp's HTTP parser (the python one, not llhttp) still overly lenient about separators
CVE-2024-23807
Apache Xerces C++: Use-after-free on external DTD scan
CVE-2024-2379
CVE-2024-23775
CVE-2024-23744
CVE-2024-23722
In Fluent Bit 2.1.8 through 2.2.1 a NULL pointer dereference can be caused via an invalid HTTP payload with the content type of x-www-form-urlencoded. It crashes and does not restart. This could result in logs not being delivered properly.
CVE-2024-23653
BuildKit interactive containers API does not validate entitlements check
CVE-2024-23652
BuildKit possible host system access from mount stub cleaner
CVE-2024-23651
BuildKit possible race condition with accessing subpaths from cache mounts
CVE-2024-23650
BuildKit possible panic when incorrect parameters sent from frontend
CVE-2024-23594
Lenovo: CVE-2024-23594 Stack buffer overflow in Lenovo system recovery boot manager
CVE-2024-23593
Lenovo: CVE-2024-23593 Modify Boot Manager and Escalate Privileges
CVE-2024-2357
IKEv2 misconfiguration can cause libreswan to abort and restart
CVE-2024-23450
Elasticsearch Uncontrolled Resource Consumption vulnerability
CVE-2024-23444
Elasticsearch elasticsearch-certutil csr fails to encrypt private key
CVE-2024-23342
python-ecdsa vulnerable to Minerva attack on P-256
CVE-2024-23337
jq has signed integer overflow in jv.c:jvp_array_write
CVE-2024-23334
aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal
CVE-2024-23307
Integer overflow in raid5_cache_count in Linux kernel
CVE-2024-23170
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2024-23829 aiohttp's HTTP parser (the python one, not llhttp) still overly lenient about separators | 1% Низкий | 12 месяцев назад | ||
CVE-2024-23807 Apache Xerces C++: Use-after-free on external DTD scan | CVSS3: 8.1 | 1% Низкий | больше 1 года назад | |
2% Низкий | почти 2 года назад | |||
CVSS3: 7.5 | 1% Низкий | больше 1 года назад | ||
CVSS3: 7.5 | 1% Низкий | больше 1 года назад | ||
CVE-2024-23722 In Fluent Bit 2.1.8 through 2.2.1 a NULL pointer dereference can be caused via an invalid HTTP payload with the content type of x-www-form-urlencoded. It crashes and does not restart. This could result in logs not being delivered properly. | CVSS3: 7.5 | 1% Низкий | больше 2 лет назад | |
CVE-2024-23653 BuildKit interactive containers API does not validate entitlements check | CVSS3: 9.8 | 3% Низкий | 6 месяцев назад | |
CVE-2024-23652 BuildKit possible host system access from mount stub cleaner | CVSS3: 9.1 | 2% Низкий | больше 2 лет назад | |
CVE-2024-23651 BuildKit possible race condition with accessing subpaths from cache mounts | CVSS3: 7.4 | 1% Низкий | больше 2 лет назад | |
CVE-2024-23650 BuildKit possible panic when incorrect parameters sent from frontend | CVSS3: 5.3 | 1% Низкий | 6 месяцев назад | |
CVE-2024-23594 Lenovo: CVE-2024-23594 Stack buffer overflow in Lenovo system recovery boot manager | CVSS3: 6.4 | 0% Низкий | больше 2 лет назад | |
CVE-2024-23593 Lenovo: CVE-2024-23593 Modify Boot Manager and Escalate Privileges | CVSS3: 6.7 | 0% Низкий | больше 2 лет назад | |
CVE-2024-2357 IKEv2 misconfiguration can cause libreswan to abort and restart | CVSS3: 6.5 | 1% Низкий | 12 месяцев назад | |
CVE-2024-23450 Elasticsearch Uncontrolled Resource Consumption vulnerability | 1% Низкий | 12 дней назад | ||
CVE-2024-23444 Elasticsearch elasticsearch-certutil csr fails to encrypt private key | 0% Низкий | 12 дней назад | ||
CVE-2024-23342 python-ecdsa vulnerable to Minerva attack on P-256 | 1% Низкий | 6 дней назад | ||
CVE-2024-23337 jq has signed integer overflow in jv.c:jvp_array_write | CVSS3: 4.3 | 0% Низкий | 6 дней назад | |
CVE-2024-23334 aiohttp.web.static(follow_symlinks=True) is vulnerable to directory traversal | 77% Высокий | 12 месяцев назад | ||
CVE-2024-23307 Integer overflow in raid5_cache_count in Linux kernel | CVSS3: 4.4 | 1% Низкий | около 2 лет назад | |
CVSS3: 5.5 | 0% Низкий | больше 1 года назад |
Уязвимостей на страницу