Количество 18 047
Количество 18 047
CVE-2024-52533
gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufficient for a trailing '\0' character.
CVE-2024-52532
GNOME libsoup before 3.6.1 has an infinite loop and memory consumption. during the reading of certain patterns of WebSocket data from clients.
CVE-2024-52531
GNOME libsoup before 3.6.1 allows a buffer overflow in applications that perform conversion to UTF-8 in soup_header_parse_param_list_strict.
CVE-2024-52530
GNOME libsoup before 3.6.0 allows HTTP request smuggling in some configurations
CVE-2024-52338
CVE-2024-52337
Tuned: improper sanitization of `instance_name` parameter of the `instance_create()` method
CVE-2024-52336
Tuned: `script_pre` and `script_post` options allow to pass arbitrary scripts executed by root
CVE-2024-52308
Connecting to a malicious Codespaces via GH CLI could allow command execution on the user's computer
CVE-2024-52006
CVE-2024-52005
The sideband payload is passed unfiltered to the terminal in git
CVE-2024-5187
CVE-2024-51744
CVE-2024-51741
Redis allows denial-of-service due to malformed ACL selectors
CVE-2024-5160
Chromium: CVE-2024-5160 Heap buffer overflow in Dawn
CVE-2024-5159
Chromium: CVE-2024-5159 Heap buffer overflow in ANGLE
CVE-2024-5158
Chromium: CVE-2024-5158 Type Confusion in V8
CVE-2024-5157
Chromium: CVE-2024-5157 Use after free in Scheduling
CVE-2024-50615
CVE-2024-50614
TinyXML2 through 10.0.0 has a reachable assertion for UINT_MAX/16, that may lead to application exit, in tinyxml2.cpp XMLUtil::GetCharacterRef.
CVE-2024-50613
libsndfile through 1.2.2 has a reachable assertion, that may lead to application exit, in mpeg_l3_encode.c mpeg_l3_encoder_close.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2024-52533 gio/gsocks4aproxy.c in GNOME GLib before 2.82.1 has an off-by-one error and resultant buffer overflow because SOCKS4_CONN_MSG_LEN is not sufficient for a trailing '\0' character. | CVSS3: 9.8 | 3% Низкий | около 1 года назад | |
CVE-2024-52532 GNOME libsoup before 3.6.1 has an infinite loop and memory consumption. during the reading of certain patterns of WebSocket data from clients. | CVSS3: 7.5 | 1% Низкий | около 1 года назад | |
CVE-2024-52531 GNOME libsoup before 3.6.1 allows a buffer overflow in applications that perform conversion to UTF-8 in soup_header_parse_param_list_strict. | CVSS3: 8.4 | 0% Низкий | около 1 года назад | |
CVE-2024-52530 GNOME libsoup before 3.6.0 allows HTTP request smuggling in some configurations | CVSS3: 7.5 | 0% Низкий | около 1 года назад | |
CVSS3: 9.8 | 5% Низкий | 11 месяцев назад | ||
CVE-2024-52337 Tuned: improper sanitization of `instance_name` parameter of the `instance_create()` method | CVSS3: 5.5 | 0% Низкий | 11 месяцев назад | |
CVE-2024-52336 Tuned: `script_pre` and `script_post` options allow to pass arbitrary scripts executed by root | CVSS3: 7.8 | 0% Низкий | 11 месяцев назад | |
CVE-2024-52308 Connecting to a malicious Codespaces via GH CLI could allow command execution on the user's computer | CVSS3: 8 | 1% Низкий | 11 месяцев назад | |
1% Низкий | 10 месяцев назад | |||
CVE-2024-52005 The sideband payload is passed unfiltered to the terminal in git | 0% Низкий | 3 месяца назад | ||
CVSS3: 8.8 | 1% Низкий | около 1 года назад | ||
CVSS3: 3.1 | 0% Низкий | 10 месяцев назад | ||
CVE-2024-51741 Redis allows denial-of-service due to malformed ACL selectors | CVSS3: 4.4 | 0% Низкий | 10 месяцев назад | |
CVE-2024-5160 Chromium: CVE-2024-5160 Heap buffer overflow in Dawn | 1% Низкий | больше 1 года назад | ||
CVE-2024-5159 Chromium: CVE-2024-5159 Heap buffer overflow in ANGLE | 1% Низкий | больше 1 года назад | ||
CVE-2024-5158 Chromium: CVE-2024-5158 Type Confusion in V8 | 1% Низкий | больше 1 года назад | ||
CVE-2024-5157 Chromium: CVE-2024-5157 Use after free in Scheduling | 1% Низкий | больше 1 года назад | ||
CVSS3: 6.5 | 0% Низкий | 7 месяцев назад | ||
CVE-2024-50614 TinyXML2 through 10.0.0 has a reachable assertion for UINT_MAX/16, that may lead to application exit, in tinyxml2.cpp XMLUtil::GetCharacterRef. | CVSS3: 6.5 | 0% Низкий | 3 месяца назад | |
CVE-2024-50613 libsndfile through 1.2.2 has a reachable assertion, that may lead to application exit, in mpeg_l3_encode.c mpeg_l3_encoder_close. | 0% Низкий | 3 месяца назад |
Уязвимостей на страницу