|
249341
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
net: add more sanity checks to qdisc_pkt_len_init()
One path takes care of SKB_GSO_DODGY, assuming
skb->len is bigger than hdr_le…
|
NVD-CWE-noinfo
|
CVE-2024-49948
|
2024-11-13 06:19 |
2024-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249342
|
7.5 |
HIGH
Network
|
-
|
-
|
A flaw was found in Gateway. Sending a non-base64 'basic' auth with special characters can cause APICast to incorrectly authenticate a request. A malformed basic authentication header containing spec…
|
CWE-863
Incorrect Authorization
|
CVE-2024-10295
|
2024-11-13 06:15 |
2024-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249343
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: MGMT: Fix possible crash on mgmt_index_removed
If mgmt_index_removed is called while there are commands queued on
cmd_…
|
NVD-CWE-noinfo
|
CVE-2024-49951
|
2024-11-13 06:06 |
2024-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249344
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
net: avoid potential underflow in qdisc_pkt_len_init() with UFO
After commit 7c6d2ecbda83 ("net: be more gentle about silly gso
r…
|
CWE-476
NULL Pointer Dereference
|
CVE-2024-49949
|
2024-11-13 06:03 |
2024-10-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249345
|
9.8 |
CRITICAL
Network
|
eyecix
|
jobsearch_wp_job_board
|
Deserialization of Untrusted Data vulnerability in Eyecix JobSearch allows Object Injection.This issue affects JobSearch: from n/a through 2.5.9.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-47636
|
2024-11-13 05:52 |
2024-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249346
|
9.8 |
CRITICAL
Network
|
eyecix
|
jobsearch_wp_job_board
|
Missing Authorization vulnerability in eyecix JobSearch allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects JobSearch: from n/a through 2.5.4.
|
CWE-862
Missing Authorization
|
CVE-2024-43929
|
2024-11-13 05:49 |
2024-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249347
|
8.8 |
HIGH
Network
|
eyecix
|
jobsearch_wp_job_board
|
Missing Authorization vulnerability in eyecix JobSearch allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JobSearch: from n/a through 2.5.4.
|
CWE-862
Missing Authorization
|
CVE-2024-43928
|
2024-11-13 05:49 |
2024-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249348
|
9.8 |
CRITICAL
Network
|
wpmanageninja
|
fluent_support
|
Missing Authorization vulnerability in WPManageNinja LLC Fluent Support allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Fluent Support: from n/a through 1.8…
|
CWE-862
Missing Authorization
|
CVE-2024-47302
|
2024-11-13 05:40 |
2024-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249349
|
9.8 |
CRITICAL
Network
|
kraftplugins
|
wheel_of_life
|
Missing Authorization vulnerability in Kraft Plugins Wheel of Life allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wheel of Life: from n/a through 1.1.8.
|
CWE-862
Missing Authorization
|
CVE-2024-47311
|
2024-11-13 05:35 |
2024-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249350
|
9.8 |
CRITICAL
Network
|
templately
|
templately
|
Missing Authorization vulnerability in Templately allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Templately: from n/a through 3.1.2.
|
CWE-862
Missing Authorization
|
CVE-2024-47308
|
2024-11-13 05:35 |
2024-11-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|